Back to the insights archive
Your business

GDPR – what business should know

The General Data Protection Regulation (GDPR or GDPR) will become applicable on 25 May 2018 To date, each Member State had its own data protection legislation.

The General Data Protection Regulation (GDPR or GDPR) will become applicable on 25 May 2018 To date, each Member State had its own data protection legislation.

GDPR creates one a set of data protection rules across the EU to facilitate business...

The General Data Protection Regulation (GDPR or GDPR) will become applicable on 25 May 2018 To date, each Member State had its own data protection legislation. GDPR creates one a set of data protection rules across the EU, which is intended to make it easier for businesses to trade in the Union, including the UK, even though it is no longer formally within the EU structures.

Need for data protection

GDPR is a response to a completely new way of functioning personal data. Companies collect huge amounts of data, and the risk of them leaking to the public domain is enormous. Entrepreneurs realize that the more they know about their customers, the better they can submit their offer to them.

On the other hand, if the customers are not fully aware of or have not agreed to use their personal data, may have serious consequences primarily for the customers. Less consequences are borne by companies that process data. The GDPR requires companies to prove the consent of the data subject.

The new law also requires economic operators to provide data subjects with more information on how their data are used. It also introduces new rights, such as the right to be forgotten and the right to transfer data.

Another danger that has developed in recent years is the increasing risk of data theft by hacking. Data theft can also be used to blackmail companies to obtain ransom. GDPR is to introduce tools that will eliminate these practices.

Demonstration of conformity

Companies must demonstrate to what extent they comply with the GDPR. Companies that process personal data on a large scale in their basic operations may need to appoint a Data Protection Officer (DPO) to monitor internal compliance with GDPR assumptions. Most companies will not need a Data Protection Officer, but will need a senior management person who will be able to demonstrate knowledge and understanding of the requirements of the GDPR.

Non-compliance is punishable by severe penalties. In the UK, companies that do not take their responsibility for the protection of personal data into account or do not take them seriously may be fined up to 20,000,000 EUR or of which 4% global income.

Source: https://www.russellbedford.com/latest/insight/gdpr-what-businesses-need-to-know/

Prepare to enter GDPR:

Companies should introduce GDPRs to be an integral part of their activities and all future initiatives, carrying out impact assessments to take account of the risks associated with data protection and any impact on personal data and data subjects. This is not a requirement for GDPR, but a reasonable way for entrepreneurs to follow the rules.

GDPR does not apply only to companies established in the EU but also includes non-EU companies that process data:

  • - within the EU,
  • - outside the EU, but concern EU entities,
  • - are targeted at data subjects in the EU.

The GPDR also includes detailed rules on the transfer of personal data to non-EU countries. This is important for many UK and European companies that conclude agreements with external data processors in the United States or transfer EU personal data outside Europe. They must examine their agreements with external data processors to ensure that they include appropriate contractual clauses that meet the requirements of the GDPR.

Although GDPR is based on the current EU data protection rules, it significantly extends the obligations that companies have to comply with. Because we're approaching 25 May 2018, when GDPR becomes a law in individual Member States, companies need to understand what personal data they store and process and work to achieve compliance with the new EU guidelines.

We comprehensively coordinate activities related to the preparation of the company for the GDPR. We offer you training in this area as well as outsorting position of personal data inspector.

Continue exploring our insights.

View the full archive
Your business

Investment in employee development will help keep the company on the market in times of crisis

For many companies, the current situation is a judgment that marks the end of their operation on the market.

Your business

Funding for the remuneration of workers in crisis shields

The crisis shield provides for a number of aid solutions for employers affected by the outbreak.

Your business

Micro enterprise loan within the Shield 2.0 – only for companies that suffered losses during the pandemic

one from the forms of aid provided for in the refreshed crisis shield package, it is possible to apply for a non-refundable loan for the company under certain conditions.