What is GDPR and Why Do You Need To Know?

What is GDPR and Why Do You Need To Know?

In this the first of a couple of articles I would like to introduce you to GDPR and outline what it will cover. While BREXIT is looming, it will in fact have little effect on GDPR, the UK Government has in fact championed the changes and are expected to adopt them even if they completely separate from the EU.

So let's talk about the act, before I do, I want to point out that this covers your busines, it covers every business from a one man show to a multi national.

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU).

The regulation was adopted on 27th April 2016. It becomes enforceable from 25 May 2018 after a two-year transition period and, unlike a directive, it does not require national governments to pass any enabling legislation, and is thus directly binding and applicable

The GDPR does not just cover data within the union, it also addresses the export of personal data outside the EU. In essence, the regulation is designed to give control back to citizens and residents over their personal data. It also will simplify the regulatory environment.

Data Includes Paper Records

While many will consider this a digital regulation, it is important that we also remember that data can be held on paper records. So we need to consider Patient record cards and their handling in our considerations as well as true digital data.

The Scope

The regulation applies if the data controller (that's you) or processor (Sycle, IPRO, Audidata etc, basically any customer data management system) or the data subject (person) is based in the EU. However, the Regulation also applies to organizations based outside the European Union if they collect or process personal data of EU residents.

I will cover in a later article who exactly is compliant and who isn't right now. Surprisingly some of the Patient management systems are not GDPR compliant. Although I have no doubt that they are working towards it. Some are competely compliant.

What is personal data?

According to the European Commission "personal data is any information relating to an individual, whether it relates to his or her private, professional or public life. It can be anything from a name, a home address, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer’s IP address."

The Penalties

Under GDPR organizations in breach of the regulation can be fined up to 4% of annual global turnover or €20 Million (whichever is greater). This is the maximum fine that can be imposed for the most serious infringements e.g.not having sufficient customer consent to process data or violating the core of Privacy by Design concepts.

There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order (article 28), not notifying the supervising authority and data subject about a breach or not conducting impact assessment. It is important to note that these rules apply to both controllers and processors -- meaning 'clouds' will not be exempt from GDPR enforcement.

What Now?

Simply put, you seriously need to consider your handling of data. You need to consider the security of any personal data collected. As I said, that includes paper records.



要查看或添加评论,请登录

Geoffrey Cooling的更多文章

  • Nexia, Should Have Called it Aquarius, Because it is The Dawn of a New Age

    Nexia, Should Have Called it Aquarius, Because it is The Dawn of a New Age

    Bluetooth is an amazing and wonderful thing, oh, and schizophrenic. It brings fantastic pleasure to hearing aid users…

    8 条评论
  • Cognitive Dissonance & The One Where You Aren't Sure Who You Are

    Cognitive Dissonance & The One Where You Aren't Sure Who You Are

    A recent conversation with an industry colleague brought an interesting example of the cognitive dissonance that has…

    3 条评论
  • Want to Sell Hearing Aids or Provide Hearing Care?

    Want to Sell Hearing Aids or Provide Hearing Care?

    What future for Audiology? OTC has very much arrived, with a plethora of offerings available from both traditional…

    14 条评论
  • A Big Boy Made Me Do It And Ran Away

    A Big Boy Made Me Do It And Ran Away

    Paraphrasing a famous Scottish saying, Starkey announced that they too are entering into the OTC market. Apparently…

    4 条评论
  • DTC, an Opportunity or an Existential Threat

    DTC, an Opportunity or an Existential Threat

    DTC Could Be A Boon, Not A Threat My open letter to GN appears to have raised a few hackles, was it the nasty, mean…

    6 条评论
  • An Open Letter To GN

    An Open Letter To GN

    Why You Are Wrong With The Jabra Enhance Plus I wrote a review of the Enhance Plus earbuds fom Jabra on Know recently…

    16 条评论
  • A Changed Landscape For Retail Audiology

    A Changed Landscape For Retail Audiology

    All of the predictions are coming to pass and retail audiology faces a changed landscape moving forward. The…

    9 条评论
  • Hearing Loss, Stigma & My Hearing Day

    Hearing Loss, Stigma & My Hearing Day

    In response to a dear colleague, I want to talk about hearing loss, stigma, why you are all gobshites, beautiful music…

    13 条评论
  • Can Domiciliary Audiology be The New Concierge Care?

    Can Domiciliary Audiology be The New Concierge Care?

    With the changing nature of the hearing care landscape, I was thinking about domiciliary hearing care as a business…

    2 条评论
  • Tuned, An Entirely Different Online Model

    Tuned, An Entirely Different Online Model

    I came across an exciting company, and website recently called Tuned Care. The site is the first-ever online hearing…

社区洞察

其他会员也浏览了