EU’s General Data Protection Regulation (GDPR)
EU’s General Data Protection Regulation (GDPR) THE EU’s General Data Protection Regulation comes into force on 25 May 2018. All companies, including international firms, doing business with individuals located in EU member nation territory must comply. The principles are similar to those already in the Data Protection Act, with an added new accountability requirement. The new law will require all businesses to show how they comply with the principles, for example, by documenting decisions taken. What impact will this new regulation have on your company? Data Protection of the Individual Cloud, Internet of Things (IoT) and mobile computing have all added to the challenge of sharing, managing and securing information. The GDPR tries to help add further layers of control and accountability to protect the misuse of personal data. Some of the new obligations of GDPR include:
- Right to obtain and access data, allowing individuals to request access to data held about them and how that data is held and used.
- Right to deletion, giving individuals the right to have personal data removed.
- Consent to collection of personal information, ensuring organisations gather information with explicit consent of the individual and are able to prove that they have done so.
- Right to rectification of and objection to information being used for profiling that may result in discrimination.
- What types of personal data you are holding.
- How you are holding that information and how it has been obtained – relying on silence or pre-ticked boxes will not be acceptable.
- Why you are holding the information, and what your retention/destruction policies are.
- Where the folders holding the electronic files are located.