
The new European General Data Protection Regulation ( GDPR ) has had a difficult journey since it was presented in January 2012. Today, more than 6 years later, it is just days away from its effective implementation, after the two-year grace period offered by the text has practically expired
That is why we believe it is a good time to remember the basic characteristics of the GDPR, as well as see how this new text, which aims to be an updated response to protect privacy and overcome the obsolete Directive from way back in 1995, may affect you.
GDPR, a single standard for 28 member states
One of the main features of the GDPR is that it will be directly applicable in all EU Member States. This aims to harmonize both the rights of individuals and the obligations of those who collect and process their data. This makes sense, as it is unusual for the Single Market to have different obligations depending on the Member State of residence of data subjects or those obligated to comply with the law.
I already comply with the LOPD (Spanish Data Protection Law), what do I have to do?
If you have done your homework and comply with the LOPD, how does the GDPR affect you?
- You should review their privacy policies. The GDPR requires you to provide additional information such as: the period for which the data will be processed, where complaints can be lodged, and the identity of your DPO (if you are required to appoint one).
- Don't hide consent for data processing in the middle of endless legal texts. Clearly state that the user is giving their consent and explain why they are doing so.
- Apply the Right to be forgotten and data portability.
- Establish an internal system to report incidents to the Spanish Data Protection Agency and, in some cases, to those affected by such incidents.
- Appoint a Data Protection Officer (DPO) if you process sensitive data on a large scale or monitor people's behavior. These are broad concepts that will need to be further defined.
- Apply privacy by design or by default principles . Put user privacy at the heart of business decisions, for example, when designing an app or implementing time and attendance systems. In some cases, you will be required to conduct a Data Protection Impact Assessment .
- Train your staff.
How much time do I have?
Its effective date is set for May 25, 2018, meaning that if the transition period established by the regulation for adaptation has not been used, urgent action will be necessary. The GDPR is a significant challenge, especially for companies that not only "comply with the LOPD" (Spanish Data Protection Law) but also have a genuine policy of respecting personal data. It implies changing processes, decision-making methods, and ultimately, implementing an effective data protection culture that must become a key competitive advantage for the organization.
If you need help implementing or adapting your company's data protection regulations, please contact us. We'd be happy to assist you.
Victor Roselló Mallol
Do you have any questions about this topic?
Our team of expert advisors will help you resolve any issues related to our services.
Contact us now
A Àmbit Assessor, SL has 40 years dedicated to the tax, comptable and labor consultancy of the Pime.
Latest entries from MGI Àmbit
(see all)
Related