GDPR (General Data Protection Regulation)
The GDPR (General Data Protection Regulation) is an EU (European Union) Regulation that significantly enhances the protection of the personal data of EU citizens and increases the obligations on organizations who collect or process personal data. The regulation builds on many of the 1995 Directive’s requirements for data privacy and security but includes several new provisions to bolster the rights of data subjects and add harsher penalties for violations. The regulation came into effect on May 25th, 2018.
The GDPR applies to businesses that a) market their products to people in the EU or who b) monitor the behavior of people in the EU. In other words, even if you’re based outside of the EU but you control or process the data of EU citizens, the GDPR will apply to you.
The GDPR steps up the standard for disclosures when obtaining consent, as it needs to be “freely given, specific, informed and unambiguous,” with controllers using “clear and plain” legal language that is “clearly distinguishable from other matters”. Controllers will also be required to provide evidence that their processes are compliant and followed in each case.
Essentially, your customer cannot be forced into consent, or be unaware that they are consenting to process of their personal data. They must also know exactly what they are consenting to and they must be informed in advance of their right to withdraw that consent. Obtaining consent requires a positive indication of agreement – it cannot be inferred from silence, pre-ticked boxes, or inactivity. This means that informing the user during the opt-in is becoming more important.
New Rights for Individuals
The regulation also builds in two new rights for data subjects: a "right to be forgotten" that requires controllers to alert downstream recipients of deletion requests and a "right to data portability" that allows data subjects to demand a copy of their data in a common format. These two rights make it easier for users to request that any information stored should be deleted or that information that has been collected should be shared with them.
Data subjects always had a right to request access to their data. But the GDPR enhances these rights. In most cases, you will not be able to charge for processing an access request, unless you can demonstrate that the cost will be excessive. The timescale for processing an access request will also drop to a one-month period (but this can be extended a further two months in some circumstances. In certain cases, organizations may refuse to grant an access request, for example where the request is deemed manifestly unfounded or excessive. However, organizations will need to have clear refusal policies and procedures in place, and demonstrate why the request meets these criteria.
Privacy by Design and DPIA
There are several new principles for entities that handle personal data, including a requirement to build in data privacy "by design" when developing new systems and an obligation to perform a Data Privacy Impact Assessment (DPIA) when processing using "new technologies" or in risky ways. A DPIA is a process of systematically considering the potential impact that a project or initiative might have on the privacy of individuals so that potential privacy issues can be identified before they arise, giving the organization time to come up with a way to mitigate them before the project is underway.
Data Privacy Officer
On the security side, the GDPR requires many businesses to have a Data Privacy Officer (DPO) to help oversee their compliance efforts. Organizations requiring DPOs include public authorities, organizations whose activities involve the regular and systematic monitoring of data subjects on a large scale, or organizations that process sensitive personal data on a large scale.
Contracts & Privacy Documentation
Since the GDPR is all about transparency and fairness, Controllers and Processors need to review their Privacy Notices, Privacy Statements, and any internal data policies to ensure they meet the requirements under the GDPR. If a Controller engages third-party vendors to process the personal data under their control, they need to ensure their contracts with those Processors are updated to include the new, mandatory Processor provisions set out in Article 28 of the Regulation. Similarly, Processors should consider what changes they’ll need to make to their customer contracts to be GDPR compliant.
One particular item in the GDPR should serve to make the lives of these Data Protection Officers easier: the GDPR’s new "one-stop shop" provision, under which organizations with offices in multiple EU countries will have a "lead supervisory authority" to act as a central point of enforcement so they don’t struggle with inconsistent directions from multiple supervisory authorities.
The GDPR contains a requirement that controllers must notify their country’s supervisory authority of a personal data breach within 72 hours of learning of it unless the data was anonymized or encrypted. In practice, this will mean that most data breaches must be reported to the Data Protection Commissioner. Breaches that are likely to bring harm to an individual – such as identity theft or breach of confidentiality – must also be reported to the individuals concerned.
The GDPR applies to non-EU businesses who market their products to people in the EU or who monitor the behavior of people in the EU. In other words, even if you’re based outside of the EU but you control or process the data of EU citizens, the GDPR likely applies to you.
This concept requires Controllers and Processors to be able to demonstrate their compliance with the GDPR to their local supervisory authority. Processes should be recorded, implemented, and reviewed on a regular basis. Staff should be trained and appropriate technical and organizational measures should be taken to ensure and demonstrate compliance.
A person who lives in the EU
Any information related to an identified/identifiable data subject (e.g., name, national ID number, address, IP address, health info)
A company/organisation that collects people’s personal data and makes decisions about what to do with it. So if you’re collecting personal data and are determining how it will be processed (for example using the HubSpot services to market to prospects and customers), you’re the Controller of that data and must comply with applicable data privacy legislation accordingly.
A company/organisation that helps a controller by “processing” data based on its instructions, but doesn’t decide what to do with data. So for example, HubSpot is the processor of the data you collect in your HubSpot portal. We don’t control how you collect or use the data; we merely process it on your behalf and on your instruction.
Any operation or set of operations which is performed on personal data or on sets of personal data, by automated means or otherwise, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Protection Officer (DPO)
A representative for a controller/processor who oversees GDPR compliance and is a data-privacy expert
Data Privacy Impact Assessment (DPIA)
A documented assessment of the usefulness, risks, and risk-mitigation options for a certain type of processing
Formerly called “data protection authorities”; one or more governmental agencies in a member state who oversee that country’s data privacy enforcement (e.g., Ireland’s Office of the Data Protection Commissioner, Germany’s 18 national/regional authorities)
Countries outside the EU
Standard Contractual Clauses
The SCCs, a/k/a “model clauses” are standardized contract language (approved by the European Commission) that is one method of permission for controllers/processors to send personal data to third countries. The SCCs are included in Exhibit 1 of our Data Processing Agreement).