GDPR: Ready for accountability?
In our third blog post on GDPR preparation, we are going to talk about the principles that, among other things, put the onus on the controller to demonstrate security and compliance. Part of this we have already taken care of in the previous blog through a proper privacy statement for processing personal data. However, it's not only about transparency and customers' personal data, but also about your employees' personal data; about internal policies that put security first; about the documentation obligation; about the notification obligation; about Privacy by Design and by Default as well as FG and PIAs.
Are these terms new? Then read our very first GDPR blog on scope, consequences and jargon.
To successfully demonstrate that your company has taken appropriate technical and organisational security measures and thought of all rights & duties, introduce (or update) your privacy policy. Today, we will look at preparing our own policy. I talk about what is allowed, what should be and why one does this.
Internal privacy policy
The main purpose of the privacy policy is to ensure and demonstrate that personal data are processed in accordance with applicable laws and regulations.
For an adequate internal privacy policy, you should at least have included the following:
that the principles of the GDPR are applied to personal data processing;
that appropriate technical and organisational measures are in place;
that you have all your processing activities listed in a register;
that Privacy by Design is included in every project and/or product;
that Privacy by Default is included in every project and/or product;
that a PIA/ DPIA is carried out where necessary;
that you record data breaches and take the appropriate steps afterwards;
who bears responsibility for the above tasks/duties;
who checks when the above tasks/duties are met.
Free design.
There are no rules or guidelines for classifying your privacy policy, only that you should be able to show that your organisation has the above in place.
Due to the free nature of privacy policies and the choices companies can make to demonstrate compliance, there is no single designated template or good implementation but hundreds of options. Indeed, there is no list of technical or organisational measures that one must or can apply, and opinions may differ on what does or does not demonstrate a company's compliance with a particular requirement. Thereby, the steps to be taken towards compliance are very different for one company than for another. For example, take a look at the table of contents of our privacy policy:
I. Scope
Here I tell that the policy applies to all our employees, interns, freelancers and other relations. I also tell what we want to achieve by implementing and complying with this policy. Certain policies may only apply to a department or subsidiary organisation of your company. Specify the exact coverage of the document.
II. Principles
The basic principles of the GDPR consist of 7 sections that place strict limits on the processing of personal data:
Transparency : People are aware of the processing of their personal data, have given their consent and know their rights.
Purpose limitation : Data collected may only be used for a predetermined purpose.
Data limitation : No more personal data should be collected than is strictly necessary for the predefined purpose.
Preservation restriction : Personal data should not be kept longer than (legally) necessary for the predefined purpose. This is also covered in a processing agreement;
Correctness : Personal data must be, and remain, correct.
Integrity & Confidentiality : Personal data must be (appropriately) protected against access, loss and/or destruction.
Responsibility : Data controllers must be able to demonstrate compliance with applicable laws and regulations.
In my own words, I report that we apply the above principles as far as possible to all processing of personal data. That just doesn't adequately cover all the principles. How do you demonstrate adequate protection? How do you demonstrate accountability?
III. Accountability
In this section, I briefly explain who has what responsibility with regard to the implementation of and compliance with the privacy policy. This obviously varies from organisation to organisation, however, the director is ultimately responsible everywhere and always.
For example, we have raised compliance with Privacy by Design and Privacy by Default on a project-by-project basis as the responsibility of the project manager. It is the Office Manager's responsibility to monitor this, and then again the director's responsibility that everything is actually done.
Appropriate measures.
This can be an annoying requirement for many as it is a rather vague obligation. So how do you know whether a measure is appropriate under the GDPR? Quite specifically, there is no way to know. It is currently not clear what exactly is expected from data controllers. These kinds of questions will only be answered after case law has been done on such matters.
The assessment of whether a measure is appropriate must be made at the outset itself. The measure must be appropriate for 'a level of security appropriate to the risk'.
Suppose; NAW (Name, Address, City) data is stored in the database of your website, platform or app. Only certain employees can access this by logging in with 2-Factor-Authentication and all communication between server and database is SFTP. Then you can reasonably argue that this data is safe relative to the risk and privacy implications for the data subject.
Suppose; name and address details + sexual preference or political affiliation are stored in the same kind of database. This can be logged in with the company's info@ mail account that both employees and interns have the password to, and data communication is not encrypted. Now it becomes a lot harder to defend that this data is adequately secured, especially compared to the possible consequences for the data subject should there be a data breach.
Articles.
Under the heading articles, I list the measures taken on various topics. This will also be different for each company in connection with widely varying activities, personal data, categories of them and, for example, also the size of the organisation.
By making clear agreements on access to platforms that process personal data, we dare to say that this data is appropriately secured. Partly through personal login, 2-Factor-Authentication, standards on passwords and secure data traffic.
Thus, you treat all places, devices, people, services, platforms and networks in which personal data are processed, used or visible. By establishing rules for the above, you can demonstrate that security and privacy of data subjects have been considered.
It is important to have a good idea of the obligations under the GDPR so that all the necessary elements are included in your privacy policy. For example, in a healthcare organisation where many employees have access to all kinds of special personal data, much stricter measures will need to be taken.
Check that everything covered by accountability is included and you are in possession of an appropriate privacy policy. Note that drafting a privacy policy and implementing it are two completely different and major tasks.
Good luck!
Ready for the next step? We are too.
Want to know what your organisation needs to do to comply with the GDPR? Bob will be happy to help you.
Dit sluit mooi aan...
GDPR : Have you written your statements?
GDPR : AIready prepared?