So you thought there was only one GDPR?
28 member states, 4 years, 3.999 amendments

So you thought there was only one GDPR?

Before the first proposal for a new European privacy law was brought to the EC in the beginning of 2012, the intention was to harmonize privacy laws across the EU. This would be realized by replacing the existing Privacy Directive 95/46/EG with a regulation: a regulation is directly effective, bypassing the need for implementation in national laws. 

This is Europe, however...

This is Europe, however, so the reality was 28 member states negotiating for more than 4 years and a record number of 3.999 amendments. The result is that the GDPR gives member states much room for local interpretation, to be laid down in 'implementing legislation'. These should have come in effect at the same date as the GDPR itself, May 25 2018, but not all countries where ready in time: the national implementations of Bulgaria, Czechia, Greece, Portugal, and Slovenia are still in development.

Even at the core of the GDPR, two of the lawful grounds for processing – out of a total of six – can be filled in on a national level: compliance with a legal obligation and the performance of a public task.

Other examples of room for national interpretation of the GDPR include:

  • Extra protection for special categories of personal data, that enlarge the risk of discrimination, exclusion or fraud.
  • Minimum age of consent for the processing of personal data: it's 13 in Denmark, Sweden, and Belgium, 14 in Cyprus, 15 in France and 16 in the Netherlands.
  • Limitation of subject rights under certain circumstances, like national security.
  • Deviation for journalistic purposes.

Enforcement of the GDPR will most likely also show different nuances for member states. Each member state is obligated to appoint its own supervisory authority with the possibility to apply sanctions. But what sanctions will be applied in which situation, is largely up to the member states themselves.

The conclusion is, that although there is only one regulation for all EU member states, it's advisable to do local compliance checks when you're entering new markets.


Based on a Dutch article.

要查看或添加评论,请登录

Richard Kranendonk的更多文章

  • Finding Hidden Risks

    Finding Hidden Risks

    Work processes are full of hidden risks, that only come to the attention of the CISO or DPO in case of incidents or…

  • Compliance requires knowledge of IT

    Compliance requires knowledge of IT

    You’ve probably never heard of them, but chances are Spanish service provider Prestige Software has exposed your…

    2 条评论
  • AP: We Gaan De Cowboys Aanpakken!

    AP: We Gaan De Cowboys Aanpakken!

    In een toespraak voor het Nederlands Genootschap voor Functionarissen Gegevensbescherming heeft Munish Ramlal, Hoofd…

  • Targeted advertising companies receive GDPR notices

    Targeted advertising companies receive GDPR notices

    French privacy authority CNIL (Commission nationale de l'informatique et des libertés) has taken aim at four companies…

  • Handhaving AVG: welke organisaties zijn als eerste aan de beurt?

    Handhaving AVG: welke organisaties zijn als eerste aan de beurt?

    De Autoriteit Persoonsgegevens (AP) geeft op haar site verschillende criteria en lijsten van verwerkingen waarvoor het…

    4 条评论
  • AVG: recht op inzage kan leiden tot datalek

    AVG: recht op inzage kan leiden tot datalek

    Als je een verzoek om inzage onterecht honoreert, veroorzaak je een datalek. Maar vraag je teveel van de indiener om…

    7 条评论
  • De AVG is bewust vaag – hoe ga je daar mee om?

    De AVG is bewust vaag – hoe ga je daar mee om?

    In het kader van de AVG hebben organisaties behoefte aan concrete richtlijnen: wat moeten we precies doen, wat mag wel,…

    1 条评论
  • Handhaving AVG: interessante uitspraken van directeur AP

    Handhaving AVG: interessante uitspraken van directeur AP

    Directeur Cecile Schut van de Autoriteit Persoonsgegevens heeft op de ledenvergadering van het Nederlands Genootschap…

    45 条评论
  • GDPR protection for the uninformed

    GDPR protection for the uninformed

    This morning I stumbled upon this beauty in a Reddit post: GDPR shield. User Greatbytes, whom I suspect to be the…

  • A very interesting LinkedIn scam

    A very interesting LinkedIn scam

    A couple of days ago, we got mail: "Nice website. I’m the systems manager at a company that just acquired 2 sites in…

    3 条评论

社区洞察

其他会员也浏览了