DO YOU HAVE CLIENTS LIVING IN THE EU? YOU MAY BE SUBJECT TO THE GDPR.

DO YOU HAVE CLIENTS LIVING IN THE EU? YOU MAY BE SUBJECT TO THE GDPR.

The European Union approved the General Data Protection Regulation (“GDPR”) on April 14, 2016. It went into effect May 25, 2018. It is considered to be the largest overhaul of the European Union’s data privacy laws in 20 years.

Who does it effect?

Regardless of whether you are established inside or outside of the EU, any company offering paid or free services or goods to individuals in the EU is subject to the GDPR.

The application of the law does not depend on the size of your firm, but instead, the activities of your firm.

Point of clarification- For EU citizens outside the EU when the data is collected, the GDPR would not apply.

What activities trigger application of the law?

If you collect the personal data, or personally identifiable information, of an EU citizen while they are in the EU, than that data is protected by the GDPR.

What if I am not specifically targeting EU citizens?

Just because an EU citizen comes across your website doesn’t automatically mean that any data gathered from that citizen is subject to the law. Instead, your business must be targeting EU citizens. For example, if your website is in Danish and there are references to Danish users or customers, then your website would be considered targeting marketing and the GDPR would apply. If you were also to accept the Danish kroner and your website had a .dk extension, then this would be more evidence that your business is subject to the GDPR.

I am subject to the GDPR. What kind of data can I process?

The type and amount of personal data you may process depends on the reason you’re processing it and what you want to do with it. Follow these rules:

  • Personal data must be processed in a lawful manner and you must be completely transparent and fair to the individuals whose personal data you’re processing
  • You can’t process personal date for just any reason. You must have specific purposes for processing the data and you must indicate those purposes to the individuals when collecting their personal data. You can’t say there is an “undefined purpose” as to why you are collecting the data.
  • you must collect and process only the personal data that is necessary to fulfil that purpose
  • you must ensure the personal data is accurate and up-to-date, and correct it if not
  • You can’t use the personal data for any other purpose beyond the original purpose of collection.
  • You must store data for the shortest time possible, taking into consideration the reasons why you need to process the data
  • you must install appropriate technical and organizational safeguards that ensure the security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technology

What information must I provide individuals whose personal data I collect?

At the time of collecting their data, individuals must receive very clear and concise information on:

  • who your company is, including contact information;
  • why your company will be using their personal data;
  • the categories of personal data collected;
  • the legal justification for processing their data;
  • for how long the data will be kept;
  • who else might receive it;
  • whether their personal data will be transferred to a recipient outside the EU;
  • that they have a right to a copy of the data (right to access personal data) and other basic rights in the field of data protection (see complete list of rights);
  • their right to lodge a complaint with a Data Protection Authority (DPA);
  • their right to withdraw consent at any time;
  • where applicable, the existence of automated decision-making and the logic involved, including the consequences thereof.

The information may be provided in writing, orally at the request of the individual (once you have verified their identity by other means) or electronically. Your company must do that in a concise, transparent, intelligible and easily accessible way, in clear and plain language and free of charge.

When data is obtained from another company, your company should provide the information listed above to the person concerned:

  1. within no more than 1 month after your company obtained the personal data; or,
  2. when the data is used to communicate with the individual; or,
  3. when the personal data was first disclosed.

You are required to inform the individual of the categories of data and the source from which it was obtained including if it was obtained from publicly accessible sources.

Bottom Line. 

If you have clients that are residents of the European Union, you may be subject to the GDPR. The consequences of not complying are steep. Depending on the violation, you could face a fine of up to 20 million Euros or 4% of your total revenue for the preceding year. Don’t wait to get put out of business, give us a call today to schedule a consultation.

要查看或添加评论,请登录

Leila Shaver的更多文章

  • Do You Understand Custody Rules?

    Do You Understand Custody Rules?

    Custody rules can be confusing, but compliance is not optional. Many advisors unknowingly find themselves in violation…

    1 条评论
  • It’s Your Duty

    It’s Your Duty

    In 2025, the Securities and Exchange Commission (SEC) continues to emphasize the enforcement of Regulation Best…

  • A Wrap On February Finance

    A Wrap On February Finance

    Welcome to March! Before we get too ahead of ourselves I wanted to share a few things that happened this February to…

  • Is Your Marketing Compliant?

    Is Your Marketing Compliant?

    If you’re an investment advisor looking to grow your business without pouring money into traditional marketing, you’re…

    5 条评论
  • Is Your Firm Registered Correctly?

    Is Your Firm Registered Correctly?

    Registering your firm or yourself is the first compliance step that you need to get right when you start your finance…

  • Cybersecurity Moves Fast!

    Cybersecurity Moves Fast!

    Cybersecurity is a critical compliance issue. The SEC has consistently made cybersecurity one of its top five…

    2 条评论
  • January in Finance

    January in Finance

    Welcome to Friday! Before you go racing off into the weekend I wanted to share a few things that happened this week to…

  • History Repeating Itself - More Record-Keeping Failures

    History Repeating Itself - More Record-Keeping Failures

    Another wave of recordkeeping failures has hit the financial world, and let’s be honest, it’s not surprising anymore…

  • What Firms Are Getting Wrong When It Comes To Their Code Of Ethics

    What Firms Are Getting Wrong When It Comes To Their Code Of Ethics

    A Code of Ethics is more than just a piece of paper or a checkbox to satisfy regulatory requirements. It’s the backbone…

  • What to Prioritize in Compliance for 2025.

    What to Prioritize in Compliance for 2025.

    As 2025 kicks off, the SEC’s Division of Examinations has made it clear: staying ahead of compliance requirements is…

社区洞察

其他会员也浏览了