Skip to main content

Changes with the new GDPR

The new General Data Protection Regulation of the EU was voted the 25th May 2016 ans will therefore enter into force the 25th May 2018.
As opposed to its predecessor (which will be in force till then) which was a directive, this will be a regulation. The difference is that a directive has to be transposed by national legislation and is therefore subject to "customisation" by the different national legislations. Thus, companies operating in several EU member states were faced with these different rules. The new regulation also defines some questions which member states can regulate but these mainly concern processing of data by their public services. Companies and nonprofits will have to adapt to the same rules whichever member state of the European Economic Area they operate in. By the "one stop shop" and the rules of co-operation between the national data protection authorities will make easier both for data subjects and data controllers to deal with cases concerning several countries.
They will also benefit from a number of other changes: the new rules concentrate more on accountability and records evidencing compliance than administrative procedures. Even direct marketing can be considered in some cases as legitimate ground for collecting and using personal data. On the other hand, this comes with enforced rights of the data subjects - the famous "right to be forgotten" but also the right to data portability and a clarification of the requirements for consent to be given (which are stricter in the case of "special categories of data", i.e. sensitive data which merit special protection) and requirements for the data controllers (the companies using the data, for example) to have more foresight - privacy by design, privacy by default, privacy impact assessments.
In the following series of posts I will go through the main new and changed features of data protection legislation and give some hints how data controllers can prepare and then comply.

Comments

Popular posts from this blog

Why is there no article about transmission of data to EU controllers in the GDPR?

There is an article, number 9, in the data protection regulation for EU institutions (Regulation (EU) 2018/1725, called EUDPR). The transmission to other EU institutions or to another controller within the same institution is, however, only subject to recital 21. In the GDPR , even the recitals do not mention transmission of personal data to other European organisations. Of course, the use of processors is regulated in both acts, but not the transmission to another controller. It can be concluded that the transmission to entities under the same legislation is not covered while transmission from EU institutions to entities under a regulation which has a wider scope, is. The reason is clear: protection by the EUDPR is intended to be stricter. For example, EU institutions are not allowed to process data based on legitimate interest. Therefore transmission to another controller, who may process data based on legal bases unavailable for EU institutions, is restricted to cases where the sam...

The Transatlantic Data Privacy Framework - new way to transfer personal data to US organisations

 After long negotiations, the new adequacy decision for processing personal data of EU data subjects in the United States resulted in new rules and the setting up of new organisations in the US and an adequacy decision by the European Commission. This enables the transfer of personal data only by organisations in the US who register to the EU-U.S. Transatlantic Data Privacy Framework. Organisations registered to the predecessor of the new framework, the Privacy Shield, retain their registration if they maintained it and continue to fulfil the conditions. The list of organisations registered can be found here: https://www.dataprivacyframework.gov/s/participant-search .   As mentioned above, it is not only the Commission adequacy decision which is new, the United States also undertook a number of measures, in particular concerning the regulation of surveillance of electronic communications, to harmonise the American rules more with the European data protection requirements. ...

The right to information and data subject access requests

The European Court of Justice dealt with some cases concerning data subject access requests and clarified the scope of certain information to be provided. 1. The right to informationThe data subjects have the right to be informed about how their personal data are processed by the controller. This information has to be provided using a privacy statement which is also called data protection notice. The privacy statement has a set content which serves not only to inform data subjects about which of their personal data are processed and how but also to assure them that their personal data are processed in compliance with EU rules. Some information in the privacy statements is nevertheless general and therefore data subjects can request further information and access to the personal data the controller processes about them. Privacy statements can be displayed on the webpages of the controller. Some controllers publish one comprehensive privacy statement which contains information about vari...