The General Data Protection Regulation (EU) 2016/679 enters into force today and will apply from 25 May 2018, replacing the 1995 Data Protection Directive and, in the UK, the Data Protection Act 1998.
Headline changes
- A new accountability principle: you must be able to demonstrate compliance.
- Mandatory breach notification to the supervisory authority within 72 hours where there is a risk to individuals.
- Data protection by design and by default, and data protection impact assessments for high-risk processing.
- Stronger rights for individuals and stricter rules on consent.
- Direct obligations for processors, and mandatory data protection officers for some organisations.
- Fines of up to €20 million or 4% of global annual turnover.
Article 32 requires “appropriate technical and organisational measures” to secure personal data. An ISO/IEC 27001 information security management system provides a strong, demonstrable foundation. Two years sounds a long time, but it is not: start your gap analysis now.
Source: Regulation (EU) 2016/679 – GDPR (EUR-Lex)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.