
Do you know which fines to expect for driving a GDPR non-compliant website?
⠀
Neither do I, that’s why I am studying the new General Data Protection Regulation of the European Union.
⠀
✅ comes into force on 25 May 2018;
⠀
✅ directly applicable to all companies operating in the EU;
⠀
✅ also for exclusively Swiss companies without branches in the EU;
⠀
✅ even outside of the EU so long as your company dealing with data of EU residents.
⠀
What does it need to do?
⠀
1️⃣ Update Terms and Conditions.
⠀
2️⃣ Publish GDPR compliant data protection rules and policies.
⠀
3️⃣ Both will have to be approved by all existing and all new users of your website.
⠀
4️⃣ Implement the possible to protect data and do not query unnecessary data.
⠀
5️⃣ Appoint a Data Protection Officer, if necessary.
⠀
6️⃣ Create a table of processing activities and their purpose, there you can list what data was collected, when, how and why in your company.
⠀
7️⃣ Conduct Privacy Impact Assessment. Only if you work with highly sensitive data, like a doctor or an insurance company.
⠀
? Further information comes. Is the topic relevant for you?