The General Data Protection Regulation, known by the abbreviation GDPR, requires businesses to take measures to protect the personal information they store or process. Failure to comply will be costly. Here's what organizations need to know. Companies that have data of EU citizens will have to comply with the strict rules that are coming. The regulation will establish a new standard for protecting consumers and the personal information they provide to businesses. Companies will have to organize their systems and processes so that they meet legal requirements. Questions and new expectations are being raised for IT departments. For example, GDPR expands the concept of personal data.
Companies will have to ensure protection of IP addresses, information from “cookies” at the same level at which they protect the name, address and PIN - that of their customers. A large part of the requirements are subject to interpretation, i.e. they are left to the companies' understanding, without giving precise instructions on how to proceed. GDPR stipulates that they must provide a “appropriate” (reasonable) level of protection of personal data, but does not define the concept. This gives regulators a great deal of latitude to impose fines in the event of a data breach or non-compliance. Many of the requirements appear to have no relevance to information security at first glance. However, a closer look at the regulation, such as the fact that business processes and information systems (especially old ones) must comply with the new measures, will require a review of existing security protocols. The regulation’s requirements will force many companies to change the way they process, store and protect customer data.
This is only allowed if users have given consent, but users’ personal information is not kept until the reason for which it was collected no longer applies. For example, if a contract with a customer has expired and the law does not require the data to be kept, it must be deleted. Personal information of individuals is subject to transfer from one company to another, but upon request by the person whose personal data it is, it must be deleted. The latter is also known as the “right to be forgotten”. There are exceptions – if legally required, the organization can keep the data (in cases of payroll, credit file). Some requirements have a direct effect on IT security. The regulation provides that companies must ensure an “appropriate” level of data security, but it does not specify what is meant by “appropriate”. Companies are also obliged to report any data leak to the national supervisory authority and to the individuals affected by it within 72 hours of the breach being detected. Businesses will be required to carry out impact assessments, help reduce the risk of breaches by identifying vulnerabilities and developing a strategy on how to deal with them. Companies that provide recruitment and human resources assessment services will be most affected. If a company with a similar line of business is caught not meeting the requirements, it will face not only a fine, but also the loss of part of its business. Mechanisms to ensure the security of personal data include encryption. This is important for companies that process a large amount of sensitive data, such as healthcare facilities, utility companies, mobile operators, internet and cable TV providers, banks and insurance companies. There are various ways to achieve GDPR compliance, keeping in mind the accountability principle enshrined in the regulation, and documenting the steps they have taken to meet the requirements. Law firm “Causa Legis” offers you two types of measures that are consistent with your personal GDPR policy:
1. Preparation of a detailed package of measures, which includes a research and detailed documentation on GDPR, a detailed consultation period on technical and legal issues, as well as the introduction of the features in your company.
2. We also offer you the option of receiving basic GDPR documentation. This includes forms of the main documents: company rules, technological measures and declarations of consent.
This article examines some aspects of the topic and does not represent full analysis of the problem.
Author: Petya Stoevska, Dr. Sc
The site uses cookies 🍪 If you continue to use our website, you agree to the use of these cookies.