Home / Information / GDPR: ‘Deadline’ for implementation is approaching, are you ready?

GDPR: ‘Deadline’ for implementation is approaching, are you ready?

Consultant for the General Data Protection Regulation (GDPR) Ana Keglović Horvat presented this Regulation on Monday, which was adopted by the European Union in 2016, and will begin to be applied in all EU countries from May 25, along with its compliance with the Croatian Personal Data Protection Act, which is expected to be adopted soon.

– Regardless of whether Croatia will adopt a law within the deadline that will regulate the issue of personal data protection at the national level, this Regulation will come into effect on May 25, as it is a general regulation, meaning it is uniformly applied in all 28 member states of the European Union, emphasized Keglović Horvat at a press conference.

>>>Lider’s guide to GDPR can be found at Tisak and iNovine

It would be beneficial for Croatia to appoint a personal data protection commissioner

The General Data Protection Regulation (GDPR) brings changes to the way of doing business and in the legislative sector, especially regarding the rights of citizens who have personal data stored or processed by certain organizations, she explained.

– According to the Regulation, from May 25, numerous organizations will have to align and change their operations, and citizens will be given the opportunity to exercise some of their seven rights related to personal data protection. This protection is now elevated to the level of human rights, thus enabling fundamentally different behavior towards data, emphasized Keglović Horvat.

>>>Project Privacy: Fundamental GDPR guidelines for startups

She stated that the Regulation applies to every organization that collects and processes data of respondents, EU citizens, so practically every organization, such as a public authority, company, association, school, hospital – must comply with this Regulation.

From May 25, every organization with more than 250 employees and that collects large amounts of data or particularly protected categories of data, as well as every public authority, will have to appoint a data protection officer. She also advocated for Croatia to appoint a commissioner for personal data protection.

>>>GDPR: From next year, rigorous European obligations in personal data protection

– The protection of personal data has been elevated to the level of human rights, and therefore I think it would be very useful for Croatia to show concern for human rights in the category of personal data by appointing a commissioner for personal data protection, just as we currently have a commissioner for information, she said.

Fines for violations of personal data protection up to 20 million euros

She emphasized that with the application of the Regulation, there will be the possibility for any supervisory body from EU member states to conduct oversight with the consent of the national local agency and in any other EU member state. Thus, it is likely that supervisory bodies from the EU will come to Croatia, but the Croatian Agency for Personal Data Protection (AZOP) will likely also be under oversight in another EU country.

>>>Alfatec: Big Data is a ‘must have’ for business improvement, GDPR impacts sales and marketing

She stated that for violations of personal data protection, the Regulation defines maximum fines of up to 20 million euros or four percent of the organization’s global annual turnover, depending on which number is higher. However, lesser fines are also foreseen depending on the nature of the violation, the amount of data, and the scope of the violation itself. She added that the criteria for determining these fines are currently unknown, and it is mentioned that they will be higher than they have been so far.

She also mentioned that it has appeared in the media that the Minister of Administration Lovro Kuščević said that public authorities could not be punished, or be a party in that procedure because it is a misdemeanor procedure.

>>>Petrušić: GDPR clearly states that it is the duty of companies to protect customer data

– However, the Regulation and the proposed law speak of administrative procedures and administrative monetary fines. In our law, there are many situations where the state does not act in proceedings from a position of authority but as an equal party, which is absolutely known in administrative procedures. Therefore, I see no reason why this criterion should be taken as a reason to exempt public authorities from the possibility of administrative monetary fines, said Keglović Horvat.

An example with papers from a kindergarten indicates low awareness of the importance of personal data protection

She pointed out that, for example, it has recently been reported in the media that in one kindergarten, children were drawing on papers that came from the Croatian Health Insurance Institute (HZZO) because there were confidential data on the back of the papers regarding a request for gender change of a person.

>>>Berislav Lastrić: The process of adapting to GDPR regulations must be aligned with the highest level

– That paper was unnecessarily printed in multiple copies, and at some point, someone decided to throw it away in a way that it was used and given to children to draw on the back. This is a very significant violation of personal data, and it also shows how low the awareness of some people in public authorities is regarding the importance of protecting others’ personal data, said Keglović Horvat.

With the application of the Regulation, the person whose personal data protection has been violated could contact the Agency for Personal Data Protection. According to the proposed law, no monetary administrative fine could be imposed on HZZO, as it is a public authority, which Keglović Horvat considers bad.

She also noted that with the application of the Regulation, tourists coming to Croatia from other EU countries could question the collection of data about them in hotels where, for example, their passports or ID cards are copied or scanned, said Keglović Horvat.