Go to main content Go to main navigation Go to footer
Back to overview

GDPR : AIready prepared?

By now, you may have heard about the GDPR, the General Data Protection Regulation, and stumbled upon our article orientatively. Both you, and we, and many other organisations, will need to prepare well for the upcoming consequences. Laws and regulations have been lagging behind technological developments and digitalisation for years, resulting in a lack of compliance with the fundamental right to privacy. With this new regulation, the EU wants to catch up and achieve future-proof policies.

Bob ten Vergert - Security officer bij Cube - Oldenzaal
Author Test Engineer | Security & Privacy
Reading time
3 min
Image without description

We walk you through the GDPR.

At Cube, we are busy breathing life into an GDPR-resistant policy. With a mixed internal team, my job includes getting our organisation and customers ready for what is to come.

Well our technical team contains no miracle of law, which makes the vaguely worded regulation sometimes tedious to interpret. The GDPR may require that the wording of your privacy notice be written in simple language, but the regulation itself is not.

The guideline is about 100 pages, but with all the references and cross-references, it is more like 6,000.

Therefore, we decided to turn both our collection of facts and the full preparation for the GDPR into informative blog posts. That way, we will all soon understand how the legislation works and learn to manage everything better.

The foundation of the regulation.

The basis for data protection lies with the data subject, a natural person and citizen of the EU. This owner of personal data will soon be able to exert much more influence on the processor of this data. This processor must comply with a range of brand-new obligations, and the financial consequences of failure in this provision are significantly increased.

For a crisp framework of the new privacy law, you must first get to know the players. The following three roles are the common thread of the regulation to which all rights and obligations can be traced;

The data subject is the natural person who can be directly or indirectly identified, the one to whom the personal data relates. The controller is the party who determines the purposes and means of processing personal data. The processor is the party processing the personal data on behalf of the controller.

The main implications and changes of this change in the law are in a convenient summary ready for consumption. If you want to know more about a specific proposition, most contain an in-depth link for lusty readers.

Image without description

The GDPR; short and sweet.

1. The term personal data is greatly expanded, bringing activities under the new privacy law much faster.

2. Privacy statements should be offered more transparent and detailed. In simple language, it should explain what you collect personal data for, under which right it is processed and how long and where it is stored.

3. All data leaks should be registered, including those that do not have to be reported. A data leak already occurs when, for example, an unauthorised person gains access to certain personal data.

4. All processing of personal data should be kept in a register. This applies even to trivial information such as personnel records or the newsletter mailing list.

5. A processor agreement should be concluded with all suppliers and customers with whom personal data are communicated. This contains agreements on handling and securing personal data.

6. Failure to comply with the requirements of the new GDPR legislation could result in huge fines, ranging up to 20 million or 4% of a company's global annual turnover.

7. If you process large amounts of personal data or systematically observe people, you are obliged to appoint a Data Protection Officer (FG).

8. Even if you do not need to appoint an FG, it is a good idea to make someone responsible for compliance with privacy legislation. We even opted for several people.

9. When there are potential risks involved in processing personal data, it will soon become mandatory to carry out a Privacy Impact Assessment (PIA) before such processing.

10. Data minimisation is at the heart of the GDPR, which means that soon only the most essential data may be collected and kept. If the purpose can be achieved with less personal data, you are obliged to do so.

11. In doing so, no personal data may soon be stored longer than necessary. As soon as the purpose has been achieved, the required data must be deleted (with the exception of certain data for tax purposes).

12. Every product, software and services will soon have to take privacy into account from the first day of production. This is called 'Privacy by design'. At every step, privacy aspects must be named and taken into account in the design.

13. Every product, software and services will soon have to be set by default on the day of release to ensure as much privacy as possible. This is called 'Privacy by default'.

14. A privacy policy that ensures maximum security of personal data helps your organisation demonstrate GDPR compliance. Think about limiting access, securing communications and informing your employees.

15. Proper security of personal data becomes an obligation; where things like data encryption, two-factor authentication and the infrastructure to securely edit, separate and delete data are not a luxury.

16. Indeed, that infrastructure is also important for complying with requests from data subjects. Indeed, they may request, delete and edit any data related to them. An organisation is obliged to respond in writing or by e-mail to a request for inspection within 4 weeks and to handle it within a reasonable time.

17. Can data subjects store personal information in an online service? If so, there should be an option whereby one can export all information in a standard format, to transfer to another organisation. The right to data portability.

18. Foreign parties may no longer process personal data of European citizens without strict regulation and approval from the European Commission. There are a number of approved countries with an adequate level of protection.

19. Are interest profiles or risk analyses of customers and/or visitors being made? Then you are obliged to explain to them, in your privacy statement, exactly how this is done and for what purpose. This applies to all possible processing of personal data.

20. Do you collect special personal data? Even much stricter rules apply to this. You could think of certain medical and biometric data. Besides being directly identifiable, anything that can be discriminated against falls under special personal data.

As you have seen, what is being implemented is not nothing and is going to have far-reaching implications for organisations of all varieties. A survey by Compuware shows that almost 70% of companies are far from prepared for the GDPR, and 45% have barely even heard of it.

Keep an eye on Cube for the next post on our GDPR preparation. Left with a question following my post? Our contact details can be found here.

Good luck!

Cube is ISO 27001 gecertificeerd

Need help with the GDPR? Get in touch.

Do you have questions about the GDPR or want to know how to prepare your organisation for it? Our team is ready to help you navigate through these regulations.

Worth reading next...