MAPS® now offers our clients a full GDPR consultancy compliance service – working directly with our clients to ensure they become GDPR compliant. This includes training on what GDPR means for businesses and organisations, to providing qualified data protection officers (DPOs) who will carry out data impact assessment reports. After putting together an initial compliance report, our DPOs will then return to give regular audits on compliance throughout the year. In this way, MAPS® can ensure that businesses and organisations are fully compliant.
What is the GDPR?
The General Data Protection Regulation (GDPR) is the new framework for data protection laws which will be standardised across the EU and EEA. The regulation is designed to give individuals greater protection and rights when it comes to the collection of data on citizens in EU countries and in third countries where there are links with EU business operations.
So in essence, the GDPR is the first global attempt at introducing standards for consumers rights online.
The GDPR comprises 99 articles that set out the rights of individuals and the obligations on organisations to carry out compliance according to the regulation.
GDPR in a nutshell
- It gives EU citizens more control over their personal data, making it easier to access it, delete it and transfer it.
- Companies and organisations must obtain specific consent to use or share people’s data. This includes retail consumer data as well as data held on a B2B basis. With all the stored data, companies must provide details of how this data will be handled.
- Consumers have a right to have their personal data kept safe. There is also a right to complain if data is mishandled or misused and people also have a right to know if their data has been hacked.
- The GDPR places a huge emphasis on accountability by businesses and organisations, which will have to demonstrate compliance with the principles. This will involve maintaining written records of all data handling activities and implementing and maintaining a proactive approach to data protection.
- Data protection officers (DPOs) will need to be appointed by companies where the core activities of the business requires regular monitoring of personal data on a large scale. It’s important to remember that a DPO has to be impartial and independent, reporting directly to the CEO and the ICO. It’s ultimately their duty to whistle blow on the business if they’re recommendations are ignored.
- The GDPR has expanded territorial reach and companies outside the EU which are targeting consumers in the EU will be subject to the GDPR.
- If an organisation or company has had a data protection breach, internally or externally, they will have 72 hours from identifying the breach to report it to the ICO.
Access to your data
As well putting new obligations on the companies and organisations collecting personal data, the GDPR also gives individuals a lot more power to access the information that’s held about them. When someone asks a business for their data, they must divulge the information within one month. Everyone will have the right to get confirmation that an organisation has information about them, access to this information and any other supplementary information.
The new regulation also gives individuals the power to have their personal data erased. This includes where it is no longer necessary for the purpose of why it was collected, if consent is withdrawn, if there’s no legitimate interest, and if it was unlawfully processed.
GDPR fines
If an organisation doesn’t process an individual’s data in the correct way, it can be fined. If it requires and doesn’t have a DPO, it can be fined. If there’s a security breach, it can be fined.
These monetary penalties will be decided upon by the ICO and the GDPR states smaller offences could result in fines of up to €10 million or two per cent (2%) of a firm’s global turnover (whichever is greater). Those with more serious consequences can have fines of up to €20 million or four per cent (4%) of a firm’s global turnover (whichever is greater).
Which companies does the GDPR affect?
Any company that stores or processes personal information (private or commercial) about EU citizens within EU states must comply with the GDPR, even if they do not have a business presence within the EU. Specific criteria for companies required to comply are:
- A presence in an EU country.
- No presence in the EU, but it processes personal data of EU residents.
- More than 250 employees.
- Fewer than 250 employees but its data-processing impacts the rights and freedoms of data subjects, is not occasional, or includes certain types of sensitive personal data.
Who within a company will be responsible for compliance?
Companies are required to have a DPO if they process or store EU citizen’s data, process or store special personal data, regularly monitor data subjects, or are a public authority