GDPR: Websites, Data, and the New Legislation

The acronym GDPR (General Data Protection Regulation) may still sound distant to you, even though we are only six months away from its official launch. However, from May 25, 2018, it will mark a turning point in terms of data protection.

Why?
Companies have known what it means to be custodians of our clients’ data since the LOPD (Organic Law on Data Protection) came into force in 1999.  From that moment on, we took responsibility for our clients’ data, with the obligation to report it to the AEPD (Spanish Data Protection Agency). The main objective of the LOPD was to regulate the processing of personal data and files, regardless of the medium in which they are processed, the rights of citizens over them, and the obligations of those who create or process them.
Legislators and successive governments must have thought this was sufficient protection for individuals. And all companies thought it was enough additional work.
However, the digital tsunami in which people have lived since this law was enacted has shown that data has become the fuel that drives the commercial engine around the world.
In the early days of the internet, individuals were far from understanding that the endless trail of data we now often leave unconsciously would be exploited by companies of all kinds, with good or not-so-good intentions.
But on May 25, 2018, with the entry into force of the GDPR, everything is going to change by establishing a dynamic in which the individual is at the center of everything. What are its key points?
* “Right to be forgotten”: When a person no longer wishes for their data to be processed, and provided there are no legitimate grounds for retaining it, the data will be deleted. This is about protecting people’s privacy, not erasing past events or restricting freedom of the press.
* Easier access to personal data: Individuals will have more information on how their data is processed, and this information must be available in a clear and understandable way. The right to data portability will make it easier for individuals to transmit personal data between service providers.
* Right to know when a personal data breach has occurred: Companies and organizations must notify the national supervisory authority within 72 hours of data breaches that put individuals at risk and communicate all high-risk breaches to the data subject as soon as possible so that users can take appropriate measures.
* “Data protection by design” and “Data protection by default”: These are now essential elements in EU data protection rules. Data protection must be integrated from the very beginning of the design of products or services. And the regulation about to enter into force will make privacy-friendly settings the default, for example, in social networks or mobile applications.
* Stricter enforcement of rules: Data protection authorities will be able to impose fines on companies that do not comply with EU rules, up to 4% of their total global annual turnover.
To address the above, companies will have to work in ways we haven’t had to until now:
* What third-party data your organization manages. What data is collected from third parties and where it is stored. Perhaps something we were already doing, but which will now need to be updated exhaustively.
* Consent for data transfer must be explicit. It must be accepted by the user; collecting data by default will no longer be valid. This is one of the aspects least “cared for” by companies that habitually subscribe you to their newsletter without you having requested it.
* The role of the Data Protection Officer (DPO) is born. Any company with more than 250 employees whose main activity involves the management and processing of data or special category data must have this figure.
* Implementation of monitoring, management, and data protection controls, attending to users who request information about their data.
With this outlook, there will be two possible scenarios:
– Companies that comply with the new regulation and will be able to keep their clients’ data.
– Companies that do not comply with the regulation and may have to give up keeping that data.
With the introduction of the GDPR, consumers will be able to know which companies are capable of maintaining their data by complying with the new regulations and which are not. In a landscape of absolute control over our data, we will be able to say “no” to a company that asks to keep our information once we know they cannot do so with total security.
And more importantly: we will be able to choose which company to protect our data with.  We will witness the birth of data portability, to the point where we could be clients of one company while our data is held by another—something like having to share a bed with our client’s lover. This will give rise to companies offering “ad-hoc” data storage services, opening up a new line of business.
This will mark the difference between companies capable of building new products or services thanks precisely to the knowledge they have of client data, versus those that will not be able to use that knowledge because their clients have limited the use of their data.
The GDPR is much more than a regulation that develops specific articles of what was already being applied. It is destined to create a new reality, costly to implement, but very ambitious in its objectives regarding the relationship between clients and companies.
That data will be liquid gold in the hands of companies most committed to the regulation that the GDPR imposes, and it will become a headache for companies that arrive late or fail to be perceived as secure by clients.
From May 2018, we will be able to see that our clients are more than just a data point.

Via GoodRebels

Digital Identity

Methods for analyzing and
assessing online
reputation damage