GDPR (General Data Protection Regulation) “is the most important change in data privacy regulation in 20 years – we are here to ensure you are prepared”
Prepared for what? How and when?
The GDPR is a regulation (EU - 2016/679) through which institutions of the European Union (EU) aim to strengthen and unify data protection for all people within the EU.It also addresses the export of personal data outside the EU. The main objectives of the GDPR are to give citizens and residents control over their personal data and to simplify the regulatory framework for international business through unification of standards within the EU. When the GDPR becomes effective, it will replace the Data Protection Directive in force since 1995.
The Regulation was adopted on April 27, 2016 and will apply from May 25, 2018 and, unlike a directive, does not require national governments to approve enabling legislation.
Which organizations does the GDPR apply to?
The GDPR applies not only to organizations located within the EU but also to those outside the EU, if they offer goods or services to people affected by the EU. It applies to all companies that process and retain personal data of people residing in the European Union, regardless of the physical and legal location of the company.What are the penalties for non-compliance?
Organizations that fail to comply with the regulations can be fined up to 4% of annual global revenue, or €20 million. Reasons for fines may include, for example: not having sufficient customer consent to process data, violating basic privacy concepts, not keeping records in order, not notifying the supervisory authority and the interested party about a breach, or not conducting an impact assessment, among others. It is important to note that these rules apply to both controllers and processors—which means that "clouds" will not be exempt from the application of the GDPR.What is considered personal data? Does it apply to current data and processes?
Personal data is considered to be any information related to a natural person that can be used directly or indirectly to identify that person. This can include data such as: name, photo, email address, banking details, social media publications, medical information, and even IP addresses. Although much of the GDPR legislation refers to how you collect and use information, there is also a part that describes what you must do if you have a data breach. Organizations that cannot find the answers to "who," "what," "where," "when," within 72 hours of learning that they have had a security issue and fail to notify the relevant authorities will be in serious trouble.Current processes must be reevaluated and modified to comply with the GDPR regulation. Organizations must be able to protect and demonstrate the processes that allow them to understand what happened during a data breach and comply with requirements for both new and existing data.
Conclusion
As a conclusion, we can imagine the following example.An EU citizen is traveling in a non-EU country. For some reason, they decide to take their mobile phone, access an online shopping portal, and make a transaction with their credit card. We can note that at least the following companies, from different sectors, are involved in the operation:
- Mobile telephony
- Credit card
- Bank
- Shopping portal