A nutshell guide to the GDPR privacy shakeup: Are you affected?
In general, the new GDPR regulations are mainly about how you handle personal data within your business and require changes to your business processes if you deal with any EU personal data.
You may not know if you are affected so here is a guide to understanding the latest privacy law affecting many Australian businesses.
GDPR stands for General Data Protection Regulation which is designed to provide consistent data protection for individuals in 28 EU states. It is seen to be one of the strictest and far reaching privacy and data protection regimes in the world once it is in force.
Set to come into operation 25 May, the GDPR requires a new set of obligations on businesses that collect, use, store and process EU personal data including businesses that provide services seen to โprocessโ data on behalf of another business. This will catch many hosting and processing businesses.
โPersonal dataโ generally means information that may identify an individual such as an email address.
The GDPR law is wide reaching and covers other countries, including Australian businesses which may have or be seen to be collecting any type of EU resident personal data.
You need to comply with the GDPR regulations if you:
There are some similarities: both the GDPR and Australian privacy laws include some similar requirements as both laws foster transparent information handling practices and business accountability, to give individuals confidence that their privacy is being protected.
However, there are a number of new obligations and rights that are imposed on any business in any country including Australia, when dealing with EU resident personal data including:
Australian businesses should review their data processing practices to identify whether, and to what extent, the GDPR applies to them.
If you are required to comply with the GDPR, you need to familiarise yourself with the accountability and governance requirements and put processes to meet the requirements into your business. In other words, you need to understand what these compliance requirements are and put in place measures to comply on or before 25 May.
You also need to be able to show that your processes to manage the personal data requirements will comply. This may include, for example, obtaining consent for the use of the personal data from the EU citizen depending on what and how you use it.
As the new GDPR regulations and requirements are dependent on how each individual business collects and uses data as well as the type of personal data collected, there is no one-stop-shop answer on what your business needs to do to comply. You need to look at your business to see if you are marketing your products or services to EU individuals and if so, understand your compliance requirements for your business to meet the GDPR.
Alternatively, if you do not need to comply with the GDPR, you should consider including a statement on your website that you are excluding EU residents from purchasing your products or services to make it clear that you are not marketing to EU residents.
There are high fines for non-compliance with GDPR so review your business today.
Comments