Late To Comply with GDPR? 下面是你现在可以采取的三个步骤.

Background

The European Union’s (EU) General Data Protection Regulation (GDPR) goes into effect on May 25, 2018. The regulation is specific to the protection of natural persons with regard to the processing of personal data and on the free movement of such data. The regulation applies to any organization doing business in the EU or that processes personal data originating in the EU, 无论是居民还是访客的数据.

GDPR深刻改变了人们对隐私的理解, data protection and personal data in the EU and has wide-ranging effects on anyone processing personal data of data subjects of the EU. A data subject is defined as a person whose personal data is being captured and processed. If your organization captures just one record of an EU data subject, this regulation applies to you.

Penalties for failing to comply with the articles of GDPR may subject the organization to fines up to €20m or 4% of the organization's total global revenue, whichever is greater. 如果您的组织还没有开始确保遵从性的过程, there are certain highly effective steps that you can take immediately to bring your compliance program to life. 下面是一些开始的步骤和建议.

Raise Awareness

If your organization is late to the GDPR party, chances are there is an awareness issue. Complying with GDPR means taking meaningful actions to change the way your employees use personal data within your business, including being able to respond to incidents and breaches that affect that personal data. 意识过程通过解释来支持所有其他过程, communicating and reinforcing both GDPR requirements and good practice. Therefore, raising awareness of the GDPR at all levels of the organization is imperative.

分类及识别个人资料

Understanding the data that you hold is one of the key steps in understanding how to design a program for GDPR compliance. Your organization should take a multi-disciplinary approach to this process and work with various stakeholders such as business lines, operations, technology, data and analytics departments, 人力资源和潜在的其他人, based on your business.

You should work to examine and map out your organization’s processes and data flows to identify any data inputs that may be linked to an identified (or indirectly identifiable) person. Where this is the case, the process or procedure handling the data must be identified and inventoried. It is also important to understand that this also applies to paper-based processing of data, for instance, 通过邮寄或其他纸质形式填写的表格. The output of this phase should include business process documentation, data flow diagrams, 个人资料登记册及资料处理登记册.

执行数据保护影响评估

考虑上一步的输出, performing a Data Protection Impact Assessment (DPIA) should be your next step. GDPR要求在某些情况下执行DPIA(例如.g., processing of special categories of data, large scale data processing, etc.). 为了描述数据处理,应该设计一个DPIA, assess the necessity and proportionality of processing of that data and determine compliance with the GDPR requirements. The assessment should also ensure that the risks to personal data are properly mitigated and the safeguards and security measures in place to protect personal data are appropriate in relation to the risk. Any risks to personal data that are not appropriately mitigated should have a risk treatment plan assigned to them and be tracked through remediation.

If you have any questions related to your organization’s compliance with GDPR, 请致电412-697-5285联系丹·德斯科或 [email protected].

你们已经听到了我们的想法,我们也想听听你们的想法

The Schneider Downs Our Thoughts On blog exists to create a dialogue on issues that are important to organizations and individuals. 虽然我们喜欢分享我们的想法和见解, 我们对你要说的特别感兴趣. If you have a question or a comment about this article – or any article from the Our Thoughts On blog – we hope you’ll share it with us. After all, a dialogue is an exchange of ideas, and we’d like to hear from you. Email us at [email protected].

所讨论的材料仅供参考, 而且这不能被理解为投资, tax, or legal advice. 请注意,个别情况可能有所不同. Therefore, this information should be relied upon when coordinated with individual professional advice.

© 2023 Schneider Downs. All rights-reserved. All content on this site is property of Schneider Downs unless otherwise noted and should not be used without written permission.

our thoughts on
OCC在2024财政年度的重点领域是什么?
SEC Charges SolarWinds and CISO Timothy Brown For Misleading Investors
Dynamics社区峰会你错过了什么
三思而后行:虚假浏览器更新又流行起来了
Protect Your Manufacturers: 3 Common Cyber Attack Methods to Watch Out for in 2023
Protect Your Students, Faculty and Staff: 3 Common Cyber Attack Methods to Watch Out for in 2023
Register to receive our weekly newsletter with our most recent columns and insights.
Have a question? Ask us!

We’d love to hear from you. 给我们留言,我们会尽快回复你.

Ask us
contact us
Pittsburgh
Columbus

This site uses cookies to ensure that we give you the best user experience. Cookies assist in navigation, analyzing traffic and in our marketing efforts as described in our Privacy Policy.

×