This data protection regulation extends the scope of the law to all companies, even foreign companies, who are processing data of EU citizens and residents. The net effect will be to strengthen the rights of EU citizens and residents over their personal data and shift the responsibility of how data is collected, held and processed from the individual to the organisation.
The regulation has real teeth with severe penalties, in some instances up to 4% of worldwide turnover. The regulation came into effect on the 25th of May 2018, so the clock is ticking. You now have only a year to put systems in place to ensure your initial compliance with the regulation and your continued compliance into the future.
There are three principal areas you will need to address to become compliant with the legislation:
Once compliant, there are ongoing regulatory responsibilities to ensure that personal data that you store or process will be:
Compliance is not a once-off, but an ongoing, exercise. Carve out the time now and do the groundwork needed to create and implement systems that will last your organisation into the future and secure its regulation compliance as it grows.
While some companies will be appointing a data protection officer to help with the process, others will use a consultant or an external service provider that will assist in managing the process to becoming compliant.
Image credit: www.welivesecurity.com