It’s Time to Prepare for GDPR

3 min read

Recent high-profile cases of data breaching mean that the issue of protecting customers’ information is rarely out of the headlines. Several major companies worldwide have suffered data breaches with some forced to pay out huge sums in compensation, highlighting the increased risk that companies face when storing the personal data of their clients.

The safety of personal data is of major concern to companies, and stringent new regulation is coming into force that will tighten up the way that companies will have to look at their customer’s personal data. Agreed in April 2016, the EU General Data Protection Regulation (GDPR) replaces current EU regulation on data protection and will be in force from 25th May 2018. Its aim is to protect the rights of EU citizens in relation to data protection and to simplify compliance for organizations managing the personal data of EU citizens.

What is the General Data Protection Regulation?

The GDPR replaces the current 1995 EU Data Protection Directive with the intention of addressing the changing ways that data can be used and exploited in the modern era. It seeks to give control back to individuals as to how their personal data is used, stored, transmitted, and shared between companies. The regulation is aimed at creating a clearer, standardized legal environment throughout the EU, replacing current data protection regulations, which are country-by-country. Protection for all EU citizens will be provided, no matter whether the company handling their data is EU-based or not.

How is GDPR different from existing legislation?

GDPR will include a broader definition of personal data, encompassing more information stored by companies. Issues of accountability, risk, and transparency will be given far more importance under GDPR, meaning companies will have to consider these issues thoroughly when dealing with personal data.

Rules on consent will be tightened and clear affirmation action will be required from customers, such as opt-in rather than pre-ticked boxes. This will need to be written in clear language that customers can understand, especially in relation to children, where the language should be at a level relative to their age. Parental consent will also be needed for processing data on children under the age of 16.

Notification of data breaches will become an obligation, and companies will have 72 hours on discovering a breach to notify those affected. Exceptions are if there is minimal risk to the individuals, or if sufficient measures have been introduced to minimize risk. Notifications will also need to be written in easy-to-understand language so that individuals are fully aware of the risks they face and what actions the company will be taking to solve the problem.

Penalties under the new regulations will also change, with companies who violate the regulations facing fines of up to €20 million or 4% of their worldwide revenue, whichever is greater.

Are there disadvantages to GDPR?

The most obvious disadvantage to GDPR is the additional cost that companies will face in implementing changes to their policies and procedures to comply with the new regulations.

A review of current policies, procedures, and systems may be needed to ensure that they all meet the new regulations. If not, expensive investment may be needed. Documentation and contracts relevant to customers, suppliers, and third parties may have to be amended or re-written completely, especially where the new material needs to be highly accessible.

Terms like ‘risk’ and ‘disproportionate effect’ can be difficult to define exactly and this may cause problems when different interpretations arise.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at donnelleylanguagesolutions.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.