GDPR – new law equals bigger fines for getting it wrong
The BBC is reporting that new data laws could end up bankrupting companies if they fail to look after personal data.
The European Union’s General Data Protection Regulation (GDPR) comes into force in May 2018, radically changing the way organisations have to look after our personal data. Failure to comply could lead to huge fines, yet many businesses are far from ready…
…Many of the stipulations are already covered by the UK’s Data Protection Act; but simply put, organisations need to keep records of all personal data, be able to prove that consent was given, show where the data’s going, what it’s being used for, and how it’s being protected…
If personal data gets stolen after a cyber-attack, companies have to report the breach within 72 hours of realising it.
And the definition of personal data has been extended to include extra categories such as your computer’s IP address or your genetic make-up – anything that could be used to identify you…
Non-compliance with the GDPR could lead to huge fines of 20 million euros or 4% of global turnover, whichever is the greater…
However, a spokesperson for the UK’s Information Commissioner’s Office (ICO) – the body responsible for enforcing GDPR in the UK – says: “The new law equals bigger fines for getting it wrong but it’s important to recognise the business benefits of getting data protection right.
“There is a real opportunity for organisations to present themselves on the basis of how they respect the privacy of individuals – and gain a competitive edge.”
“But if your organisation can’t demonstrate that good data protection is a cornerstone of your business policy and practices when the new law comes in next year, you’re leaving your organisation open to enforcement action that can damage both public reputation and bank balance.”…
Read more at Could new data laws end up bankrupting your company?
