What is GDPR Compliance? | Perimeter 81
What is GDPR?
GDPR fines can wind up costing your organization up to $24 million dollars. Learn how to prevent hefty GDPR penalties and remain GDPR compliant.
GDPR Meaning
GDPR stands for General Data Protection Regulation. It is a set of legal requirements that sets the guidelines for how personal information from individuals living in the European Union is collected and processed. The new privacy regulations apply to all websites that are frequented by European visitors.
As of May 2018, all businesses in the European Union must comply with the GDPR data protection act regulations for data storage or be met with hefty fines. Just to put things in perspective, Google holds the record for largest GDPR fine to date at €50 million or $56.6 million.
What’s even worse is that this fine could have been avoided had the search giant only provided more information on how their data was being processed in their privacy policies. Lack of transparency must be avoided to prevent costly mistakes such as the case with Google.
How to be GDPR Compliant?
To be in GDPR legal compliance, organizations must inform individuals of data being collected about them. The GDPR rules for websites are the same as any brick-and-mortar business in operation.
- The organization must disclose what information is being collected, the purpose for it, and where the information is being stored.
- Organizations must comply with government policies for monitoring and recording and demonstrate accountability.
- Organizations must gain consent to collect personal information and may need to request it again for updates.
- Someone must be in control of this data and safe-keeping it. Organizations may need to appoint a Data Protection Officer (DPO) to oversee these processes and report events.
- Establish policies and processes for reporting breaches. Businesses should put processes in place for detecting, investigating and reporting data breaches and have a plan for responding to threats.
Organizations must make a copy of this information available on request to the person whose information is being kept. The data controller must inform them of a breach in security.
This process also allows the customer of a business the option of opting out of being added to a mailing list. The GDPR also adds a ‘right to be forgotten’ process, which grants additional rights to people who no longer want their information collected and stored. They may be able to have it deleted, provided there is no longer a reason to keep it.
It requires the websites to disclose to visitors that general data about them is being collected and requires their content to share that information with other parties.
This is to protect sensitive data in case of a data breach. Websites collect what is referred to as cookies, which are small files containing personal information like site settings and preferences.
The GDPR key provisions are designed to improve data collection and prevent misuse and security breaches that jeopardize personal privacy.
GDPR Fines and How To Prevent Them
Penalties levied against a company that does not comply with GDPR can range from mild to severe, depending on the infraction. Businesses in the EU have had two years to get up to speed with the GDPR policies. A GDPR non-compliance fine is normally reserved for serious offenses and could face a maximum fine of €20 million Euros.
Depending on the policy not being followed, the business or organization may:
- Be issuing a warning or reprimand
- Be subject to a ban on data processing (temporary or permanent)
- Be subject to restriction or erasure of data
- Be prevented from making data transfers to third countries
For serious violations or infringements, the EU GDPR sets a fine at $20 million or 4% of global annual revenues – whichever amount is greater.
A perfect example of this is the British Airways GDPR fine. British Airways received one of the biggest GDPR fines so far at £20 million by the UK’s data protection authority over a failure to protect data, which enabled unauthorized parties to access personal and payment card information of more than 400,000 of the airline’s customers.
European Privacy Laws
GDPR applies to any organization operating in the European Union. In 1995, the EU passed the European Data Protection Directive with a focus on establishing higher security standards for data privacy.
The Directive (EU) 2016/680 which protects individuals with regard to the processing of their personal data took effect on May 5th, 2016 under the European data protection. Countries in the European Union must abide by these laws or face stringent penalties in the collection of data.
The European Data Protection Board (EDPB) helps keep GDPR regulations up-to-date and acts as a mediator between disputes.
What is The Data Protection Act?
Data Protection Act 2018
The Data Protection Act 2018 provides organizations guidance and best practices on how to use personal data. Organizations responsible for personal data must follow strict guidelines known as the data protection principles. These rules state that personal information must be:
- Used transparently and lawfully
- Held no longer than is necessary
- Kept accurate and up to date
- Used for specific purposes
- Handled in an appropriate manner
It is an organization’s responsibility to keep all forms of data secured. The following is a data security checklist any businesses can follow to remain in compliance with the DPA:
- Ensure password encryption and protection be used when transferring sensitive data. For example, the transmission of highly confidential data from a USB to a laptop.
- Businesses must make sure that their offices are fully locked when no one is there. Many companies have biometric forms of identification when entering the door and security codes in place when unattended.
- Always log off from your computer when not in use to prevent unauthorized personnel from accessing sensitive information.
- Change your password frequently and require all staff to do the same as well.
What is The Role of The ICO in GDPR?
The ICO or Information Commissioner’s Office is the UK’s data watchdog responsible for promoting good practices and upholding data protection privacy laws in regards to GDPR. The ICO is responsible for resolving disputes, conducting investigations into data breaches, and in taking appropriate action when an offense is committed under the GDPR regulations.
The ICO also issues severe fines for companies in violation of the rules. In 2018, tech giant and social media powerhouse, Facebook, was fined £500,000 by the ICO following the Cambridge Analytica data scandal. Since January of 2021, GDPR fines have risen by nearly 40% with penalties under the GDPR totaling over €158.5 million.
The ICO has recently launched a regulatory sandbox where organizations can test products and services against data protection laws, however, it is still in the beta phase.
What Are The 7 Principles of GDPR ?
These are the basic GDPR compliance principles which must be followed by businesses operating in EU member states or engaging with customers residing there. The basic principles are:
- Lawfulness, fairness, and transparency – There must be a valid reason for requesting and storing personal information.
- Purpose limitation – When collecting personal information, you need to be clear about why you’re collecting information and the purpose of it.
- Data minimization – Data should only be collected to fulfill a stated purpose, or be relevant or necessary to process a customer’s order.
- Accuracy – The information being collected and held should be accurate. If there are any mistakes, it needs to be corrected.
- Storage limitation – You should be able to justify holding onto data past a certain point. It should be kept only as long as it is needed.
- Integrity and confidentiality – When storing data, you should have security measures to protect that data from outside parties.
- Accountability – You should have accountability for the information you are responsible for.
This process allows the customer of a business the option of opting out of being added to a mailing list. The GDPR also adds a ‘right to be forgotten’ process, which grants additional rights to people who no longer want their information collected and stored.
Article 12.3 describes the GDPR 30-day rule. Companies must provide information outlining the actions that will be taken by the organization upon receiving a request for the erasure of data.
The GDPR protection principles apply to all businesses and consumers in the European Union and visitors to websites that do business with EU visitors. The protections put in place ensure the secure collection of a consumer’s private information while giving rights to consumers over how their information is used.
Under the new data privacy law, visitors can refuse to allow “cookies” to track them, as well as other policies regarding mailing lists and other means of collecting personal data.