Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Monday, December 2, 2019

Small Business GDPR Requirements Differ from Large Business

Are small businesses required to keep the same records of compliance as large businesses?
Although Article 30 of the GDPR states that companies must “maintain a record” of their processing activities, the provision contains an exemption for small businesses. Specifically, it states that if a company employs “fewer than 250 persons,” it is generally not required to maintain a record of its processing activities. The exception does not apply, however, if one of three conditions is present:
  • The small business carries out processing that “is likely to result in a risk to the rights and freedoms of data subjects,”
  • The small business carries out processing that “is not occasional,” or
  • The small business carries out processing that “includes special categories of data” or that involves “data relating to criminal convictions and offense.”
The small-business exception been interpreted very narrowly by the Article 29 Working Party. A small business of course maintains personal data concerning its employees. As that data is maintained throughout the employment relationship (and typically beyond) it is subject to systematic and periodic processing (e.g., to run payroll, collect and pay taxes on behalf of employees, evaluate performance, etc.). The Article 29 Working Party assumes that such processing cannot be characterized as “not occasional.” In order for processing to be considered “occasional,” it cannot be “carried out regularly” and it cannot be carried out within “the regular course of business or activity” of the company.  In such jurisdictions that so permit, employers often collect “data relating to criminal convictions” prior to offering an individual employment and periodically throughout the employment relationship. It is also common for an employer to hold some information about employees’ health. As a result, even if a company has fewer than 250 employees, it may still be subject to the same record keeping requirements as larger companies with respect to its human resource related data. 

Read more here...

Friday, August 16, 2019

Abuse of Online Privacy Rules Means Personal Info Can Be Compromised - So Require Credentials

With the introduction of Europe's General Data Protection Regulation, firms in Europe and around the globe should be aware that social engineering tactics can be used to acquire an individual’s sensitive data.

“…For social engineering purposes, GDPR has a number of real benefits, Pavur said. Firstly, companies only have a month to reply to requests and face fines of up to 4 percent of revenues if they don't comply, so [the] fear of failure and time are strong motivating factors.

In addition, the type of people who handle GDPR requests [is] usually admin or legal staff, not security people used to social engineering tactics. This makes information gathering much easier….” See this article.

Direct email marketing, for example, is already regulated under the EU's e-Privacy Directive. Such rules require consent before someone can be sent direct marketing. A so-called "soft opt-in" makes this slightly easier. If a firm has an existing relationship, for instance, if a customer has bought a product from them before, they may still contact that recipient.

The European Union is updating the rules on electronic communications just as the UK is hustling to engage its own Data Protection Act in place, considering how Brexit will affect tech firms. The continued flow of data between the UK and the rest of Europe (and the world) depends on governments’ ability to interact.

Wednesday, March 6, 2019

Ireland's First Report on GDPR

Last month marks the release of the first annual GDPR report from Ireland’s data protection supervisory authority, the Data Protection Commission (DPC). This is a follow-on from the DPC’s final pre-GDPR annual report and covers May through December of 2018.

The report confirms the DPC’s role as the clearinghouse for cross-border privacy complaints: A new category, termed ‘multinational complaints – others’, makes up 22% of all GDPR complaints in the report. These complaints are second to access rights as the largest category of complaint. 

This document also sets out the DPC’s views on the new complaint-handling mechanism under the Data Protection Act of 2018. When a negotiated resolution is not possible, the DPC is no longer legally obliged to make a formal, statutory decision. Instead, the DPC has a range of options: providing advice to the complainant; issuing statutory notices to controllers or processors; and, opening statutory enquires.

If a non-EU company is offering services over the internet to consumers in the EU, these companies are required to have a  data protection representative due to increased territorial scope. Article 3 of the GDPR applies to any ‘data subject’ in the EU, i.e. a person living in the EU. Notably, Article 3(2) applies to the processing of personal data of any individual “in the EU.” The individual’s nationality or residence is irrelevant. The GDPR protects the personal data of citizens, residents, tourists, and other persons visiting the EU. So as long as an individual is in the EU, any personal information of that person collected by any controller or processor who meets the requirements of Article 3(2) is subject to the GDPR. Learn more about having a data representative here.