{"id":14199,"date":"2017-10-05T08:53:50","date_gmt":"2017-10-05T06:53:50","guid":{"rendered":"https:\/\/www.emailvendorselection.com\/?p=14199"},"modified":"2020-06-08T18:44:46","modified_gmt":"2020-06-08T16:44:46","slug":"gdpr-a-new-eu-wide-data-protection-framework","status":"publish","type":"post","link":"https:\/\/www.emailvendorselection.com\/gdpr-a-new-eu-wide-data-protection-framework\/","title":{"rendered":"GDPR: A new EU-wide data protection framework"},"content":{"rendered":"<p>2018, Year Zero for GDPR<\/p>\n<p>In 2018, important changes will be made to the regulatory landscape for the protection of personal data in Europe. The <b>General Data Protection Regulation<\/b> (GDPR), which substantially alters the applicable rules, will take effect on 25 May 2018.<!--more--><\/p>\n<p>Even if this legislative text is not strictly speaking revolutionary, the changes it implements are quite significant. Firstly, instead of a European directive, which each Member State must enact in its national legislation, the European Parliament has instead established a regulation, which, in principle, is <b>identical throughout the European Union<\/b>. <\/p>\n<p>Secondly, the regulation also specifies how certain <b>fundamental principles<\/b> must be implemented, such as transparent data processing. And finally, because the regulation also imposes rather <b>heavy fines<\/b> on offenders.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Stricter_obligations_for_data_controllers\"><\/span>Stricter obligations for data controllers<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Data controllers and their subcontractors must comply with increasingly strict obligations. In everything they do, they must always endeavor to take the issue of <b>data security<\/b> into account, limiting the collected data to a minimum. In addition, they must also take <b>every possible technical and organizational measure<\/b>, ensuring it is adapted to the nature and risks associated with the processed data. <\/p>\n<p>Organizations that typically process large amounts of data (such as polling organizations) will be required to appoint a <b>data protection officer<\/b> (DPO). Finally, data controllers must also <b>communicate any security breaches<\/b> to the authorities, to their customers and to the people whose data they process.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.emailvendorselection.com\/wp-content\/uploads\/data-protection-officer.jpg\" alt=\"data-protection-officer\" width=\"550\" class=\"aligncenter size-full wp-image-14222\" \/><\/p>\n<p><b>Data transfers<\/b> to countries with different levels of protection must be strictly limited to specific cases. Last year, for example, the European Court of Justice declared the Safe Harbor framework invalid, causing quite a shockwave. Things will probably be no different for Safe Harbor\u2019s replacement, namely the Privacy Shield agreement, that will exist alongside the regulation.<\/p>\n<p>The sanctions outlined in the regulation are particularly impressive as <b>fines can amount to up to EUR 20 million or 4% of the company\u2019s annual global turnover<\/b>. The accountability of subcontractors has also increased.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Emphasis_on_transparency\"><\/span>Emphasis on transparency<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The regulation ignores the purely formal measures that had been enacted under the previous directive (i.e. the requirement to declare any processing operations), choosing instead to focus on the <b>increased transparency<\/b> of data processing operations. As such, the regulation stipulates which information must be provided to people whose data is processed. <\/p>\n<p>The information must be complete and must be communicated in an \u201cintelligible\u201d form, in clear and simple language. The <b>requirement of informed consent<\/b> makes it impossible, for example, to collect data from children under the age of thirteen. And it is one of the reasons we see <a href=\"https:\/\/wpdatatables.com\/wordpress-cookie-consent\/\" rel=\"noopener noreferrer\" target=\"_blank\">cookie consent popups<\/a> on so many sites. <\/p>\n<p>The rights of the individual whose data is collected have been extended and simplified, giving them <b>the option to oppose data processing<\/b> under certain circumstances (for example for direct marketing purposes). A person may request any data that concern him or her and which were collected by a data controller in a commonly used format so they can be transmitted to another data controller (\u201c<b>data portability<\/b>\u201d). Finally, people now also have the right to oppose profiling, for example, based on their personal data.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"It_is_not_too_late_to_do_the_right_thing\"><\/span>It is not too late to do the right thing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>It is not yet too late to implement the <b>obligations arising from the GDPR<\/b>. Nor must we lapse into blissful optimism, however. Chances are the authorities responsible for the implementation of the new regulation will do everything in their power to increase controls as soon as it takes effect.<\/p>\n<div id=\"attachment_14214\" style=\"width: 560px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.emailvendorselection.com\/wp-content\/uploads\/visual-gdpr-gameplan.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14214\" src=\"https:\/\/www.emailvendorselection.com\/wp-content\/uploads\/visual-gdpr-gameplan-small.jpg\" alt=\"visual-gdpr-gameplan-small\" width=\"550\" height=\"308\" class=\"aligncenter size-full wp-image-14213\" \/><\/a><p id=\"caption-attachment-14214\" class=\"wp-caption-text\">Visual GDPR GamePlan (<a href=\"https:\/\/www.linkedin.com\/pulse\/visual-gdpr-game-plan-tim-clements-cipp-e-cipm-cgeit-crisc\/\" target=\"_blank\" style=\"color:#000000\" rel=\"nofollow noopener noreferrer\">source<\/a>: Tim Clements)<\/p><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Which_steps_must_a_company_undertake_to_comply_with_the_regulation\"><\/span>Which steps must a company undertake to comply with the regulation?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Firstly, the company\u2019s management must be aware of the <b>overriding importance of personal data protection<\/b>. The executive management and even the Board of Directors must take charge of this matter. They must, in certain instances, provided for under the regulation, appoint a Data Protection Officer who must ensure that the measures required for the implementation of the legal measures are effectively taken.<\/p>\n<p>More specifically, the <b>Data Protection Officer<\/b> must ensure that all employees receive <b>data protection training<\/b>. They are the company\u2019s most essential link on this level. There is no point in putting in place the most advanced protection technology if employees continue to carry around personal non-encrypted data on USB sticks. Otherwise data protection will never get out of the starting blocks.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_about_Martech_Providers_in_all_this\"><\/span>What about Martech Providers in all this?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Many European Martech provider have chosen not to wait for the adoption of the GDPR to ensure that personal data is protected. Following the principles of the European Directive on Data Protection, they  have adopted a set of practices aimed at ensuring <b>data security and transparency<\/b>.<\/p>\n<p>On the other hand, a majority of the US providers fail to comply with the requirements of the Regulation, namely due to the fact that they host consumer data on the American soil. In principle, European marketers should avoid to uses these services in order to maintain compliance with EU regulation. <\/p>\n<p>The Privacy Shield Mechanism, however, provides a mechanism of authorization for companies who self-certify themselves on various aspects of data security. The American Federal Trade Commission, charged with the enforcement of the Provisions of the Privacy shield has recently alleged that several companies made false claims about Privacy Shield participation. <\/p>\n<p>This case reminds us that European marketers have a responsibility to ascertain that their providers respect the principles included in the regulation before to send them their data.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"An_opportunity_for_European_companies\"><\/span>An opportunity for European companies<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Despite the very stringent nature of the GDPR\u2019s provisions, which may contribute to a negative image of personal data protection, we, on the contrary, think that the existence of such a unified framework is a <b>real opportunity for European companies<\/b>. It allows them to distinguish themselves from their global competitors by voicing their constant concern for the protection of the interests of both consumers and citizens.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2018, Year Zero for GDPR In 2018, important changes will be made to the regulatory landscape for the protection of personal data in Europe. The General Data Protection Regulation (GDPR), which substantially alters the applicable rules, will take effect on 25 May 2018.<\/p>\n","protected":false},"author":106,"featured_media":14207,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_editorskit_title_hidden":false,"_editorskit_reading_time":0,"_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","footnotes":""},"categories":[2],"tags":[137],"dealstore":[],"coauthors":[592],"acf":[],"_links":{"self":[{"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/posts\/14199"}],"collection":[{"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/users\/106"}],"replies":[{"embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/comments?post=14199"}],"version-history":[{"count":0,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/posts\/14199\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/media\/14207"}],"wp:attachment":[{"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/media?parent=14199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/categories?post=14199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/tags?post=14199"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/dealstore?post=14199"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.emailvendorselection.com\/wp-json\/wp\/v2\/coauthors?post=14199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}