Don’t do SECURITY. Do business SECURELY.

GDPR enters into force: two years to prepare

The EU General Data Protection Regulation has entered into force and will apply from 25 May 2018.

The General Data Protection Regulation (EU) 2016/679 enters into force today and will apply from 25 May 2018, replacing the 1995 Data Protection Directive and, in the UK, the Data Protection Act 1998.

Headline changes

  • A new accountability principle: you must be able to demonstrate compliance.
  • Mandatory breach notification to the supervisory authority within 72 hours where there is a risk to individuals.
  • Data protection by design and by default, and data protection impact assessments for high-risk processing.
  • Stronger rights for individuals and stricter rules on consent.
  • Direct obligations for processors, and mandatory data protection officers for some organisations.
  • Fines of up to €20 million or 4% of global annual turnover.

Article 32 requires “appropriate technical and organisational measures” to secure personal data. An ISO/IEC 27001 information security management system provides a strong, demonstrable foundation. Two years sounds a long time, but it is not: start your gap analysis now.

Source: Regulation (EU) 2016/679 – GDPR (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights