Options
Language
Look
Color

Your choices are saved in this browser only.

  1. Home
  2. GDPR Policy
Legal information

GDPR Policy

What the General Data Protection Regulation is and when it applies.

When does the General Data Protection Regulation apply?

The GDPR applies if:

  • your company processes personal data and is based in the EU, regardless of where the actual data processing takes place
  • your company is based outside the EU but processes personal data in the context of providing goods or services to citizens in the EU, or monitors the behavior of citizens in the EU

Companies based outside the EU that process personal data of European citizens must appoint a representative in the EU.

When does the General Data Protection Regulation not apply?

The GDPR does not apply if:

  • the data relates to a deceased person
  • the data relates to a legal entity
  • the data is processed by a person acting for purposes outside their commercial or professional activity

What is personal data?

Personal data is any information about an identified or identifiable person (the data subject). Personal data includes:

  • name
  • address
  • ID card/passport number
  • income
  • cultural profile
  • IP (Internet Protocol) address
  • data held by doctors or hospitals (which identifies a person for medical purposes)

Special categories of data

You may not process data relating to:

  • racial or ethnic origin
  • sexual orientation
  • political opinions
  • religious or philosophical beliefs
  • trade union membership
  • genetic, biometric or health data, except in specific cases (for example, when the person has given explicit consent or when the processing is necessary for reasons of substantial public interest, as defined by European or national law)
  • personal data relating to criminal offenses or convictions, unless this is authorized by national or European law

Who processes personal data?

During processing, personal data can pass through several companies or organizations. Two important parties are involved in this process:

  • the data controller - decides the purpose for which personal data will be processed
  • the data processor - holds and processes data on behalf of the data controller

Who monitors how data is processed within a company?

The Data Protection Officer (DPO), if the company has appointed one, monitors how personal data is processed and informs the employees who process personal data about their obligations. The data protection officer also cooperates with the Data Protection Authority (DPA), acting as a contact point for the authority and for citizens.

When should you appoint a data protection officer?

Your company is required to appoint a data protection officer when it:

  • monitors citizens regularly or systematically, or processes special categories of data
  • processes data as its main activity
  • processes data on a large scale

For example, if you process personal data to send advertising through search engines based on users' online behavior, you are required to appoint a data protection officer. If you send promotional materials once a year, only to your customers, this obligation does not apply. Similarly, if you are a doctor and collect data about your patients' health, you probably will not need a data protection officer. However, if you process personal data relating to genetics and health on behalf of a hospital, appointing a data protection officer will be mandatory.

The data protection officer can be a member of your organization or a person contracted externally under a service contract. It can also be part of an organization, not necessarily an individual.

Processing data for another company

The data controller may authorize a data processor to handle the data processing only if the processor provides sufficient guarantees. These guarantees must be included in a written contract between the parties involved. The contract must also contain a number of mandatory clauses, for example that the processor will process data only when the data controller asks it to.

Transferring data outside the EU

When personal data is transferred outside the EU, the protection provided by the GDPR should “travel” with it. This means that if you export data abroad, your company must make sure that at least one of the following provisions is in place:

  • the EU considers the protection offered by the non-EU country to be adequate
  • your company takes the necessary measures to provide adequate protection, for example by including specific clauses in the contract agreed with the data importer outside the EU
  • your company relies on specific derogations that allow the transfer, such as the person's consent

When is data processing allowed?

Under EU data protection rules, you should process data fairly and lawfully, for a specific and legitimate purpose, and only the data needed to fulfill that purpose. To process personal data, you must meet one of the following conditions:

  • you have the consent of the data subject
  • you need the personal data to honor a contractual obligation to the person concerned
  • you need the personal data to fulfill a legal obligation
  • you need the personal data to protect the vital interests of the data subject
  • you process personal data to carry out a task in the public interest
  • you are acting in the legitimate interest of your company, as long as the fundamental rights and freedoms of the people whose data is processed are not seriously affected. If the person's rights override your company's interests, you cannot process the personal data.

Agreeing to data processing: consent

The GDPR sets strict rules for processing data on the basis of consent. The purpose of these rules is to ensure that the data subject understands what they are consenting to. This is why consent must be freely given, specific, informed and unambiguous, through a request presented in clear and plain language. Consent must be given through a positive act, such as checking a box online or signing a form.

When a person agrees to the processing of their personal data, that data may be processed only for the purpose for which consent was obtained. You must also give the person the option to withdraw their consent.

Providing transparent information

You must give data subjects clear information about the entity processing the personal data and the purpose of that processing. At a minimum, you must state:

  • who you are
  • why you are processing personal data
  • what legal basis you are relying on
  • who will receive the data (if applicable)

In some cases, the information you provide must include:

  • the contact details of the data protection officer (if there is one)
  • what legitimate interest your company pursues when it processes data on the legal basis it invokes
  • what measures apply when the data is transferred to a country outside the EU
  • how long the data will be stored
  • what data protection rights the person has (the right of access, correction, erasure, restriction, objection, portability, etc.)
  • how consent can be withdrawn (when consent is the legal basis for the processing)
  • whether there is a legal or contractual obligation to provide the data
  • in the case of automated decision-making, information about the logic, significance and consequences of the decision

You must present this information in clear and plain language.

Specific rules for children

If you collect personal data from children on the basis of consent, for example through a social network account or a download account, you must first obtain parental consent by sending a notification to the parent or guardian. The age up to which a person is considered a child varies from country to country, ranging from 13 to 16 years.

Right of access and right to data portability

You must make sure that data subjects have the right of free access to their personal data. If you receive such a request, you must:

  • tell the person concerned that you are processing their data
  • give them details about the processing (the purpose of the processing, the categories of personal data concerned, the recipients of the data, etc.)
  • send them a copy of the personal data being processed (in an accessible format)

When the data processing is based on consent or on a contract, the data subject can ask for their personal data to be returned to them or transmitted to another company. This is known as the right to data portability. You must provide the data in a commonly used, machine-readable format.

Right to correct data and right to object

If a person believes that their personal data is incorrect, incomplete or inaccurate, they have the right to have it corrected or completed without delay.

In this case, you must inform all recipients of the data if any of the data you shared with them has been modified or deleted. If some of the shared data turned out to be incorrect, you must inform everyone who viewed it (unless this would involve a disproportionate effort).

A person can object at any time to the processing of their personal data when the company processes that data on the basis of its own legitimate interest or to carry out a task in the public interest. If you do not have a legitimate interest that overrides the interest of the data subject, you must stop processing the personal data.

A person can also ask for the processing of their personal data to be restricted while it is being determined whether your company's interest overrides theirs. However, in the case of direct marketing, you are always required to stop processing the personal data if the person concerned asks you to.

Right to erasure (“right to be forgotten”)

In certain situations, a person can ask the data controller to erase their personal data, for example if the data is no longer needed for the purpose of the processing. However, your company is not required to do so if:

  • the processing is necessary to respect freedom of expression and information
  • you must keep the personal data to comply with a legal obligation
  • there are other public interest reasons that justify storing the data, such as those related to public health or to scientific and historical research
  • you must store the personal data for possible legal action

Automated decision-making and profiling

Citizens have the right not to be subject to a decision based solely on automated processing. However, there are a few exceptions to this rule, for example when the person explicitly accepts the automated decision. Unless the automated decision is based on a law, your company must:

  • inform the person about the automated decision-making
  • give the person the right to ask for the automated decision to be reviewed by a human
  • give the person the option to contest the automated decision

For example, if a bank automates the decision on whether a particular person can get a loan, that person must know that the decision was automated and must be able to contest it and ask for human intervention.

Data breaches: providing proper notification

A data breach occurs when personal data you are responsible for is disclosed, accidentally or unlawfully, to unauthorized recipients, when the data is altered, or when access to the data is temporarily interrupted.

If a data breach occurs that poses a risk to individual rights and freedoms, you must notify the Data Protection Authority within 72 hours of discovering the breach.

Depending on the consequences of the data breach, your company may be required to inform all the people affected.

Responding to requests

If your company receives a request from a person who wants to exercise their rights, you must respond as quickly as possible, and no later than 1 month after receiving the request. The time to respond can be extended to up to 2 months for complex or multiple requests, as long as the person concerned is informed of the extension. Requests must be handled free of charge.

If the request is rejected, you must tell the person concerned the reasons for the rejection and inform them of their right to lodge a complaint with the Data Protection Authority.

Impact assessment

A data protection impact assessment is mandatory whenever the processing would pose a high risk to fundamental rights and freedoms, for example when new technologies are used.

Such a risk arises when:

  • automated processing and profiling mechanisms are used to evaluate people
  • a publicly accessible area is monitored on a large scale (e.g. closed-circuit television)
  • special categories of data, or personal data relating to criminal offenses and convictions, are processed on a large scale (e.g. health data)

Note: Data protection authorities may consider that other categories of data processing can also pose a high risk.

If the measures set out in the impact assessment do not eliminate all the high risks identified, you must consult the Data Protection Authority before the data processing takes place.

Records of processing

Your company must be able to show that it acts in accordance with the GDPR and meets all its applicable obligations, in particular at the request of the Data Protection Authority or during its inspections.

One way to do this is to keep detailed records of:

  • the name and contact details of the entity involved in the data processing
  • the reason(s) for the data processing
  • a description of the categories of people who provide personal data
  • the categories of organizations that receive the personal data
  • transfers of personal data to another country or organization
  • the storage period for the personal data
  • a description of the security measures used when processing the personal data

Your company should keep written procedures and guidelines, update them periodically and communicate them to employees.

If you own an SME or an even smaller company, you do not need to keep records of your data processing activities, as long as they:

  • are carried out periodically
  • do not affect the rights or freedoms of data subjects
  • do not involve sensitive data or criminal records

Data protection by design and by default

Data protection by design: your company must take data protection into account from the earliest stages of planning a new way of processing personal data. Under this principle, the data controller must take all the technical and organizational measures needed to implement the data protection principles and to protect the rights of data subjects. These measures could include, for example, the use of pseudonymization.

Data protection by default: the company should make the settings that provide the highest level of data protection the default ones. For example, if two settings are possible and one of them prevents third parties from accessing the personal data, that one should be used as the default setting.

Violations and penalties

Failure to comply with the GDPR can lead to fines of up to EUR 20 million or 4% of your company's global turnover. The Data Protection Authority can impose additional corrective measures, for example by requiring you to stop processing personal data.

Let's talk

Got a project or an IT problem? We are here.

Call us, email us or message us on WhatsApp. We reply promptly, with a solution and a quote that fit you.