GDPR for Dummies

GDPR for Dummies

This Article is a quick and dirty introduction to GDPR which can get you started.

General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals who reside in the European Union. It also addresses the export of personal data outside the EU. This regulation primarily aims to gives control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.

GDPR was approved by European Parliament on April 14, 2016 and a two-year transition period for organizations to reach compliance was provided. That ended on May 25, 2018. This regulation is now applicable to all existing systems storing data of EU residents. You can see that they took enough time to deliberate on the regulation and must have went through multiple rounds of reviews and discussions.

GDPR Supersedes EU previous laws/directive on data privacy and this was drafted by the Council of the European Union, European Parliament, and European Commission. GDPR is a law and applies to all companies doing business with European data subjects (EU residents), irrespective of where the company is located.

Data can be as simple as Name, Photo, Email, Phone number, Race and as complex as Medical records, tax records, bio-metric etc. Basically any data that can be used to determine your identity. This also includes Pseudonymous data. In case of minors below 16, consent from parent/legal guardian must be obtained to collect and store data.

GDPR consists of 11 chapters and 99 articles. Here is the link

Compliance to GDPR can be validated by getting audited via either internal SME or external agency.

GDPR is being actively looked at by other countries like US and might soon become a standard in other counties too.

Laws in India are also being worked up to increase privacy of user data. As of now, certain companies in India are referring to ISO27001

GDPR expects data protection and privacy by design and by default

Data should only be accessed via explicit consent and not publicly. Also data should not lead to a data subject directly without additional info which needs to be stored separately. Basically full anonymization.

Data subject has the right to revoke consent anytime and systems should provide a way to enable this. Consent provided should not be assumed as permanent and immutable.

Data protection officer role should be established in an organization. This role should have authority, independence and should be the internal gate keeper for data privacy.

Organizations coming under National Defense, Financial Fraud Prevention, Revenue/Tax and Law Enforcement are exempted from GDPR implementation

You can read more at following locations:

  • https://www.coredna.com/blogs/general-data-protection-regulation
  • https://www.hipaaguide.net/gdpr-for-dummies/

There is also a book with the same name https://www.metacompliance.com/media/2002/dummiesguide.pdf

要查看或添加评论,请登录

Sameera Ramachar的更多文章

  • Timing is the key!

    Timing is the key!

    I will give 2 examples to set the context first..

  • Coach-ability - State or Condition of being coach-able

    Coach-ability - State or Condition of being coach-able

    Coach-ability, as you might know means that a person is receptive to feedback, to receiving constructive criticism, and…

  • 9 "Quotes" on Software Testing

    9 "Quotes" on Software Testing

    Some interesting quotes on software testing which pretty much capture what it is all about !! "Testing is the process…

    2 条评论
  • API Security testing - Starter kit

    API Security testing - Starter kit

    API (Application Programming Interface) security testing is an essential part of ensuring the protection of sensitive…

    1 条评论
  • Employee Vs Management

    Employee Vs Management

    Some one sent this pic in a ex-employees whatsapp group and this initiated a chain of discussion. I am penning down my…

    1 条评论
  • My thoughts on near perfect CV

    My thoughts on near perfect CV

    CV or Résumé is a written overview of a person's experience and other qualifications typically used for securing a job…

  • Slack Overflow!

    Slack Overflow!

    Context: Most of the companies use messenger type of applications for faster communication either internally or…

  • Hacks for efficient management of Software Development teams

    Hacks for efficient management of Software Development teams

    Here are my thoughts on how to effectively lead and manage high performance software development teams. Please feel…

    1 条评论
  • You are only as good as...

    You are only as good as...

    You are only as good as your code is on production! I heard this weird sounding statement from a tech leader couple of…

    1 条评论
  • Stitching Quality

    Stitching Quality

    In software industry, one of the biggest challenges is to translate user requirements and develop software in the way…

社区洞察

其他会员也浏览了