What is GDPR?

The European Parliament adopted GDPR in April 2016, replacing a data protection directive approved in 1995. The new law carries requires businesses to protect the personal data and privacy of EU citizens for all data transactions. The GDPR also regulates the export of personal data outside the EU zone.

Who does GDPR apply to?

It applies to any organization that collects and processes data of EU citizens, even if the processing is done outside of the EU. GDPR classifies organization as ‘controllers’ or ‘processors.’

  • Controllers: Any natural or legal person, public authority, agency or other body which determines the purposes and means of the processing of personal data
  • Processors: Any natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Penalties for violations:

Article 83(5) of GDPR, DPAs would be able to impose fines of up to €20M or 4% of the offending company’s total worldwide annual turnover of the preceding financial year, whichever is higher.

Key Features of GDPR:

  • Fines of up to €20M or 4%
  • Mandatory Privacy Impact Assessments (PIA)
  • Privacy by Design by Default
  • 72 Hour Breach Notification
  • Mandatory data erasure and portability
  • Consent for Personal Data Profiling.
gdpr key features

How to approach GDPR?

Developing a framework to ensure your organization is complaint with GDPR is a must. Like many large-scale initiatives, go with a phased approach.

Phase 1: Develop

  • Identify senior stakeholders and engage with each business unit affected.
  • Make an inventory and analyze the personal data held by your organization.
  • Allocate adequate resources.
  • Verify GDPR procedures to ensure the rights of EU individuals are covered.
  • Review how consent is obtained and recorded.
  • Designate a Data Protection Officer (DPO) for your organization.

Phase 2: Implement

  • Conduct a gap analysis and develop project plan to meet the data protection requirements set forth by GDPR. Two important areas are: data protection impact assessments (DPIA) and subject access requests (SAR).
  • Implement procedures to detect, report and investigate personal data breaches.
  • Test and deploy all controls and solutions developed to achieve compliance.
  • Develop an internal GDPR audit plan.
  • Operationalize the efforts of monitoring all data protection controls created.

Phase 3: Monitor and Improve

  • Monitor and improve regularly if necessary.
  • Conduct reviews and set maintenance and update processes in place for GDPR.
  • Improve controls and build trust with customers.