The introduction of the General Data Protection Regulation (GDPR) has set the web abuzz. This project, which has been in the works for two years now, came into force on 25 May 2018. Should we be wary of the GDPR? Is it really that complicated to be compliant?
What is the GDPR for? What does it actually contain?
The GDPR protects internet users’ privacy by securing their personal data. Here, factually, are the main pillars of the GDPR:
- Transparency about the terms of data use: companies must explain to you why they are using your data, what they are going to do with it, how long it will be kept and, above all, you will have to give your consent to its use.
- Signing up to a social network is now possible from the age of 15 (below that, you will need parental authorisation).
- Data portability: this new right allows you to transfer data out of a platform (social network, messaging service, cloud, etc.).
- Access to personal data: every company must give you access to the data it holds about you. You can ask for it to be deleted or withdraw your consent at any time.
Is my company at risk because of the GDPR?
Being GDPR-compliant costs time and money, which is a problem for micro-businesses and SMEs. However, the European Association of Craft, Small and Medium-Sized Enterprises (UEAPME) requested a one-year grace period before sanctions were applied to companies (the time needed to bring their organisations into line with the law).
According to the CNIL, to be fully compliant, three types of organisation must appoint a DPO (Data Protection Officer):
Public bodies, and companies “whose core activity leads you to carry out regular and systematic monitoring of individuals on a large scale, or to process so-called ‘sensitive’ data, or data relating to criminal convictions and offences, on a large scale.”
This means that as soon as you record user data (through Google Analytics, for example), it is advisable to appoint a DPO (internally or externally) in order to avoid any form of sanction.
If your company uses user data, you will need to complete 6 steps to be fully compliant (according to the CNIL):
- Appoint a DPO
- Map your personal data processing activities
- Prioritise the actions to be taken (make sure that only the data essential to your objectives is processed, identify the legal basis for the data, ensure that your subcontractors are aware of your new data management policy, etc.)
- Manage risks (carry out a data processing impact assessment in order to demonstrate that your new data protection policy complies with the GDPR). Set up data protection processes
- Produce documentation on data protection and GDPR compliance
For companies, the GDPR makes it possible to establish transparency with users about how their data is used. This law can therefore help build a climate of trust between professionals and their customers. So this regulation is not risky for companies, but it can cost money and, above all, time.
For users, the GDPR is highly advantageous: data is now kept only temporarily, and you can access it on any platform at any time and delete or modify it.
To keep up with all the latest web and development news, take a look at our other articles.