On May 25, 2018, the GDPR (General Data Protection Regulation) will take effect. It appliesto “the processing of personal data, whether fully or partially automated, as well as the non-automated processing of personal data contained in or intended to be included in a file.” This is a European regulation—Regulation (EU) 2016/679—that applies to all companies and organizations based in Europe.For organizations with fewer than 250 employees, the requirements are less stringent —the record of processing activities is not mandatory, unless the data processing poses a risk to the rights and freedoms of individuals—see Article 9.
The purpose of this regulation is to ensure that citizens enjoy a high level of protection for their personal data.
How do I do that?
The first step is to conduct an inventory within each company of existing files and the information (personal data) they contain—customers, prospects, suppliers, employees, job applicants, etc. What information is truly useful for the organization’s operations? What information is obsolete or unnecessary? What information needs to be updated?
The CNIL provides a sample form:https://www.cnil.fr/fr/modele/mention/formulaire-de-collecte-de-donnees-personnelles
Next, you should sort through the data and take this opportunity to optimize your practices —for example, by drafting standard operating procedures for each department involved in managing a database and retaining only the relevant information. Be sure to keep a record of all this audit and update work.
Next, when contacting third parties for whom you maintain a database, you must inform them and allow them to exercise their rights.
Finally, you must secure your data —ensuring IT security both internally and in your interactions with any subcontractors used to process this personal data.
For more information, see the guide below, which was developed in collaboration with the CNIL:https://www.cnil.fr/sites/default/files/atoms/files/bpi-cnil-guide-rgpd-tpe-pme.pdf
Paradoxes!
At a time when BIG DATA is on the rise and artificial intelligence is learning to gather, combine, and identify data that is useful to businesses, this European regulation restricts access to information. Granted, the goal is to protect personal data, but don’t social media platforms make that data freely available anyway?
At the same time, the prior authorization system—which previously required a request to the CNIL when creating a personal data file—has been eliminated—a simplification! The new system, established by this mandatory regulation, is designed to operate on a self-regulatory basis. This does not preclude very high penalties —ranging from 2 to 4 percent of revenue!
So, we’ll simplify things, and then transfer the responsibilities to organizations and companies. It’s up to them to get organized—with severe penalties for noncompliance! After all, ignorance of the law is no excuse, right?
The GDPR therefore requires companies to optimize their practices and introduces a new risk and a few more responsibilities!
