GDPR compliance is not optional for US companies that touch EU data. The definition of personal data is far wider than most teams assume. The European Union has made bold strides toward protecting personal information from the businesses that collect it. The General Data Protection Regulation (GDPR) took effect on May 25, 2018. It reaches every US company with connections to EU citizens.
GDPR Data Protections
Companies collecting data on EU citizens must comply with the GDPR. The GDPR took years of work across the EU. It brings data protection rules in line with how personal data is actually used today. The rules should set a new standard for protecting consumer rights. However, the new legislation could find some companies struggling to comply without new systems and processes for data protection.
The GDPR covers any transaction inside an EU member state, and any transaction involving a citizen located in the EU. It also covers data exported out of the EU. These requirements are consistent for all 27 countries in the EU and are quite strict compared to previous standards. Most companies will, therefore, have to make significant changes to meet the new requirements.
Companies must already protect personally identifiable data. The GDPR widens what counts as “personally identifiable.” The new standard moves beyond Social Security numbers and names to include individual IP addresses, cookie data, and much more. The GDPR protects basic identity information, web data, and health and genetic data. It also covers biometric data, racial and ethnic data, political views and sexual orientation.
GDPR compliance rests on five protections. You need consent before processing data, anonymized personal data, and timely breach notifications. You also need safe data transfers, and in some cases a designated data protection officer.
How to Build GDPR Compliance Into Your Operations
If you store or process that information about EU citizens living in the EU, GDPR compliance applies to you. These new regulations will impact an estimated 65 to 90 percent of US companies.
Security teams will have new concerns, since GDPR compliance changes what they must prove. Companies must show compliance across controllers, processors and protection officers. They are also answerable for contractor compliance. The new regulations make third-party processors just as liable as the corporations for whom they work.
You may need a data protection officer if you handle large volumes of EU citizen data. So any contracts with external contractors must clearly outline compliance expectations and responsibilities.
Related reading
Need Help to Comply With the GDPR Guidelines?
To check that your company is ready, contact the Volico team and talk through your data collection and security options. Our team understands the GDPR and gives clear, professional advice on data privacy. Contact us today.
• Call: (305) 735-8098
• Chat with a member of our team to discuss which solution best fits your needs.







