GDPR – ARE YOU READY?
The European Union has a new privacy law, the GDPR, which goes into effect in May 2018, and unlike previous laws, these are extra-territorial. That means the new privacy law applies to countries outside of the EU. We’ve put together a breakdown of what it means for you as a website owner.
WHAT IS THE GDPR?
The GDPR is the new sweeping European Union (EU) legislation that modernizes and reforms the laws that address the handling of personal data. It replaces the European Data Protection Directive (95/46/EC) which was implemented inconsistently across Europe and did not have legislative authority.
Stricter consent rules
- The GDPR requires that individuals give unambiguous, informed consent before their data may be processed. Consent cannot be assumed from inaction.
Enhanced rights for data subjects
- Individuals have more rights under the GDPR including rights to: have their personal data erased, have inaccurate data corrected, be removed from digital marketing, and request personal data be ported to another service provider.
Data breach notification
- Organizations must notify those whose data has been breached, within 72 hours of the breach.
Increased accountability measures
- There are a number of new governance requirements for subject organizations, including conducting privacy impact assessments and appointing a data protection officer.
- Maximum penalties are €20 million or 4% of annual global revenue, whichever is greater.
DATA MINIMIZATION VS DATA MAXIMIZATION
Today, most businesses and their marketing teams follow the practice of data maximization, that is, collecting as much data about consumers as possible, sometimes before they know exactly what, how, or when that data will be used. In addition they will extract as much value out of this data as they can, including at times, reusing it for various purposes or even selling it to another party. One of the biggest tenets of the GDPR is the principle of data minimization, that is, that firms collect only the smallest amount of personal data for the shortest period of time possible, and delete it as quickly as possible after its specific purpose is completed.