GDPR Deadline Is Looming

law photo

The date on which companies need to be in compliance with the General Data Protection Regulation (GDPR) is approaching fast. Find out when this deadline is and what it means for businesses worldwide.

 

Passed by the EU Parliament in 2016, GDRP is designed to provide data privacy rights to EU citizens and protect them from data breaches.  This legislation spells out numerous requirements that companies must meet:

  • Businesses must get customers’ consent to collect, process, and store their personal data. When companies ask for permission, they must use easy-to-understand terms rather than legal jargon.  Plus, it must be easy for customers to withdraw their consent.
  • Companies can only collect, process, and store the personal data needed to complete a given task and not any extra information. Further, the data collected and stored for one task cannot be repurposed without further consent from customers.
  • Businesses must notify customers within 72 hours of first becoming aware of a breach that involves their personal data.
  • Companies need to include data protection measures when they are initially designing their systems rather than adding the measures later on.

All companies that collect, process, or store the personal data of EU citizens are required to comply with GDPR’s requirements, no matter where the organizations are located.  For instance, US and Canadian business that have customers who live in the European Union must adhere to the regulation.

The penalties for non-compliance are high.  The maximum fine, which is reserved for the most serious violations, is €20 million (around $24 million USD) or 4% of a company’s annual global turnover (whichever is greater).  The fine structure is tiered, so smaller fines will be levied for less serious infractions.

There are resources available to help businesses understand the GDPR requirements.  The official website, EUGDRP.org, has an extensive list of articles, videos and other types of resources.  Its sister site, EUGDRP.com provides GDRP updates and news.

Some IT Vendors also offer GDRP resources, many of which are free.  Here are a few examples:

  • Microsoft provides an e-book, an online readiness assessment, webcasts, and whitepapers.
  • Trend Micro has an infographic, checklist, whitepaper, and webinar
  • IBM furnishes an e-book, webinars and whitepapers.
  • IT Governance offers a video, infographic, paper, and templates.

Many blogs and articles are also available to help companies understand GDPR.  Ask us at info.pccorp.com, we can help you find more resources on GDPR.

Small Business

Education

Government

Enterprise