When will GDPR come into effect?
After years of debate and preparation, the General Data Protection Regulation (GDPR) will be enforced from May 25 2018.
Why is GDPR being implemented?
GDPR is designed to harmonize data privacy laws across Europe, protect and empower all EU citizens' data privacy, and reshape the way organisations approach data privacy.
Where will GDPR be implemented?
This regulation will be implemented in all local privacy laws across the entire EU and EEA region. It will apply to all companies selling and storing personal information about citizens in Europe, including companies on other continents.
It provides citizens of the EU and EEA with greater control over their personal data and ensures that their information is being securely protected.
Under GDPR, individuals have the right;
- To access their personal data and ask how their data is used by the company after it has been gathered. The company must provide a copy of the personal data free of charge and in electronic format if requested.
- To be forgotten – if consumers are no longer customers, or if they withdraw their consent from a company to use their personal data, then they have the right to have their data deleted.
- To data portability – Individuals have a right to transfer their data from one service provider to another and this must occur in a commonly used, machine-readable format.
- To be informed before companies gather any data. Consumers have to opt in for their data to be gathered and consent must be freely given rather than implied.
- To have information corrected – this ensures that individuals can have their data updated if it is out of date, incomplete or incorrect.
- To restrict processing – Individuals can request that their data is not used for processing. Their record can remain in place, but not be used.
- To object – this includes the right of individuals to stop the processing of their data for direct marketing. There are no exemptions to this rule, and any processing must stop as soon as the request is received. In addition, this right must be made clear to individuals at the very start of any communication.
- To be notified – If there has been a data breach which compromises an individual’s personal data, the individual has a right to be informed within 72 hours of first having become aware of the breach.
Will GDPR impact my business?
Short answer, yes.
This new regulation will put the consumer in the driving seat and the duty of compliance onto businesses.
GDPR not only applies to organisations located within the EU but it will also apply to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of EU data. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location. Even with the likes of Brexit looming, the UK will still have to adhere to GDPR.
If a business fails to comply with GDPR then it will face a fine of up to 4% of annual global turnover or €20 million. This is the maximum fine that can be imposed for the most serious infringements e.g. not having sufficient customer consent to process data or violating the core of Privacy by Design concepts.