New EU law on personal data protection will come into force
Hi guys!
Have you probably already been notified of any changes to the privacy policy? I received a lot of letters from the services in which I am registered.
Probably many don't understand what is sussano and take these reports with a surprise or worry.
Calm down! In this I article I will explain everything in detail. So ...
What is the essence of the new law and who issued it?
The law is called General Data Protection Regulation, or GDPR. This regulation The European Union (EU) 2016/679 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with respect to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46 / EC (General data protection regulations). It came into force in may 2016 and is mandatory for application in the European Union since may 25, 2018 as a document of direct action and therefore his regulation has the force of law throughout the European Union.
You may think - Well, what do we do here?
The regulation applies not only to EU residents, but also to persons outside the EU processing personal data EU residents in connection with the offer or sale of goods and services to them, or monitoring the actions of data subjects in the European Union.
Obliquely to the websites and materials that are published online, are taken in consideration of such factors:
- One of the EU languages is used
- Prices are formed/payment in Euro is accepted
- Referred customers from the European Union, etc.
Can we elaborate? Of course!
GDPR introduces the concept of the CONTROLLER and PROCESSOR personal data's.
The CONTROLLER is a natural or legal person, public authority, Agency or another body that, alone or in Association with others, determines the purposes and means of processing personal data.
The CONTROLLER shall comply with the following rules:
- Cooperate with data processors in certain cases
- Maintain records
- To assess the impact of personal data processing on the rights data subjects for some types of data processing
- Implement data protection mechanisms
- At the time of collection of personal data to provide data subjects with full information about the purposes of personal data collection, the rights of data subjects if possible, notify national protection authorities within 72 hours data Protection Authorities (DPAs) on personal data leakage detection data, and relevant subjects of personal data.
The PROCESSOR is a natural or legal person, a state body that processes personal data on behalf and on behalf of the controller.
The handler is obliged to execute the following rules:
- Maintain a written register of operations on processing of personal data performed on behalf and on behalf of each controller
- If the handler does not have a representative in the European Union, he is obliged to appoint such person in certain cases
- Notify the controller of personal data leaks without delay
participate in cross-border data transfer activities.
It is unclear who is obliged to follow all these rules? The regulations are binding on all companies that collect, store or processing personal data of EU residents, it's controllers and data processors, regardless of the location of such controllers and handlers.
The regulations expressly prohibit, under the threat of penalties, the movement of personal data of EU residents to countries outside the European Union, if the European Commission is not recognizes these countries as having an adequate level of personal data protection.
Such countries are recognized:
Liechtenstein
Norway
Iceland
Andorra
Argentina
Canada
Israel
Isle of man
Faroe Islands
New Zealand
Switzerland
Uruguay
USA
Is it necessary to comply with the new law of the European Union? The principle of the Regulations is its enforceability, if there is no possibility to bring to the responsibility of the controller or processor provided for by the Regulations personal data in a certain country, processing of personal data residents of the European Union would be illegal.
What penalties are provided for non-compliance with this law?
The law comes into force on may 25, 2018 and provides for significant sanctions for its violation in the processing of personal data of EU residents, namely up to 20 million euros or up to 4% of the annual turnover of the company.
The requirements of the Terms of use apply far beyond the content of the privacy policy posted on any website.
Yes, very large fines. How not to get caught?
At a minimum, we recommend that you fully comply with the GDPR:
- Compliance with the requirements of the local legislation of such country on the protection of personal data, including obtaining advice from the local authority for the protection of personal data.
- The appointment of internal or external inspector for personal data protection (DPO, its necessity must be evaluated in the course of consultations on the spot.
- Develop a Privacy policy with the requirements of the GDPR.
- Development of a system of notifications and obtaining users ' consent on the basis of a preliminary audit of the service.
- Development, implementation and description of the system of technical protection of personal data (in internal regulations and instructions).
- If your company is located in the CIS countries, it is recommended to transfer ownership of the project to a resident of one of the EU countries to comply with the new regulations.
All these measures should be implemented in a complex.
Non-compliance of your service with the requirements of the GDPR could potentially entail sanctions both on the owner of the service and its customers-employers, in amounts critical to the business.
What will change with the entry into force of the law from may 25, 2018?
If data processing is significant (criterion not clarified in the law), GDPR requires the controller or the processor of the destination internal or external inspector for personal data protection (DPO), brings to the job specific requirements of competency and impose personal responsibility for the implementation of Regulations. If you are unable opredelila with the criterion scale, you can take the measure of one of the early projects GDPR treatment from 5000 entries or 250 employees.
The GDPR strictly regulates the procedure for obtaining the consent of users to the processing of Personal data at the time of their collection, the procedure for revocation and a number of other rights.
One of the rights of the user is the right to file complaints to the Supervisory authority of one of the European Union countries for the protection of personal data, and the text of the Privacy Policy should clearly indicate this Supervisory authority and its contacts. In addition, as a data processor, the site owner is obliged to notify such Supervisory authority of data leakage within 72 hours.
The GDPR requires protection systems and technical regulations for the protection of personal data.
If the project owner or data processor is outside the European Union and processes the data on a regular basis, the GDPR requires the appointment of a permanent representative of the processor in the EU.
Can I download the document?
Yes! Download GDPR now!
Thank you for reading to the end!
Until next time!