Sunday, October 16, 2016

GDPR - The Law Part 0

General Data Protection and Regulation in nutshell from wikipedia




  1. Applies registrar and processors based on EU but also global organization if they process personal data from EU residents witch.
  2. Each member country must have organization and authority to work with the organization, EU and residents
  3. Data Protection Officer DPO, new role required for companies over 250 employees. Under the GDPR, the independent Data Protection Officer (DPO) will be under a legal obligation to notify the Supervisory Authority without undue delay and this is also still subject to negotiations at present.
  4. Data Breach and notifications
    1. 72 hours or if high risk then as soon as possible
  5. Sanctions 
    1. 2% or 10 000 000,00 Euros from global turnover witch ever is greater
    2. 4% or 20 000 000,00 Euros from global turnover witch ever is greater
  6. Law explain the mindset of personal data but as described in earlier or later chapter it can be quite blurry with extension based on age, religion, color and so on.
  7. rights
    1. rights to be forgotten
    2. Data portability - should these mean that my data in Instgram should be movable using drag and drop to Twitter or Facebook or vice versa. Maybe not :-)
    3. My Data - right to see what personal data is stored from me

To Be Continued...

"All thoughts and pictures are my own and I don't have any legal background"

Extreme Car Show 2010


No comments:

Post a Comment