What is the GDPR and who does it apply to?

The General Data Protection Regulation, or GDPR, is the regulation on the protection of natural persons with regard to the processing of personal data and the free movement of such data, which entered into force in 2016 and will be applicable from May 2018.

The GDPR requirements apply to any organisation operating in the EU or processing personal data originating from the EU, whether from residents or visitors.
Therefore, any organisation that processes data relating to any person (data originating from the EU) is subject to the GDPR, regardless of its size or country.

Key aspects from a data security perspective

The main points of the new law to consider are as follows:

  • The data controller must implement appropriate technology and organisational measures that ensure GDPR compliance, as well as technical measures to ensure that only the data that truly needs to be processed is processed.
  • In the event of a data security breach, the affected individuals must be informed, with some exceptions, such as when the effort to inform all data subjects would be disproportionate, in which case the breach may be communicated through public channels. 
  • It will also be mandatory to notify the Supervisory Authority of potential security breaches within 72 hours. 
  • A Data Protection Impact Assessment, or DPIA (“Data Protection Impact Assessment”) is required when a new processing system is introduced. 
  • Data subjects must give their explicit consent for their personal data to be recorded. 
  • Data subjects may choose whether they want their personal data to be erased (“right to be forgotten”). They may also decide whether they want to transfer their data to another controller (“right to data portability“). 
  • One-stop-shop system: there is a single data protection authority acting as the point of contact for all Member States.

Penalties for non-compliance

Article 58 of the GDPR grants the supervisory authority the power to impose administrative fines in accordance with Article 83, depending on various factors. Potential penalties fall into two tiers: a fine of €10 million, or 2% of annual turnover from the previous year (whichever is higher); on the other hand, for more serious infringements, fines of €20 million, or 4% of turnover (whichever is higher).

The importance of data protection for organisations

According to a survey by Crowd Research Partners, 30% of organisations are not ready to comply with the GDPR. With the entry into force of the new regulation, the requirements for organisations that handle data of EU citizens increase, as do those for foreign companies that handle data of European consumers.

With the widespread use of technology and messaging services, organisations can make certain basic mistakes that could result in significant fines, such as adding a WhatsApp user without consent or including them in WhatsApp groups with other users. This violates their right to privacy, putting people’s freedoms and security at risk. It also involves sharing a private phone number without permission, making it accessible to other users.

Are you concerned about safeguarding your organisation’s information and preventing external attacks that could affect the company and your customers? Become a cybersecurity expert with the Postgraduate Programme in Cybersecurity Management that we deliver in collaboration with the business school Inesdi. Personal and private information is more valuable than ever, and it is the responsibility of companies to ensure data security and prevent potential attacks by cybercriminals that could jeopardise the safety of people and organisations.

Digital Identity

Methods for analyzing and
assessing online
reputation damage