General Data Protection Regulation: Time To Get Ready!

The countdown has started: in less than five months, the General Data Protection Regulation (the "GDPR") will become directly applicable within the European Union (the "EU"). As from 25 May 2018, all entities located in the EU which process personal data in the context of their activities will have to comply with the requirements of the GDPR, regardless of whether the processing takes place in the EU or not. Under certain circumstances, entities located outside the EU which process personal data of data subjects located in the EU will also have to apply the GDPR.

GDPR will entail substantial changes in the approach to personal data processing: the accountability of entities will become of paramount importance, the supervisory authorities will be granted stronger powers and the administrative fines will be clearly dissuasive.

By way of thorough data mapping, entities will in particular have to identify and document (i) the types of personal data processed, (ii) the capacity under which they process personal data (as controller, joint controller or processor), (iii) the data subjects targeted, (iv) the purposes and legal grounds for each processing, including for data transfers outside of the...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT