In News / Updates

GDPR: secure your data and those of your users by the 25th of May

12 April 2018
20180412 GDPR

One of the main issues discussed these days is the amount of personal data that we all have communicated to social media (willingly or not), which are suspected not to have used them in conformity with the law. With regard to this, there’s a new crucial regulation that is going to be applied very soon, but many companies seem not to be ready yet.

We are referring to the General Data Protection Regulation, (UE) Regulation 2016/679 which will enter into force on the 25th of May 2018.

 

To whom does the GDPR address?

To any company that owns and gather the data of citizens of the European Union, be they clients, prospects, employees or suppliers. 

 

What should my company do not to incur penalties?

 

  • Make an inventory of your policies and check how they might change according to new rules. Understand what it concretely means to have to specify the data source and retention period.
  • Analyze what data you have at your disposal and make an up-to-date mapping of them.
  • Use a sentinel software to manage the new obligation to notify violations in the use of personal data and to check the possible extra European flux of data using cloud services.
  • Experiment privacy by design (i.e. think about protection of personal data since the design and data gathering phases) and do the Privacy Impact Assessment, entrusting competent experts that might help the company minimize the impact and reduce management costs. 
  • Experiment new forms of visual policies based on icons. Analyze what data you have at your disposal to have an up-to-date mapping.
  • Think about introducing a Data Privacy Officer (DPO) in your company.
  • Analyze the effects of the right to data portability and take organizational precautions to avoid serious impacts on the stability of the company databases. Define new rules for the acquisition and documentation of consent.
  • Verify the data suppliers with care. This is the moment for tests, tests, and tests. 
  • Check if you are dealing with minors’ data, keeping in mind that the new rules oblige to manage also the consent of those who exercise the parental authority with the consent of minors under 16. 

 

What if I am not ready?

From the 25th of May you might be subject to penalties up to 20 million euros or up to 4% of your company's total turnover.

 

Don't panic!

We are here to help you: give us your contact details, specifying the type of business. We will put you into contact with our consultants.

Click here to contact us!