LexGo

European General Data Protection Regulation: 10 things You should know before the Christmas break
23/12/2015

While some people never stopped believing that the General Data Protection Regulation ("GDPR") would one day become a reality, others had started to despair as more and more time passed. Indeed, the European Commission's initial proposal dates back to 25 January 2012!  Finally, however, almost four years later, the European institutions have agreed on a final text.

It goes without saying that the GDPR is a lengthy document, and it will take some time to examine the practical implications for businesses. In order not to spoil your - and our - holidays, we've decided to wait until next year to provide you with an in-depth analysis and have limited this newsflash to 10 key points:

  1. NO, you don't have to cancel your Christmas plans in order to start implementing the GDPR within your organisation right away. In fact, once the GDPR is published in the Official Journal of the European Union, in early 2016, it will not apply for another two years.
  2. NO, data processing activities will not be regulated by the GDPR alone. Member States will still be able to lay down specific rules in their national law.
  3. NO, you will no longer need to notify your data processing activities to the national data protection authority. Instead, certain processing activities will be subject to a data protection impact assessment ("DPIA"). The national data protection authorities will prepare lists of processing activities for which a DPIA is required.
  4. NO, you will not be obliged to appoint a data protection officer unless your core activities require regular, systematic monitoring of data subjects on a large scale or entail the processing of sensitive data on a large scale.
  5. YES, you will need to keep records of all processing activities and be able to provide them to the data protection authorities upon request. An exception applies to organisations with fewer than 250 employees provided (i) the processing is not likely to give rise to a risk to the rights and freedoms of the data subjects, (ii) the processing is occasional, and (iii) no sensitive data are processed.
  6. YES, you will need to review your privacy policies and fair processing notices to ensure they are drafted in clear and plain language and contain all required information. The GDPR indeed requires that more information be provided to data subjects than is currently the case under the Data Protection Directive (95/46) (e.g. the legitimate interests pursued, if the processing is based on this ground, the retention period, etc.).
  7. YES, if, in the context of offering information society services (eg video on demand, chatrooms, online sales), you process the personal data of children below the age of 16 on the basis of consent, such consent must be given or authorised by their parents. Member States may lower this age threshold to 13.
  8. YES, you will need to review your data processing agreements to ensure that they contain all required information. The GDPR indeed requires that more information be included in data processing agreements than is currently the case under the Data Protection Directive (95/46) (e.g. conditions for enlisting sub-processors).
  9. YES, you will need to notify any data breaches to the data protection authority within 72 hours after becoming aware of them; in some cases, the data subjects must also be informed.
  10. Last but not least, YES, violations of the GDPR will be severely sanctioned, with fines of up to EUR 20,000,000 or, for legal entities, up to 4% of the company's total worldwide annual turnover for the preceding financial year, whichever is greater.

We would like to extend our very best wishes to you and your family. We'll be back in 2016 with detailed recommendations and tips to help you tackle the GDPR. In the meantime, enjoy your holidays.

Related : Nautadutilh Avocats Luxembourg Sàrl ( Mr. Vincent Wellens )

[+ http://www.e-nautadutilh.com/56/1942/landing-pages/10-things-you-should-know-before-the-christmas-break.asp?sid=7bc05ec9-0501-4db2-9e96-36a4a5556ae2]

Mr. Vincent Wellens Mr. Vincent Wellens
Partner
[email protected]

Lastest articles by Mr. Vincent Wellens

Insufficient cybersecurity measures under GDPR: 100k EUR fine in Belgium & key fines elsewhere
29/04/2021

On 26 April 2021, the Litigation Chamber of the Belgian Data Protection Authority (BDPA) handed down its first fine specif...

Read more

Regulatory changes in the audiovisual media sector
16/04/2021

The Act of 26 February 2021 and certain grand ducal regulations have transposed into Luxembourg law the Audiovisual Media ...

Read more

New bill brings Luxembourg to the forefront of distributed ledger technology
17/03/2021

On 22 January 2021 Parliament approved Bill 7637, which modified:  the Law of 5 April 1993 on the financial sec...

Read more

The Sky Is Not the Limit: Space Activities in Luxembourg
15/02/2021

At the end of 2020, Luxembourg adopted the Act of 15 December 2020 on space activities (loi du 15 décembre 2020 por...

Read more

LexGO Network