General Data Protection Regulations (GDPR)
[edit] Introduction
On 25 May 2018, the EU General Data Protection Regulation (GDPR) replaced the Data Protection Directive 95/46/EC.
GDPR was designed to harmonise data privacy laws across Europe, to protect and empower all EU citizens' data privacy and to reshape the way organisations across the region approach data privacy.
[edit] What is GDPR?
GDPR resulted from EU legislation which updated data protection legislation into line with the numerous ways that data is now used. Hitherto, the UK abided by the Data Protection Act 1998. This was superseded by the GDPR legislation and ushered in higher penalties for breaches and non-compliance.
[edit] What are the aims and benefits of GDPR?
Put simply, GDPR was designed to give the public more say over which organisations have access to their data and what they do with it. GDPR will apply to personal data.
GDPR was aimed at protecting all EU citizens from privacy and data breaches in an increasingly data-driven world that is vastly different from the time in which the 1995 directive was established.
Although the key principles of data privacy still hold true to the previous directive (95/46EC), many changes have been proposed to the regulatory policies; the key points of the GDPR as well as information on the impacts it will have on business can be found below.
[edit] What are the key changes?
The key changes are provided under the GDPR website, and it is advised to visit this portal for the most up-to-date information to ensure you and/or your organisation are compliant. However, the key changes are described as:
[edit] Increased Territorial Scope (extra-territorial applicability)
GDPR applies to all companies processing the personal data of data subjects residing in the European Union, regardless of the company's location.
[edit] Penalties
Organisations in breach of GDPR can be fined up to 4% of annual global turnover or €20 million (whichever is greater). This is the maximum fine that can be imposed for the most serious infringements
[edit] Consent
Companies will no longer be able to use long illegible terms and conditions full of legalese, as the request for consent must be given in an intelligible and easily accessible form, with the purpose for data processing attached to that consent (EUGDPR.ORG Portal, 2018).
[edit] Roles: 'Controller' or 'Processor'
In considering who GDPR applies to, the terms 'controllers' and 'processors' are used. To provide a simple definition:
- Controllers determine the purposes and means of processing personal data.
- Processors are responsible for processing personal data on behalf of a controller.
As a processor, GDPR places specific legal obligations to maintain records of personal data and processing activities. The processor will have legal liability and be responsible for a breach.
For Controllers, GDPR places further obligations on you to ensure your contracts with processors comply with the GDPR.
[edit] Data subject rights
Under GDPR, organisations must consider how they store personal data and organise themselves appropriately. For data subject rights, this includes:
- Breach Notification to become mandatory in all EU member states where a data breach is likely to "result in a risk for the rights and freedoms of individuals". This must be done within 72 hours of first having become aware of the breach. Data processors will also be required to notify their customers, the controllers, "without undue delay" after first becoming aware of a data breach.
- Right to access is the right for data subjects to obtain from the data controller confirmation as to whether or not personal data concerning them is being processed, where and for what purpose. Further, the controller shall provide a copy of the personal data, free of charge, in an electronic format.
- Right to be forgotten/Data erasure entitles the data subject to have the data controller erase his/her personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data.
- Data portability is the right for a data subject to receive the personal data concerning them, which they have previously provided in a 'commonly used and machine readable format' and have the right to transmit that data to another controller.
- Privacy by design calls for the inclusion of data protection from the onset of the designing of systems, rather than an addition. More specifically - 'The controller shall..implement appropriate technical and organisational measures..in an effective way.. in order to meet the requirements of this Regulation and protect the rights of data subjects'.
- Under GDPR, Data Protection Officers (DPO) will not be required to submit notifications / registrations to each local DPA of data processing activities. Instead, there will be internal record-keeping requirements. DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences.
[edit] Will GDPR matter for organisations in the UK after Brexit?
If companies in the UK process data about individuals in the context of selling goods or services to citizens in other EU countries then they will need to comply with the GDPR, irrespective as to whether or not the UK retains the GDPR post-Brexit.
[edit] What should you do next?
GDPR came into effect from 25 May 2018. Organisations must continue to plan and consider how their existing practice might result in a data breach, or result in them being judged 'non-compliant'.
[edit] About this article
This article was written by Adam Kirkup. It was previously published on the website of ICE in January 2018 and can be accessed HERE.
More articles by ICE on Designing Buildings Wiki can be accessed HERE.
--Institution of Civil Engineers
[edit] Related articles on Designing Buildings Wiki
Featured articles and news
New apprentice pay rates coming into effect in the new year
Addressing the impact of recent national minimum wage changes.
EBSSA support for the new industry competence structure
The Engineering and Building Services Skills Authority, in working group 2.
Notes from BSRIA Sustainable Futures briefing
From carbon down to the all important customer: Redefining Retrofit for Net Zero Living.
Principal Designer: A New Opportunity for Architects
ACA has launches a Principal Designer Register for architects.
A new government plan for housing and nature recovery
Exploring a new housing and infrastructure nature recovery framework.
Leveraging technology to enhance prospects for students
A case study on the significance of the Autodesk Revit certification.
Fundamental Review of Building Regulations Guidance
Announced during commons debate on the Grenfell Inquiry Phase 2 report.
CIAT responds to the updated National Planning Policy Framework
With key changes in the revised NPPF outlined.
Councils and communities highlighted for delivery of common-sense housing in planning overhaul
As government follows up with mandatory housing targets.
CIOB photographic competition final images revealed
Art of Building produces stunning images for another year.
HSE prosecutes company for putting workers at risk
Roofing company fined and its director sentenced.
Strategic restructure to transform industry competence
EBSSA becomes part of a new industry competence structure.
Major overhaul of planning committees proposed by government
Planning decisions set to be fast-tracked to tackle the housing crisis.
Industry Competence Steering Group restructure
ICSG transitions to the Industry Competence Committee (ICC) under the Building Safety Regulator (BSR).
Principal Contractor Competency Certification Scheme
CIOB PCCCS competence framework for Principal Contractors.
The CIAT Principal Designer register
Issues explained via a series of FAQs.
Comments
Great posts and info! You might be interested in our new article about GDPR in construction. Check it out and find there many helpful details! https://geniebelt.com/blog/gdpr-in-construction