GDPR - Is your company ready?
There is very little time left before 25 May 2018, the date by which it will be mandatory to have adopted the GDPR, i.e. the General Data Protection Regulation (EU Regulation 2016/679).
Is your company ready for the GDPR?
If the answer is “NO” or “I don't know what the GDPR is”, then you had better take action right away, because the fines for those who fail to comply can reach up to 4% of annual turnover.
What is the GDPR?
The regulation was promoted by the European Commission and will affect all European companies, and also non-European ones, that handle the personal data of European citizens.
The GDPR covers several points, but in short you will need to pay attention to:
Consent - the request for consent to data processing must be clear and understandable, and must avoid hard-to-understand legalese. Essentially, the user must give authorization with full understanding of what they are allowing to be done. In addition, the user must subsequently be able to withdraw or restrict that consent.
Data security - the data controller must be able to guarantee a good level of security for such data. In other words, if a company holds an individual's personal data, it must do so with a high level of security. To meet this requirement, it is certainly a good idea to turn to providers who can support us in this respect. For example, Google offers G Suite (i.e. corporate email and storage) and Google Cloud Platform (servers hosting corporate software), guaranteeing full GDPR compliance. In this regard, I invite you to download a Google Cloud white paper on the GDPR.
Data breach notification: should a data breach occur, the controller must report it to the authorities within 72 hours of discovering the breach
Right to erasure, i.e. the milder version of the already well-known right to be forgotten. Essentially, if a user asks to have their data removed from a company's information systems, that company must be equipped to do so. Of course, this does not apply to documents that must be kept by law (e.g. Invoices).
Data portability - if the user requests it, the data controller must be able to export, in a commonly used format, all of that user's personal information, so that they can transfer their data from one IT system to another.
Pseudonymisation - a complex term that essentially means encrypting the user's identity. In this way a company can hold information about John Doe without the system's users knowing that this information is actually linked to John Doe.
Some of the points listed above can be implemented without any particular technological measures (e.g. Breach Notification), but others require compliant IT tools (e.g. Google Cloud) and the involvement of IT consultants (e.g. Portability and Pseudonymisation).
We at Open Gate are more than willing to help your company in this respect.
Contact us and together we will plan a strategy and a road map to reach the 25 May finish line prepared.
