General Data Protection Regulation

Everything You Need to Know About GDPR

Does your organization comply with the new data protection rules?

The General Data Protection Regulation (GDPR) was enacted by the European Parliament, the European Commission, and the Council of the European Union for the benefit of all European Union residents. The GDPR key provisions exist to strengthen and standardize data protection, and to give EU residents more control over their data. The GDPR should also be good for international businesses because it unifies data protection standards making compliance. The regulation also governs how you export personal data.

The EU adopted the GDPR on April 27, 2016. It will be enforceable as of May 25, 2018. The regulation doesn’t require that the individual EU members pass any legislation of their own to enable the law. The GDPR replaces the current Data Protection Directive. Companies that fail to be GDPR compliant by May 25, 2018, will be subject to harsh fines and penalties.

GDPR Key Provisions at a Glance

The regulation has 91 articles. Some of the benefits of these articles are:

  •    You must have the individual’s consent before processing their data.
  •    Subjects have the right to prompt notice when a breach exposes their data.
  •    Anonymize the data.
  •    Handle cross-border data transfers securely.
  •    Some businesses and organizations will need to appoint a data protection officer (DPO). For example, companies that handle data about ethnic origin, religious belief, health, racial, or genetic data must use a DPO.
  •    Any business, regardless of where it is located, that markets services or goods to residents of the EU must comply with the GDPR. This means any business that operates globally must comply with the regulation.

Residents have the right to portability, which means they can move their data between service providers more securely. In some cases they can even demand erasure.

Companies must put reasonable data protection measures in place. This includes the requirement to conduct assessments to identify consumer data risks.

Data protection duty officers ensure compliance with the GDPR and report to data subjects and to supervising authorities.

Penalties for failing to comply with the GDPR

Supervising authorities can investigate noncompliance, and since their powers now exceed those in the old Directive, they can order corrections outright. They can also order deletion and block transfers to other countries.

Companies that fail to comply face fines in two tiers. The lower tier reaches 2% of global annual turnover or EUR 10 million, and the upper tier reaches 4% or EUR 20 million. In each tier, whichever figure is higher applies.

A European Data Protection Board (EDPB) governs the Supervising Authorities.

Some GDPR Considerations

  •       The need to have a Data Protection Officer is new.
  •       Legislators wrote the GDPR with cloud providers and social networking in mind.
  •       An Irish DPA may be advisable for non-European businesses because it’s English language-based.
  •       Companies previously not subject to similar data protection rules will need to spend a lot of time and effort to become compliant. Companies in compliance with current privacy policies will still need to work hard to meet the conditions of the new GDPR regulation.

Related reading

Understand the new GDPR requirements and what you need to do to be compliant.

The GDPR is a complicated new law. Because the law targets cloud providers directly, a good data center already knows which steps matter. To get GDPR compliant before the May 2018 enactment date, please contact Volico and talk with one of our compliance professionals.

•  Call: (305) 735-8098
•  Chat with a member of our team to discuss which solution best fits your needs.

Share this blog

About cookies on Volico.com

Volico Data Centers use cookies to collect and analyse information on site performance and usage. This site uses essential cookies which are required for functionality.  More detail is available in our privacy policy. Learn more