Skip to main content

The day has come...

when the new GDPR entered into force. If not else, you noticed it by receiving e-mails from all quarters, partially confirming that the sender complies with the new rules or that changed its privacy policies in line with the new rules or asking for your consent to use your data.
Did those who did not write you, miss something? Did you miss something when you did not write to all people whose data you store? Well, it depends.

Those who complied with the old directive (and the national laws transposing it), do not necessarily have to do something. There are, however, three changes behind for them:
- instead of relying on a notification to their data protection authority, they themselves have to keep documentation demonstrating that they comply with the new regulation
- there are more strict and also more precise rules when someone can ask "to be forgotten" i.e. his/her data erased
- non-compliance can result in hefty fines.
Some organisations may have to nominate a data protection officer which they didn't have before.

So for whom do things change?
Those who had vague or non-comprehensive privacy statements, have to adjust them to contain all information required by the regulation.
The scope of the regulation being wider than that of the directive, overseas organisations who process personal data of EU residents clearly have to comply now. One sign of that are the notices we receive about new privacy policies - they may have indeed changed but  it is also possible that only the content of the privacy statements was made comprehensive.

Finally, the biggest change can be for those, who based their personal data processing on implicit consent. The requirement for an express and informed consent was reinforced in the new regulation, leaving a pre-ticked box ticked or simply continuing to browse or to use a service does not constitute consent any more. So therefore do we get e-mails where organisations ask us to consent for the use (processing in the jargon of the regulation) of our personal data in order to be able to continue using the service.

Now this is an interesting setup as unless the data are necessary for the use of the service, the consent cannot be the condition of using it. Of course we cannot use Facebook without giving some basic data as it does not make sense and an e-mail address for contact may also be necessary. No one can be expected to deliver goods to us without knowing our address. There are, however, some questions ahead: a payment provider needs our payment card data, but a merchant (the seller) may simply redirect us to the sit of the payment provider, they do not need our card data. A convenience service can be offered to remember the card data so that we do not have to enter them again at the next purchase, but this is typically the case where this cannot be a precondition for buying. There are a number of similar cases so look forward for some disputes in the future, and not just the high-profile crusade of Mr Schrems against Facebook and now, Google and others). This crusade, however, will be subject of an article soon.

Comments

Popular posts from this blog

Why is there no article about transmission of data to EU controllers in the GDPR?

There is an article, number 9, in the data protection regulation for EU institutions (Regulation (EU) 2018/1725, called EUDPR). The transmission to other EU institutions or to another controller within the same institution is, however, only subject to recital 21. In the GDPR , even the recitals do not mention transmission of personal data to other European organisations. Of course, the use of processors is regulated in both acts, but not the transmission to another controller. It can be concluded that the transmission to entities under the same legislation is not covered while transmission from EU institutions to entities under a regulation which has a wider scope, is. The reason is clear: protection by the EUDPR is intended to be stricter. For example, EU institutions are not allowed to process data based on legitimate interest. Therefore transmission to another controller, who may process data based on legal bases unavailable for EU institutions, is restricted to cases where the sam...

The Transatlantic Data Privacy Framework - new way to transfer personal data to US organisations

 After long negotiations, the new adequacy decision for processing personal data of EU data subjects in the United States resulted in new rules and the setting up of new organisations in the US and an adequacy decision by the European Commission. This enables the transfer of personal data only by organisations in the US who register to the EU-U.S. Transatlantic Data Privacy Framework. Organisations registered to the predecessor of the new framework, the Privacy Shield, retain their registration if they maintained it and continue to fulfil the conditions. The list of organisations registered can be found here: https://www.dataprivacyframework.gov/s/participant-search .   As mentioned above, it is not only the Commission adequacy decision which is new, the United States also undertook a number of measures, in particular concerning the regulation of surveillance of electronic communications, to harmonise the American rules more with the European data protection requirements. ...

The right to information and data subject access requests

The European Court of Justice dealt with some cases concerning data subject access requests and clarified the scope of certain information to be provided. 1. The right to informationThe data subjects have the right to be informed about how their personal data are processed by the controller. This information has to be provided using a privacy statement which is also called data protection notice. The privacy statement has a set content which serves not only to inform data subjects about which of their personal data are processed and how but also to assure them that their personal data are processed in compliance with EU rules. Some information in the privacy statements is nevertheless general and therefore data subjects can request further information and access to the personal data the controller processes about them. Privacy statements can be displayed on the webpages of the controller. Some controllers publish one comprehensive privacy statement which contains information about vari...