Are you ready for the new privacy regulation to take effect?
The Italian Data Protection Authority (Garante della Privacy) has developed a Guide for the application of European Regulation 2016/679 on the protection of personal data, adopted by the European Parliament last April 2016, to enable individuals, businesses, and public bodies to understand and correctly apply the new provisions on the matter.
The Regulation, which will become fully effective on May 25, 2018, will be operational in all EU countries, without the need for any transposition procedure, and will replace the current Privacy Code, adopted instead with Legislative Decree 196 of 2003 in implementation of a previous EU directive.
Within a year, therefore, the national privacy and data protection regulations of all European Union member states will be harmonized into a single set of rules.
The system developed by the European Union consists of two parts: a regulation covering individuals, businesses, and administrations, and a more specific directive regarding the use of personal data in the context of security, policing, and justice. This second part will need to be transposed into individual national laws through implementing legislation.
The Garante's Guide addresses the issues raised in the first part of the legislation, dividing them into six groups (foundations of lawfulness of processing; information; data subject rights; data controller, data processor, and data processor; risk-based approach to processing and accountability measures for data controllers and processors; international data transfers), and addresses the relevant innovations and potential issues for each.
Specifically, the new provisions introduced by the regulation include some that benefit data subjects. First and foremost, any privacy notice signed by the data subject must be clear, concise, transparent, intelligible, and easily accessible. Furthermore, the data subject may, if necessary, decide to transfer the data from one entity to another, thus allowing the data controller to be changed without losing the data provided. Explicit consent to the transfer of personal data will be required only for non-European countries or international organizations that do not have an adequate privacy policy.
On the other hand, the regulation promotes the accountability of data controllers and the adoption of approaches and policies that constantly take into account the risk that a given processing of personal data may pose to the rights and freedoms of data subjects.
Finally, another important innovation concerns the introduction of the role of Data Protection Officer, a professional responsible for managing and monitoring the privacy policies of companies and organizations.
Within a year, therefore, we will discover the effects of this reform and see how it will change the management of personal data throughout the European Union.