{"id":15045,"date":"2018-04-18T19:26:09","date_gmt":"2018-04-19T02:26:09","guid":{"rendered":"https:\/\/www.podfeet.com\/blog\/?page_id=15045"},"modified":"2018-05-21T19:11:09","modified_gmt":"2018-05-22T02:11:09","slug":"gdpr-explained-by-bart-busschots","status":"publish","type":"page","link":"https:\/\/www.podfeet.com\/blog\/gdpr-explained-by-bart-busschots\/","title":{"rendered":"CCATP #534 &#8211; Bart Busschots on GDPR"},"content":{"rendered":"<p>This content was originally posted as part of the Chit Chat Across the Pond podcast on 14 April 2018 but since the subject is evergreen it is repeated here as a permanent Page. <\/p>\n<h4>Introduction<\/h4>\n<p>In this article, Bart Busschots explains the General Data Protection Regulation, or GDPR.  This is a regulation that will take effect across the European Union starting on 25 May 2018.  Bart first gives us an overview, outlining the main objectives, the 7 core principles, and explains how a regulation differs from a directive.  From there he defines the terminology and concepts which are critical to understanding the regulation.  He explains the legal grounds, what consent means and what rights individuals will have.  Then he covers data processing objections, how automation decision making is affected, and people&#8217;s right to erasure.  Finally, he goes through what kind of data breaches are mandatory to be disclosed and to whom.  It&#8217;s a really impressive bit of work that the EU have done here, and Bart does a great job explaining it.<\/p>\n<audio class=\"wp-audio-shortcode\" id=\"audio-15045-1\" preload=\"none\" style=\"width: 100%;\" controls=\"controls\"><source type=\"audio\/mpeg\" src=\"https:\/\/media.blubrry.com\/nosillacast\/traffic.libsyn.com\/nosillacast\/CCATP_2018_04_18.mp3?_=1\" \/><a href=\"https:\/\/media.blubrry.com\/nosillacast\/traffic.libsyn.com\/nosillacast\/CCATP_2018_04_18.mp3\">https:\/\/media.blubrry.com\/nosillacast\/traffic.libsyn.com\/nosillacast\/CCATP_2018_04_18.mp3<\/a><\/audio>\n<p><a title=\"mp3 download\" href=\"https:\/\/media.blubrry.com\/nosillacast\/traffic.libsyn.com\/nosillacast\/CCATP_2018_04_18.mp3\" target=\"_blank\" rel=\"noopener noreferrer\">mp3 download<\/a><br \/>\n<!--more--><\/p>\n<h2>The Problem to be Solved<\/h2>\n<ul>\n<li>Each nation in the EU has data protection laws, and they&#8217;re similar in many ways, but they&#8217;re all different.<\/li>\n<li>Many, if not most, of the existing data protection laws pre-date the modern internet, so they need to be updated to reflect developments (social media, the <em>Facebook-style<\/em> business model, the rise in identity theft, etc.).<\/li>\n<li>There&#8217;s no clear EU-wide set of data protection rights for citizens<\/li>\n<li>The penalties for breaking the existing data protection laws are not uniform, but generally considered lenient.<\/li>\n<\/ul>\n<h2>Overview<\/h2>\n<ul>\n<li>The GDPR is the <em>General Data Protection Regulation<\/em>.<\/li>\n<li>The GDPR Covers all <em><strong>personal data<\/strong> processed by manual or automated means<\/em> \u2014 note, not all data, just all <em>personal data<\/em>.<\/li>\n<li>The main objectives are:\n<ol>\n<li>Give individuals more advanced and more clearly defined rights, and more control over how their personal data is stored and used.<\/li>\n<li>Empower individuals to seek compensation from organisation who breach their data protection rights.<\/li>\n<li>Make organisations more accountable and instil a culture of privacy awareness.<\/li>\n<\/ol>\n<\/li>\n<li>The GDPR is built around 7 core principles:\n<ol>\n<li>Collected personal data should be for a <strong>specific and legitimate purpose<\/strong> (if you collect data for one purpose, you can&#8217;t just use it for anything you fancy).<\/li>\n<li>Collected personal data should be <strong>adequate<\/strong> to meet the needs, but <strong>minimised<\/strong> (gather the personal data you need, but only the personal data you need).<\/li>\n<li>Stored personal data should be <strong>accurate and kept up-to-date<\/strong>.<\/li>\n<li>Personal data should be <strong>kept for no longer than necessary<\/strong>.<\/li>\n<li>Personal data should be <strong>stored securely<\/strong>.<\/li>\n<li>Organisations or people that hold personal data must be <strong>accountable<\/strong> for what happens with that data (the <em>accountability principle<\/em>).<\/li>\n<li>Use of personal data must be <strong>lawful, fair, and transparent<\/strong>.<\/li>\n<\/ol>\n<\/li>\n<li>The GDPR is an EU regulation (not a directive), so it applies directly all across the EU.\n<ul>\n<li>Directives are instructions from the EU to member states to draft national legislation that meets certain requirements. Every EU nation has to implement a directive, but each nation&#8217;s implementation will be unique.<\/li>\n<li>Previous EU privacy controls had been applied as directives, so each state had their own data protection laws.<\/li>\n<li>The GDPR replaces the mish-mash of different national privacy laws with a single EU-wide regulation.<\/li>\n<\/ul>\n<\/li>\n<li>The GDPR comes into force across the entire EU (including the UK) on the 25th of May 2018.<\/li>\n<li>The penalties for breaches of the GPDR are robust \u2014 up to \u20ac20 million or 4% of the organisation\u2019s annual turnover, whichever is greater.<\/li>\n<li>The GDPR applies to anyone in the EU processing personal data from anyone anywhere in the world, and anyone anywhere in the world processing the Personal Data of anyone physically in the EU (not just EU citizens).<\/li>\n<\/ul>\n<h2>Terminology &amp; Concepts<\/h2>\n<ul>\n<li><strong>Personal Data:<\/strong> any information that could <strong>identify<\/strong> a living person (the dead are not protected by GDPR!). This sounds simple but it&#8217;s not, and there are lots of grey areas open to interpretation, so there&#8217;s a lot of confusion and uncertainty ATM (precedents will get set over time, so things should become clearer).\n<ul>\n<li>Indirect identification is covered. The combination of multiple pieces of information that individually wouldn&#8217;t be covered could become covered if combining them allows the identity to be determined. E.g. a name alone isn&#8217;t covered (lots of people share the same name), nor is a data of birth alone, but store both and they might be covered, and add an address and they&#8217;ll definitely be covered.<\/li>\n<li>Depending on circumstances, incomplete information may also be covered. E.g. A customer ID doesn&#8217;t look like personal data, but if that links to a full customer profile, then it is. IP addresses are covered.<\/li>\n<li>Pseudonymised data is also covered \u2014 if the organisation holds the mapping between the anonymised identifier and the original identity, then it&#8217;s still personal data, no matter what it looks like at first glance. (If you don&#8217;t hold the mapping then it&#8217;s <em>anonymised data<\/em> which is not covered.)<\/li>\n<li>Long-standing identifiers like national ID numbers, phone numbers, email addresses etc. are covered, but so are some newer data types including devices IDs (like MAC addresses), online identifiers (like IP addresses and tracking cookies), and location data.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Special Category Data:<\/strong> this is the official GDPR term for what you or I would call <em>sensitive data<\/em> (criminal records are expressly not covered in this category, they&#8217;re covered separately):\n<ul>\n<li>Racial or ethnic origin<\/li>\n<li>Genetic data<\/li>\n<li>Biometric data<\/li>\n<li>Physical and Mental Health data<\/li>\n<li>Sexual life (activities, orientations etc.)<\/li>\n<li>Religious or philosophical beliefs<\/li>\n<li>Political opinions<\/li>\n<li>Trade Union membership<\/li>\n<\/ul>\n<\/li>\n<li><strong>Data Processing:<\/strong> this is a broad term that covers a wide range of activities including data gathering, storage, security, analysis, transportation\/transmission, and disposal.<\/li>\n<li><strong>Data Subject:<\/strong> the living person the personal data is about (you!).<\/li>\n<li><strong>Data Controller:<\/strong> An organisation or person who makes decisions on why and how personal data should be stored\/processed (a user of personal data, e.g. a company, school, or government).<\/li>\n<li><strong>Data Processor:<\/strong> A person or organisation who stores\/processes data on behalf of a <em>Data Controller<\/em> (you can be a controller and a processor, and most organisations are, but many organisations also out-source to third-parties, and those third parties would be processors but not controllers).<\/li>\n<li><strong>Data Protection Officer (DPO):<\/strong> A named person responsible for an organisation&#8217;s compliance with GDPR.\n<ul>\n<li>DPOs are mandatory for any organisation who&#8217;s core activities include:\n<ul>\n<li>large-scale systematic data monitoring, or<\/li>\n<li>large-scale processing of <em>special category data<\/em> (sensitive data), or<\/li>\n<li>processing of criminal records.<\/li>\n<\/ul>\n<\/li>\n<li>All organisations are encouraged to appoint at DPO.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Supervisory Authority:<\/strong> A national data protection authority that enforces GDPR (every EU nation will have one, e.g. in Ireland it&#8217;s the <em>Data Protection Commissioner<\/em>).<\/li>\n<li><strong>Privacy Notice:<\/strong> a document <em>data controllers<\/em> are required to publish that describes <strong>what personal data<\/strong> they collect, <strong>why<\/strong> they collect it, and <strong>what they do with it<\/strong>, including <strong>who they share it with<\/strong>. Privacy notices also have to explicitly state the <strong>legal grounds<\/strong> on which the personal data is being collected (more on this later).<\/li>\n<li><strong>Subject Access Request (SAR):<\/strong> a request from a <em>data subject<\/em> for a copy of all the <em>personal data<\/em> a <em>data controller<\/em> holds on them.<\/li>\n<li><strong>Data Breach:<\/strong> under GDPR, the term <em>data breach<\/em> is very broad, it doesn&#8217;t just cover the obvious stuff like <strong>unauthorised access<\/strong> &amp; <strong>data loss<\/strong>, but also <strong>unauthorised disclosure<\/strong> (not stolen but given away when it shouldn&#8217;t have been), <strong>unauthorised alteration<\/strong>, and <strong>unauthorised destruction<\/strong>.<\/li>\n<\/ul>\n<h2>Legal Grounds<\/h2>\n<p>All personal data collected needs to be justified under one of six legal grounds, and the grounds need to be specified in a person\/organisation&#8217;s privacy notice.<\/p>\n<p>GDPR allows the following six legal grounds:<\/p>\n<ol>\n<li><strong>consent<\/strong> \u2014 the data subject consented to the collection and use of the data.<\/li>\n<li><strong>Legitimate Interest<\/strong> \u2014 the data is collected and used in a way that would be reasonably expected. Use of this ground is limited because it can&#8217;t override a person&#8217;s rights or freedoms, and can&#8217;t be used by a public sector body.<\/li>\n<li><strong>Contractual Obligations<\/strong> \u2014 the data is collected and used to fulfil a contract entered into with the data subject. E.g. if you purchase an item to be delivered, you have to provide a delivery address for the vendor to be able to fulfil their contractual obligations to you.<\/li>\n<li><strong>Legal Obligations<\/strong> \u2014 the data is collected and used in order to comply with a law.<\/li>\n<li><strong>Vital Interests<\/strong> \u2014 the collection and use of the data is of vital interest <strong>to the data subject<\/strong>. The bar is high here, you&#8217;re pretty much talking about matters of life and death only.<\/li>\n<li><strong>Public Interests<\/strong> \u2014 the collection and use of the data is in the public interest. This can be used to justify the archiving of data for scientific or historical research, or the generation of statistics.<\/li>\n<\/ol>\n<h2>consent<\/h2>\n<p>This is the most clear-cut and strongest legal ground to gather and use personal data under.<\/p>\n<p>The regulation states that for consent to be valid it must be <em>&#8216;<strong>freely given<\/strong>, <strong>specific<\/strong>, <strong>informed<\/strong> and <strong>unambiguous<\/strong> either by a statement or by a clear affirmative action&#8217;<\/em>.<\/p>\n<p>That means:<\/p>\n<ul>\n<li><em>Data subjects<\/em> can&#8217;t be railroaded into giving consent, it has to be an actual choice.<\/li>\n<li>Silence, pre-ticked boxes, or inactivity do not indicate consent \u2014 the old chestnuts like <em>&#8216;by using this site you agree &#8230;&#8217;<\/em> do not count as valid consent under the GDPR.<\/li>\n<li><em>Data subjects<\/em> have to be able to withdraw their consent at a later time. <em>Data controllers<\/em> also have to explicitly inform <em>data subjects<\/em> that they have the right to withdraw their consent, and, provide a clear and simple mechanism for doing so.<\/li>\n<li>Consent can&#8217;t be inferred, the <em>data subject<\/em> has to pro-actively do something to consent, e.g. verbally state their agreement or click a clearly labeled button\/checkbox.<\/li>\n<li>Requests for consent have to be clearly labeled and separated out, you can&#8217;t just mush them into the middle of the small print.<\/li>\n<\/ul>\n<p>Children get extra protections under GDPR:<\/p>\n<ul>\n<li>Parental consent is needed before digital services (like social networks) can process a child&#8217;s <em>personal data<\/em>, and <em>reasonable efforts<\/em> have to be made to verify that consent.<\/li>\n<li>Outside of digital services <em>data controllers<\/em> have to assess whether or not a child has the <em>competency<\/em> to understand and consent on their own behalf.<\/li>\n<li><em>Privacy notices<\/em> that children are expected to consent to have to be written in language that children can reasonably be expected to understand.<\/li>\n<\/ul>\n<p>Note that the <strong>GDPR defines as child as anyone under 16<\/strong>, but does allow individual countries to re-define that ages down to a lower-limit of 13.<\/p>\n<h2>Individual Rights<\/h2>\n<p>The GPDR grants <em>data subjects<\/em> the following rights when it comes to their <strong>personal data<\/strong>:<\/p>\n<ol>\n<li><strong>Information<\/strong> \u2014 people have a <strong>right to be informed<\/strong> about how their <em>personal data<\/em> will be processed. The mechanism here is the <em>privacy notice<\/em> that <em>data controllers<\/em> must publish.<\/li>\n<li><strong>Access<\/strong> \u2014 people the right to see all personal data a <em>data controller<\/em> has stored on them.<\/li>\n<li><strong>Rectification<\/strong> \u2014 people have the right to correct any mistakes in the <strong>personal data<\/strong> a <em>data controller<\/em> has stored on them. The <em>data processor<\/em> has to fix erroneous data &#8216;<em>without undue delay<\/em>&#8217;, and definitely within one month, and they have to make sure the correction is propagated to any third-party <em>data processors<\/em> they share data with.<\/li>\n<li><strong>Erasure<\/strong> \u2014 citizens have a right to request their <strong>personal data<\/strong> be deleted by a <em>data controller<\/em>, but it&#8217;s not an absolute right, there are caveats.<\/li>\n<li><strong>Objection<\/strong> \u2014 <em>data subjects<\/em> have a right to object to certain uses of their <em>personal data<\/em>, and when that happens, the <em>data controller<\/em> has to stop processing the data unless there is a compelling reason not to. <em>Data subjects<\/em> can object to their data being used for <strong>direct marketing<\/strong> or research.<\/li>\n<li><strong>Restrict Processing<\/strong> \u2014 when there are disputes, a <em>data subject<\/em> can demand the processing of their <em>personal data<\/em> be restricted until the dispute is resolved. E.g. the <em>data subject<\/em> and <em>data controller<\/em> disagree about whether or not a piece of data is accurate, or the <em>data subject<\/em> challenges the <em>legal grounds<\/em> for the processing.<\/li>\n<li><strong>Data Portability<\/strong> \u2014 when technically feasible, <em>data subjects<\/em> have a right to request their <em>personal data<\/em> be copied or moved to another <em>data controller<\/em>, including to a competitor. The idea is that people shouldn&#8217;t be needlessly locked in to suppliers.<\/li>\n<\/ol>\n<p>When these rights are violated, <em>data subjects<\/em> have standing to sue <em>data controllers<\/em> for compensation.<\/p>\n<h2>Privacy Notices<\/h2>\n<p>The primary function of a <em>privacy notice<\/em> is to let citizens know <strong>what<\/strong> personal data is being collected, <strong>why<\/strong> it&#8217;s being collected, and <strong>how it&#8217;s going to be used<\/strong>. A big part of how it&#8217;s going to be used is <strong>who<\/strong> it will be shared with.<\/p>\n<p>Privacy notices don&#8217;t just have to be <strong>easy to find<\/strong>, they actually have to be <strong>highlighted for attention<\/strong>.<\/p>\n<p>Privacy notices also have to be clear and easy to understand \u2014 no obfuscations, and no hiding important stuff deep in the small print! A <em>privacy notice<\/em> that&#8217;s not clear would be considered a violation of <strong>the right to be informed<\/strong>.<\/p>\n<p>You&#8217;d imagine it would go without saying, but privacy notices have to be available <strong>free of charge<\/strong>. You can&#8217;t charge citizens for a privacy notice.<\/p>\n<p>A <em>privacy notice<\/em> should be:<\/p>\n<ul>\n<li><strong>Concise<\/strong> \u2014 it should contain all the information it needs to, but no more. Overloading citizens with so much superfluous information that they can&#8217;t find the important stuff is not OK!<\/li>\n<li><strong>Transparent and Intelligible<\/strong> \u2014 it should be written in clear, plain language. No using legalese to try confuse citizens!<\/li>\n<li><strong>Supplied in Context<\/strong> the privacy notice should be available when consent is given and\/or the <em>personal data<\/em> is collected, or, if the data is acquired indirectly, the <em>data subject<\/em> needs to be provided with the privacy notice <strong>within a reasonable time<\/strong>.<\/li>\n<\/ul>\n<p>Privacy notices must contain: <\/p>\n<ul>\n<li>Contact details for the <em>data controller&#8217;s<\/em> DPO.<\/li>\n<li>The <em>legal grounds<\/em> for the data collection (from the list above).<\/li>\n<li>A list of the <em>data processors<\/em> that will process the <em>personal data<\/em>.<\/li>\n<li>A retention policy for the <em>personal data<\/em> (how long will it be kept).<\/li>\n<li>An explanation of a person&#8217;s rights regarding the processing of their <em>personal data<\/em> including their right to withdraw consent, to object to certain kinds of data processing, and to complain to the relevant <em>supervisory authority<\/em>.<\/li>\n<\/ul>\n<p>The notification of a person&#8217;s rights has to be clearly separated out from the rest of the notice so it&#8217;s easy to find. <\/p>\n<p>The notification also has to include the right to have their personal data moved or copied to another organisation, even when the other organisation is a competitor. That&#8217;s not an absolute right though, it has to be technically feasible.<\/p>\n<h2>SARs (Subject Access Requests)<\/h2>\n<p>Since citizens have a <strong>right to access<\/strong>, <em>data controllers<\/em> have to provide a mechanism for <em>data subjects<\/em> to submit so-called <em>Subject Access Requests<\/em>, or SARs. In general there shouldn&#8217;t be a a fee for submitting a SAR, but there are exceptions. If the data is returned electronically, it has to be in a commonly used format.<\/p>\n<p>When a <em>data controller<\/em> receives a SAR it has to be passed to their DPO promptly, and they are then responsible for processing it.<\/p>\n<p>Generally speaking, SARs need to be processed within a month.<\/p>\n<h2>Data Processing Objections<\/h2>\n<ul>\n<li><em>Data subjects<\/em> have a <strong>right of objection<\/strong>. What that means is that they can object to some uses of their <em>personal data<\/em>, and <em>data controllers<\/em> should stop processing the data unless there&#8217;s a compelling reason not to. <em>Data subjects<\/em> can object to their <em>personal data<\/em> being used for:<\/li>\n<li><strong>Direct Marketing<\/strong> \u2014 this is the most clear-cut type of objection. If a person objects to being direct marketed at, there are no grounds to refuse to stop.<\/li>\n<li><strong>Research &amp; Statistics Generation<\/strong> \u2014 this is much less clear-cut, the public interest could out-weigh the individual&#8217;s rights, or, the individual might not have grounds on which to object, depending on the circumstances.<\/li>\n<li><strong>Processing on the grounds of legitimate Interests, public interest, or the exercise of official authority<\/strong> \u2014 if the <em>legal grounds<\/em> for processing are the <em>data controller&#8217;s legitimate interests<\/em>, or, the <em>public interest<\/em>, then <em>data subjects<\/em> have a right to raise an objection, and then a judgement will need to be made on whether or not the processing is legal under the GDPR.<\/li>\n<\/ul>\n<p>If a <em>data controller<\/em> decides to reject an objection they have to inform the <em>data subject<\/em> that they have rejected their objection, and, that they have the right to complain to the relevant <em>supervising authority<\/em>.<\/p>\n<h3>Profiling &amp; Automated Decision Making<\/h3>\n<p><em>Data subjects<\/em> can also object to the outcomes of any kind of <em>automated decision making<\/em> algorithms or <em>profiling<\/em>. Profiling is defined as <em>&#8216;any form of automated processing used to evaluate, analyse or predict personal aspects of an individual&#8217;<\/em>.<\/p>\n<p>Individuals have a right to ask for an explanation of any kind of automated decision or profile, and they can challenge the outcome.<\/p>\n<p>The GDPR gives people the <strong>right not to be subject to a decision<\/strong> based <strong>solely<\/strong> on <strong>automated processing<\/strong> if it <strong>significantly affects<\/strong> them. This right isn&#8217;t absolute though, objections can&#8217;t be raised if the profiling is required to fulfil contractual obligations, authorised by law, or based on explicit consent (though consent can be withdrawn).<\/p>\n<h2>Right to Erasure (AKA <em>Right to be forgotten<\/em>)<\/h2>\n<p>In many circumstances, <em>data subjects<\/em> have a right to demand their <em>personal data<\/em> be deleted, this includes:<\/p>\n<ul>\n<li>When the data is no-longer required for the original purpose.<\/li>\n<li>Consent is withdrawn and the data doesn&#8217;t need to be retained for legal reasons.<\/li>\n<li>The data is unlawfully processed.<\/li>\n<li>The <em>data subject<\/em> objects to the <em>data processing<\/em>, and there&#8217;s no legitimate overriding interest.<\/li>\n<li>There&#8217;s a legal obligation to delete the data.<\/li>\n<li>The data relates to the offering of <em>information services<\/em> to a child.<\/li>\n<\/ul>\n<p>There are also valid reasons for denying deletion requests, including:<\/p>\n<ul>\n<li>The public interest<\/li>\n<li>Legal obligations<\/li>\n<li>Freedom of expression<\/li>\n<\/ul>\n<p>Note that children have a stronger right to deletion, and the definition of a child&#8217;s data is based on the age they were when they signed up, not their current age. So a delation request from a 21 year old who signed up for something when they were 13 must be treated as a request from a child, even thought they&#8217;re not a child anymore.<\/p>\n<h2>Data Security &amp; Data Breaches<\/h2>\n<p>Before GDPR just about all the responsibility rested with <em>data controllers<\/em>, and it was up to them to supervise their <em>data processors<\/em>. GDPR changes that, in a few important ways:<\/p>\n<ul>\n<li>Under GDPR, <strong>both<\/strong> <em>data controllers<\/em> <strong>and<\/strong> <em>data processors<\/em> are responsible for the security of data while it transfers between them (under previous data protection directives it was just the controller who was responsible).<\/li>\n<li>If a <em>data processor<\/em> becomes aware of a data breach they must inform the <em>data controller<\/em> <em>&#8216;without undue delay&#8217;<\/em>. They also have a responsibility to report the breach to the <em>supervisory authority<\/em>.<\/li>\n<li><em>Data processors<\/em> can be sued by <em>data subjects<\/em> for damages caused by a breach of data they were processing.<\/li>\n<\/ul>\n<h3>Mandatory Reporting of Data Breaches<\/h3>\n<p>In order to protect people&#8217;s <strong>right to be informed<\/strong>, the GDPR includes mandatory reporting of <em>notifiable data breaches<\/em>. To avoid anything slipping through the cracks, <strong>all organisations<\/strong> involved in data processing have a duty to report any such data breaches they discover to the appropriate <em>supervisory authority<\/em>, not just <em>data controllers<\/em>.<\/p>\n<p>A breach is considered <em>notifiable<\/em> if it&#8217;s <em>&#8216;likely to infringe the rights and freedoms of individuals&#8217;<\/em>. That includes <strong>reputational damage<\/strong>, <strong>financial loss<\/strong>, and <strong>loss of confidentiality<\/strong>. These kinds of breaches need to be reported <strong>within 72 hours<\/strong> of the <em>data controller<\/em> becoming aware of them.<\/p>\n<p>For breaches where there&#8217;s a high risk to individuals, there is also a responsibility on the <em>data controller<\/em> to inform affected individuals, either directly, or via a public announcement.<\/p>\n<p>Failing to report a notifiable breach is a serious offence and can result in fines up to \u20ac10M or 2% of global turnover, which ever is greater! Note that these fines are <strong>in addition to<\/strong> any fines imposed for the breach itself! That means that an un-notified serious breach could cost an organisation up to \u20ac30M or 6% of global turnover!<\/p>\n<p>If you&#8217;re an employee in an organisation that&#8217;s subject to GDPR and you discover a data breach you need to immediately inform both your manager (if you have one), and your employer&#8217;s DPO (if they have one).<\/p>\n<h3>Links<\/h3>\n<ul>\n<li>The official GDPR home page (disappointingly useless, though the <a href=\"https:\/\/www.eugdpr.org\/gdpr-faqs.html\">FAQ<\/a> is OK) \u2014 <a href=\"https:\/\/www.eugdpr.org\/\">www.eugdpr.org\/\u2026<\/a><\/li>\n<li>The actual regulation (PDF) \u2014 \u200b<a href=\"http:\/\/data.consilium.europa.eu\/doc\/document\/ST-5419-2016-INIT\/en\/pdf\">data.consilium.europa.eu\/\u2026<\/a><\/li>\n<li>The Wikipedia article on the GDPR \u2014 <a href=\"https:\/\/en.wikipedia.org\/wiki\/General_Data_Protection_Regulation\">en.wikipedia.org\/\u2026<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>This content was originally posted as part of the Chit Chat Across the Pond podcast on 14 April 2018 but since the subject is evergreen it is repeated here as a permanent Page. Introduction In this article, Bart Busschots explains the General Data Protection Regulation, or GDPR. This is a regulation that will take effect [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[2471],"tags":[2489,2487,2488,2485,114,2486],"class_list":["post-15045","page","type-page","status-publish","hentry","category-special-pages","tag-data-collection","tag-eu","tag-european-union","tag-gdpr","tag-privacy","tag-regulation","post"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/15045","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/comments?post=15045"}],"version-history":[{"count":5,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/15045\/revisions"}],"predecessor-version":[{"id":15315,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/15045\/revisions\/15315"}],"wp:attachment":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media?parent=15045"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/categories?post=15045"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/tags?post=15045"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}