Skip to main content

Changes with the new GDPR

The new General Data Protection Regulation of the EU was voted the 25th May 2016 ans will therefore enter into force the 25th May 2018.
As opposed to its predecessor (which will be in force till then) which was a directive, this will be a regulation. The difference is that a directive has to be transposed by national legislation and is therefore subject to "customisation" by the different national legislations. Thus, companies operating in several EU member states were faced with these different rules. The new regulation also defines some questions which member states can regulate but these mainly concern processing of data by their public services. Companies and nonprofits will have to adapt to the same rules whichever member state of the European Economic Area they operate in. By the "one stop shop" and the rules of co-operation between the national data protection authorities will make easier both for data subjects and data controllers to deal with cases concerning several countries.
They will also benefit from a number of other changes: the new rules concentrate more on accountability and records evidencing compliance than administrative procedures. Even direct marketing can be considered in some cases as legitimate ground for collecting and using personal data. On the other hand, this comes with enforced rights of the data subjects - the famous "right to be forgotten" but also the right to data portability and a clarification of the requirements for consent to be given (which are stricter in the case of "special categories of data", i.e. sensitive data which merit special protection) and requirements for the data controllers (the companies using the data, for example) to have more foresight - privacy by design, privacy by default, privacy impact assessments.
In the following series of posts I will go through the main new and changed features of data protection legislation and give some hints how data controllers can prepare and then comply.

Comments

Popular posts from this blog

A Hungarian case about processing data based on law - what are the requirements?

This question can be interesting in respect of the latest change in Hungarian health data processing: doctors performing health on the workplace tests are obliged to upload the entire files to the common health space where access is not as limited as it should be. The concrete case adjudicated by the European Court of Justice concerns the processing of COVID vaccination data, also based on national law. For processing based on a legal obligation to which the controller is subject, Member Statesmay maintan and introduce specific provisions determining more specific requirements and can also describe features of the processing, including measures to ensure fair and lawful processing. Processing of special categories of data (including health data) for reasons of substantial public interest (in any area) or of public interest in the area of public health requires that the élaw should provide for suitable and specific measures to safeguard the fundamental rights and interests of the data ...

Doubts around data transfer - use of derogations

 A lot happened since Schrems-II , among others the European Data Protection Board published a FAQ document , a guidance on essential guarantees for surveillance measures      and submitted another guidance , on measures that supplement transfer tools. Transfer tools are either safeguards which ensure that data subjects enjoy adequate protection of their privacy at the place and in the organisation to where their data are transferred or derogations which enable transfer essentially without adequate protection. I used the term adequate protection and previously the view was that the protection ensured need not be identical with that in the EU. The Schrems II judgment, however, speaks about equivalent protection and this is stronger. In case the derogations (according to article 49 GDPR) are used, the EDPB is of the view that the last sentence of Article 44 GDPR (All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural...

What the games... tricks in cookie banners

 The e-privacy directive and the draft e-privacy regulation prescribe the rules internet sites have to follow in placing cookies. One of the main differences in opinion between the European Parliament and the Council, even within the Council was whether sites can place cookies based on legitimate interest. It is generally accepted that the e-privacy rules  should not be softer than the GDPR requirements. Many data protection experts believe that placing information on the terminal equipment of the user is so intrusive, that it should not be justified by legitimate interest. On the other hand, in case of processing of personal data based on legitimate interest, the user has the right to object - but only based on his/her particular situation. Cookies sometimes are absolutely necessary to provide the on line service. Most of these, maybe all, do not have to be kept after the session is closed (for example those which indicate that the user has been authenticated, which serve tha...