GDPR - key changes and novelties - infographic

06 lipca 2016

Traditionally, May is a stressful time for high school graduates, but May 2018 will also be challenging for entrepreneurs and public institutions. It is worth starting to consider now how to prepare in order to avoid unnecessary stress... What is it about? It is, of course, about the regulation adopted by the European Parliament concerning the harmonization of personal data protection laws across all 28 member states.

Infographic GDPR - DPO 24This regulation introduces a series of novelties and changes, which we illustrate in the infographic beside.

What do they concern? Here is a brief introduction.

1. Expanded framework

The interests of citizens have been better protected. Already at the stage of collecting our data, the data controller (ADO) will be obliged to provide information about the right to data portability, the retention period, the intention to transfer them to third countries, etc. We should also receive contact details for the Data Protection Officer (DPO).

2. Records of processing activities

It will no longer be necessary to register personal data sets with the Polish DPA. Instead, there is an obligation to maintain records of processing activities within the organization.

3. New obligations for processors

Data processors, i.e., individuals or organizations that processed data on behalf of the ADO, will also be required to maintain the aforementioned records. In certain circumstances, they will also be obliged to appoint a Data Protection Officer (DPO).

4. Change in the status and role of the ABI

This is a significant change in the context of the division of employee responsibilities and staffing solutions. Currently, there is no obligation to appoint an information security administrator (ABI), and the EU regulation changes this. The nomenclature will also change - from May 2018, the ABI will become the Data Protection Officer (DPO).

Individuals whose data will be processed will have the right to contact him regarding matters related to personal data processing. The DPO will also be obliged to cooperate with the Polish DPA.

More information in the GDPR area

5. Sensitive data

These have been more precisely defined by the legislator, and additionally, the set has been expanded to include genetic and biometric data.

6. Increased rights

This concerns the right to erasure (previously referred to as the right to be forgotten) and the right to data portability, which has become popular recently in connection with the activities of internet giants such as Google and Facebook.

7. Proactive approach

We are talking about preparing appropriate safeguards and procedures before data collection and processing even begins. This includes both training and preparing employees who will work with data, as well as technological solutions at the appropriate level (software and hardware, software design, and its appropriate default settings). A new concept is "privacy by design," which means designing solutions in such a way that they incorporate appropriate data protection from the early stages of development.

8. Reporting Data Breaches

It may sound strange, even absurd, but the regulation requires one to "report" on oneself when personal data is breached. At the moment we admit to having made a mistake, we can expect to be treated more leniently by the Polish Data Protection Authority. Moreover, in some cases, it will also be necessary to inform the individuals whose data has been breached (e.g., clients).

9. Penalties

The penalty system has been significantly expanded, with the upper limit set at 20,000,000 euros or 4% of the total global annual turnover from the previous year. This seems to be a really strong motivation to secure personal data.

10. Facilitation

This pertains to capital groups that will be able to simultaneously administer the same data. However, it will be necessary to specify who is responsible for what within a specific entity.

11. Profiling

It has been legally regulated - until now, there were no rules regarding the creation and use of such information.

12. Children

This is a kind of nod to parents, who will be able to "decide more" about their children's presence online, particularly on social media.

In addition to the infographic, we have prepared an animation that briefly discusses this topic:

We invite you to a practical GDPR Training.
What will change with the Regulation of the European Parliament and Council regarding the protection of natural persons in relation to the processing of personal data and their free movement? Why is it worth starting preparations for the new regulations today? Through this training, you will learn what changes await you and how to prepare for them.

Preparing for GDPR is a complex process that requires extensive knowledge from many fields; we have prepared a service for you to support GDPR implementation.
This service includes:

  • audit
  • risk assessment
  • process adjustment
  • dedicated documentation
  • staff training

We also encourage you to familiarize yourself with the guide on key issues prepared by the Knowledge is Safety Foundation.

GDPR. Support is useful!

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.