On 25 May 2018 the General Data Protection Regulation (GDPR) came into force. This Regulation introduces stricter rules for the protection of natural persons in the processing of their personal data. Every data controller or data processor established in a Member State of the European Union is obliged to comply with the provisions of the GDPR. The Regulation also applies to controllers and processors located outside the EU who process the personal data of natural persons who are within the EU. It is immaterial whether the processing activities are carried out within the territory of the EU or outside it.
Personal data means any information that can identify, or make possible the identification of, a natural person. The Regulation refers to such persons as 'data subjects'.
The processing of data covers any operation relating to the collection, recording, organisation, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction of data.
The GDPR grants data subjects a broad range of rights, including the right of access to their personal data, the right to rectification of data, the right 'to be forgotten', the right to data portability, the right to object, and others.
The Regulation also introduces the position of a data protection officer (DPO). This person may be an employee of the controller or the processor, or an external specialist. Their role is to monitor compliance with the requirements of the GDPR and the internal policies relating to data protection.
In the event of a personal data breach, controllers are obliged to notify the supervisory authority.
Every company or non-governmental organisation must carry out an analysis of its processes relating to the processing of personal data, as well as a risk assessment in respect of potential security breaches. It is also important to put in place appropriate policies and procedures for the protection of personal data.
If you have not yet implemented the requirements of the GDPR within your organisation, our team can offer you consultations and prepare the necessary documents and policies for the collection, storage and processing of personal data.

