On May 25, 2018, new rules for processing the personal data of EU citizens will come into effect.
The GDPR (General Data Protection Regulation) is a set of regulations for companies that collect and process the data of European Union users on the Internet. The new regulation aims to increase the level of protection and give citizens control over their data. Failure to comply with the rules will result in heavy fines (up to 4% of annual business revenue, or €20 million).
The requirements of the act apply to both organizations registered in the EU and companies located in other countries, provided that they provide services to EU citizens or otherwise collect data from such users.
Personal data and GDPR: what are they?
Personal data is any information relating to a specific individual that can be used to identify them. According to the GDPR, this includes both information that the user has voluntarily provided to a particular web resource (first and last name, gender, email address, or phone number) and data collected automatically. For example, this includes information about location, device (including IP address), operating system, etc.
In addition, personal data on the Internet includes information about viewed pages, search queries, social media posts, and all information that can be used to determine a user’s preferences and interests, social status, religious beliefs, political views, etc.
Payment details can be classified as a separate group, which are undoubtedly also considered personal data.
All this information is protected by the new GDPR rules.
The GDPR is a regulation (consisting of 99 articles) that governs the relationship between those who provide their personal data (EU citizens) and those who collect, process, and use this data in their work (internet services, web resources, commercial and non-commercial companies, organizations). For more detailed information, please refer to the full text of the GDPR.
New terms: controller and processor
Who is subject to the GDPR rules?
First, let’s look at the terms introduced in the regulation: data controllers and data processors.
Controllers are companies or organizations that collect user data. Processors are companies that process data on behalf of controllers. Controllers bear most of the responsibility and enter into agreements with processors to comply with GDPR rules when processing data transferred by controllers.
Free push notifications for your website
The General Data Protection Regulation standards apply to all companies that provide services to EU citizens, even if they are not physically located in the European Union. These are organizations that offer goods or services:
- in EU currencies with the option of payment;
- in EU languages;
- on EU domain names (e.g., with extensions such as .de, .fr, .cz, etc.).
Organizations that monitor or analyze the online behavior of EU citizens are also liable under the GDPR.
If a controller from the EU transfers its users’ data for processing to a processor outside the European Union, it is required to enter into a contract that regulates the processing of personal data in accordance with GDPR rules. Accordingly, such a processor will also be required to comply with the rules of the act.
In addition, the service processes the data of the client’s subscribers (as a processor):
- Unique identifier (RegID);
- Web session information, which includes data about the browser, IP address, geolocation, cookies, device type, and operating system.
GDPR principles and requirements
The GDPR’s approach to personal data protection is based on eight principles that were documented back in 1980 (in the “Guidelines on Privacy and Transborder Flows of Personal Data”) and approved by both the EU and the US. In the GDPR, they are reflected in seven points:
- Principle of lawfulness, fairness, and transparency. Personal data must be obtained by lawful and fair means with the consent of the data subject.
- Purpose limitation. The purpose of data collection must be specified at the time of collection, and the data must not be used for any purpose other than the original intention.
- Data minimization. The data collected must be adequate for the purposes initially specified. It is prohibited to collect more data than is necessary to achieve the purpose.
- Accuracy. Personal information must be accurate, complete, and up-to-date to the extent necessary for the specified purposes. If such data is deemed inaccurate, it must be deleted or corrected (at the user’s request).
- Storage limitation. Data is stored in a form that allows the user to be identified for no longer than is necessary to fulfill the purposes of processing the information.
- Integrity and confidentiality. Personal data must be protected by security safeguards against risks such as loss or unauthorized access, destruction, use, modification, or disclosure.
- Accountability. The controller is responsible and must be prepared to demonstrate compliance with the measures specified above.
Thus, the controller is obliged to explain the purposes of collecting personal data to users in a simple and accessible form. In addition, they must have easy access to information about their already collected data. The information must be accurate, secure, and stored for a limited time. The controller also undertakes not to collect unnecessary information about the user, but only that which is necessary, for example, to provide high-quality services.
What does the user get?
Under the GDPR, EU citizens have the right to consent to or refuse the collection of data, delete and control personal information that companies collect for business purposes. Overall, the regulation gives users more freedom and control over the information they share with companies.
Let’s outline the rights that users receive:
- the right to know who is processing their personal data and why;
- the right to access their personal information;
- the right to correct personal data;
- the right to erasure, or “the right to be forgotten”;
- the right to restrict or block data processing;
- the right to transfer personal data from one service to another;
- the right to object to data processing;
- the right to personally influence automated collection and profiling systems.
In addition, the GDPR sets specific requirements for forms used to confirm consent to the collection of personal data. In order for the form to comply with the regulations, the user must actively express their will. This means that forms with pre-checked boxes are not acceptable. Furthermore, the user must have easy access to instructions on how to withdraw their consent to data processing.