Don’t do SECURITY. Do business SECURELY.

GDPR enters into force: two years to prepare

The EU General Data Protection Regulation has entered into force and will apply from 25 May 2018.

The General Data Protection Regulation (EU) 2016/679 enters into force today and will apply from 25 May 2018, replacing the 1995 Data Protection Directive and, in the UK, the Data Protection Act 1998.

Headline changes

  • A new accountability principle: you must be able to demonstrate compliance.
  • Mandatory breach notification to the supervisory authority within 72 hours where there is a risk to individuals.
  • Data protection by design and by default, and data protection impact assessments for high-risk processing.
  • Stronger rights for individuals and stricter rules on consent.
  • Direct obligations for processors, and mandatory data protection officers for some organisations.
  • Fines of up to €20 million or 4% of global annual turnover.

Article 32 requires “appropriate technical and organisational measures” to secure personal data. An ISO/IEC 27001 information security management system provides a strong, demonstrable foundation. Two years sounds a long time, but it is not: start your gap analysis now.

Source: Regulation (EU) 2016/679 – GDPR (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights