Home / Information / GDPR: From next year, rigorous European obligations in personal data protection

GDPR: From next year, rigorous European obligations in personal data protection

Managing personal data can be crucial for business, and to prevent its misuse, the European Union is also concerned, having obligated its members with new data protection regulations (GDPR – General Data Protection Regulation) to introduce new protection standards from May 25, 2018, as otherwise they will be exposed to potential fines of 20 million euros or up to four percent of global turnover.

How to comply with the new European regulations was the focus of today’s conference organized by Lider and Alfatec titled ‘What is GDPR and how to be ready for the full application of the regulation’.

>>>Only nine months left until the application of the GDPR regulation, which will significantly change the concept of business

Alfatec’s lecturers Tomislav Musić and Marko Cukrov introduced the workshop participants to the content of the GDPR, which protects personal data more clearly and seriously than the national regulations of EU member states. The fundamental principles of the regulation are that data can only be collected for specific and lawful purposes, that they must be limited in relation to the purpose for which they are processed, that they must be accurate and regularly updated, and that they must not be stored longer than necessary. Furthermore, when collecting data, consent must be obtained from the individual in a clear affirmative action, and not merely by silence or consent without explicit expression, which has been the case until now.

For the business community, it is particularly interesting that they will have to assign and educate certain employees about the obligations of the regulations, as managing personal data also includes certain obligations for those who manage them, including reporting security breaches of the personal data collected. This is especially important, as holders of personal data who have suffered damage due to breaches of their security will have the right to compensation for the damage suffered.

>>>Alfatec: Big Data is a ‘must have’ for business improvement, GDPR impacts sales and marketing

To comply with GDPR, business entities will need to analyze the current state of personal data they manage, from data about their own employees to data about clients, and assess the risk that their security may be compromised. In order to comply, they will need to adopt, implement, and actively enforce a policy or strategy for data management. Given the looser domestic legislation, companies in Croatia have not yet caught up with GDPR, and the time when it comes into effect is getting closer.