The new General Data Protection Regulation 2016/679 (GDPR), entered into force on 24 May 2016, shall apply from 25 May 2018. It will replace the Directive 95/46 currently in force. The changes adopted by the GDPR are ambitious and make Europe fit for the digital age (big data, Internet of Things, social media).
The GDPR ensures that personal data can only be gathered under strict conditions and for legitimate purposes. In this respect, it generally strengthens individual’s rights and creates a number of new rights (data portability, right to be forgotten). In addition, the GDPR creates new obligations for data processors and subcontractors. This modernization will therefore have an important impact for most companies and organizations, which must already prepare and inter alia adapt their T&C or privacy policies so as to ensure compliance with the GDPR by May 25, 2018. In case of violation of the regulation, the newly established supervisory authorities may impose dissuasive fines.
In this respect, the Privacy Commission has published a 13-step plan for companies and organizations in order to prepare them for the application of this new regulation.