GDPR: EVERYTHING YOU NEED TO KNOW.
Are businesses and public bodies prepared to embrace the new regulation on personal data protection?
As many of you may know, EU Regulation 2016/679, known as the GDPR (General Data Protection Regulation), on the protection of natural persons with regard to the processing and free movement of personal data, has been directly applicable in all Member States since 25 May 2018.
In a nutshell, the GDPR:
- introduces clearer rules on disclosure and consent;
- defines the limits on the automated processing of personal data;
- lays the foundation for the exercise of new rights;
- establishes strict criteria for their transfer outside the EU;
- sets strict rules for data breach cases.
The rules also apply to companies located outside the European Union that offer services or products within the EU market. All companies, wherever they are located, will therefore be required to comply with the new rules. Businesses and entities will have increased responsibilities, and non-compliance risks heavy fines.
The One-Stop Shop
To resolve any difficulties, a "one-stop shop" has been introduced, which will simplify the management of data processing and ensure a uniform approach. Companies operating in multiple EU countries will be able to contact the Data Protection Authority of the country where they have their headquarters.
Data portability
The Regulation introduces the right to data portability, allowing the transfer of personal data from one data controller to another. This rule makes an exception in cases involving data contained in archives of public interest, such as registry offices. In this case, the right cannot be exercised, and the transfer of personal data to non-EU countries or international organizations that do not meet data protection security standards is also prohibited.
The principle of “accountability”
There are other important new elements. Data controller accountability has been introduced, along with an approach that takes greater account of the risks that a given processing of personal data may pose to the rights and freedoms of data subjects. This new right will facilitate the transition from one service provider to another, facilitating the creation of new services, in line with the Digital Single Market strategy.
Data breach
The data controller must report any personal data breaches to the Italian Data Protection Authority (Garante). Effectively responding to a data breach requires a multidisciplinary and integrated approach and greater cooperation at the EU level. The current approach has numerous flaws that must be addressed. This is not easy, but it must be done to avoid missing the opportunity provided by the GDPR. The first step Italian companies must take is undoubtedly the adoption of a Register of Personal Data Processing. But even before addressing the bureaucratic hassles, companies must understand the importance and value of data, as well as the significant economic damage associated with a loss of information. If the data breach poses a threat to the rights and freedoms of individuals:
The owner must also inform all interested parties clearly, simply and immediately and offer instructions on how he intends to limit the damage;
The controller may decide not to inform data subjects if it believes the breach does not pose a high risk to their rights, or if it demonstrates that it has already implemented security measures; or, finally, if informing data subjects would involve an effort disproportionate to the risk. In the latter case, it must provide public notice.
The Data Protection Authority may, however, require the data controller to inform the data subjects based on its own assessment of the risks associated with the violation committed.
The role of the DPO (Data Protection Officer)
It is no coincidence that the role of a "Data Protection Officer" (DPO) has been established, charged with ensuring the proper management of personal data in companies and institutions and selected on the basis of their professional qualities and specialized knowledge of data protection legislation and practices.
The Data Protection Officer:
- Reports directly to the top,
- He is independent, he does not receive instructions regarding the execution of tasks;
- It is allocated adequate human and financial resources for its mission.
In reality, too many doubts still persist regarding the very nature of the DPO. While a key figure, he or she is certainly not the "center" of the system established by the GDPR, which in the new system remains the Data Controller. The DPO must have specific expertise "in the laws and practices relating to personal data, as well as in the administrative rules and procedures that characterize the sector." It is equally important, however, that they also possess "professional qualities appropriate to the complexity of the task to be performed" and, especially in sensitive sectors such as healthcare, that they can demonstrate specific expertise in the types of processing performed by the controller. The DPO's decision-making autonomy and non-involvement in determining the purposes and methods of data processing are equally important if we want to restore to data subjects their sovereignty over the circulation of their data.