On 25th May 2018 the current Data Protection Directive (DPD) will be replaced with the General Data Protection Regulation (GDPR).
In December 2015, the EU announced that the GDPR was being implemented in place of DPD. The DPD was first established over 20 years ago, but it has not kept up with the changes in information technology and is no longer sufficient for today’s technologies and threats. The shortcomings of the DPD have become apparent and the EU saw the need to replace it. The UK has also agreed to adhere to these new regulations even after Brexit.
A defining change which comes with the launch of GDPR is a shift from a directive to a regulation. DPD was a directive, meaning a set of rules issued to member states, but each country can interpret and implement the rules differently. GDPR is a regulation, which requires countries to implement the regulation without any scope for varying interpretations. It removes any ambiguities on organisations’ data protection responsibilities. GDPR paves the way for data privacy as a fundamental right for EU citizens. The implementation deadline for the regulation is 25th May 2018, and organisations must implement the necessary policies, procedures, and systems to ensure they are compliant before that date.
Although it is an EU regulation, it is not limited to the EU. GDPR will affect organisations on a global scale. The regulation will apply to any organisation that offers goods or services to EU citizens. If a company based outside the EU is storing, managing, or processing personal data belonging to EU citizens, they will need to ensure GDPR compliance (GDPR Article 3, page 110). According to a recent PwC study, a staggering 92% of US multinational companies have listed GDPR compliance as data-privacy priority. A significant percentage of those organisations’ plan to spend $1 million or more on GDPR.
Data controllers vs. data processors
Controller – “The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.”
Processor – “A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.” (Article 4, GDPR page 112)
Under the DPD, data processers had very little responsibilities to comply, whereas GDPR places joint responsibility for both data controllers and data processors to comply with the regulation. As an example, if an organisation (controller) outsources its payroll to an external payroll company (processor), even though the payroll company is managing and storing data on behalf of the controller, they are now both required to comply with GDPR. This will impact controllers and processors alike. Controllers will have to conduct reviews to ensure their processors have a framework in place to comply with GDPR. Processors will have to ensure they are compliant.
The Data Protection Directive didn’t require organisations to notify authorities of any data breaches. GDPR defines a personal data breach as the “accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.” It’s worth remembering that personal data now includes IP addresses, web cookies, unique devices identifiers, and more. The GDPR also now requires organisations (or controllers, as they are known in GDPR) to report data breaches within 72 hours. If this deadline is not met, you will have to explain the reasons for the delay. If you are a data processor, you must report the breach to the controller. The controller then notifies the “supervisory authority.” Data subjects must also be informed when a breach poses a high risk to their rights and freedoms. However, if the controller had implemented protection measures such as encryption on the data, then the data subject’s rights and freedoms are unlikely to be at risk.
If your organisation is not compliant with GDPR, it can receive fines of up to €20 million or 4% of global annual turnover for the preceding financial year (whichever is greater). These penalties apply to both data controllers and processors.
The GDPR deadline is fast approaching. GDPR compliance will require significant effort from both data controllers and processors. There are several steps required to get started with GDPR, which include (but are not limited to) performing an analysis of what personal data your organisation stores and where it’s stored, reviewing existing IT security policies and procedures, and ensuring you have the necessary technological and organisational procedures in place to detect, report, and investigate personal data breaches.