GDPR is a highly topical issue these days

calendar
author Ius Aegis
GDPR je v týchto dňoch vysoko aktuálna problematika

In 2018, it looks like May will be a little different than we are used to. It will be time to implement GDPR, which is a complex and serious topic. If everything is to be done properly and in accordance with the law, it is high time for companies to prepare now. Training responsible employees and implementing processes takes time, and there is no time left until May.

What is GDPR and what led to its creation?

Rapid technological development and globalization have brought with them new challenges in the area of personal data protection. The scope of collecting and sharing personal data has increased significantly. One of the most important legislative changes in the business environment in 2018 is the new EU Regulation No. 2016/679, the so-called GDPR (General Data Protection Regulation), which will enter into force throughout the EU from 25.05.2018The primary objective of the GDPR is to ensure a high level of protection of the personal data of natural persons, regardless of where and under what circumstances the data is processed.

GDPR considers it personal data such information that can directly or indirectly identify a specific natural person. Typically, personal data are first and last name, birth number, ID card number. Some data, such as e-mail and telephone number, may or may not be personal data. It depends on whether, based on them or their combination, it is possible to determine directly or indirectly (with the help of a third party) what kind of person it is. The category of personal data also includes various pseudonymized data, where there is a possibility of identifying a person through third parties. Other personal data may include:

  • Photography,
  • Fingerprint,
  • Voice,
  • Account number,
  • Location data
  • other technical data, such as IP address or cookies

While some personal data is processed on the basis of law or in the context of fulfilling contractual obligations, other data is obtained by entrepreneurs based on the consent of the data subject. Such According to the GDPR, consent must be specific, free, informed and unambiguous (i.e. it cannot be part of the terms and conditions), and the entrepreneur must be able to demonstrate at any time that consent to the processing of personal data was actually granted.

While fines under the original Personal Data Protection Act reach a maximum of EUR 200,000, GDPR provides for fines of up to EUR 20,000,000, or up to 4 trillion of global annual turnover, for violations of personal data protection obligations.

Directive 95/46/EC of the European Parliament and of the Council ( 3 ) applies to all processing of personal data in the Member States, whether in the public or private sector. It does not, however, apply to the processing of personal data in the framework of activities falling outside the scope of Community law, such as activities in the field of judicial cooperation in criminal matters and in the field of police cooperation.