Blog » THE COUNTDOWN TO EU DATA PROTECTION REGULATION HAS BEGUN
THE COUNTDOWN TO EU DATA PROTECTION REGULATION HAS BEGUN
27 March 2017
I can imagine that when you hear the words data protection, you may not really be excited. What is worse you may skip to read this article. You probably think that when running your business, you have much bigger problems than data protection compliance. Still, I encourage you to give it 5 minutes and read through this short summary about the 5 most important impacts of the Data Protection Regulation (GDPR) on your business. The GDPR will only enter into force in May 2018 so this is the perfect time to familiarize yourself with the new rules.
Don’t let the term “EU Regulation” fool you, the GDPR catches global organisations outside the European Union, too, if they offer goods or services to EU citizens or residents. This means that if you have a company in China and you are targeting consumers in Hungary, your company will be subject to the GDPR.
To raise the stakes, not only the territorial reach has been expanded, but also the personal scope of the GDPR. Currently, the data protection is the sole responsibility of the data controller (the one who owns the data). The GDPR changes this and provides that the processor who carries out the data processing on behalf of the controller, will also be held responsible for data protection.
At the end of the day, however, the main responsibility remains by the controller as he is expected to choose a processor who provides sufficient guarantees that the processing will be in line with the GDPR.
The scariest innovation of the GDPR which will be probably attracting the attention of executives and shareholders are the fines which can be imposed for data protection infringements.
The current data protection law in Hungary allows the Data Protection Authority to impose a fine of maximum 20 Million Hungarian Forints. Additionally, the authority cannot impose fines against small and medium enterprises for the first data protection infringement.
Luckily, the GDPR does not change everything: the maximum amount of 20 Million remains. The only difference is that the currency will be Euro, not Forint. Or, in case it is higher, the maximum amount of the fine is 4 % of your annual worldwide turnover. So be careful of being a profitable business with crappy data protection. At this point of time, it is not certain whether the SMEs’ exemption from fine in case of the first infringement will remain in force or not.
When imposing fines, the authority shall consider among others the nature, gravity and duration of the infringement. In addition, the GDPR leaves to the Member States to lay down further sanctions.
K.I.S.S. – Keep it simple, stupid
You as a controller must inform and remind the consumers of their data protection related rights.
Good news for companies who like to keep it simple and bad news for lawyers who are obsessed with legal jargon: the GDPR explicitly requires that the information provided should be in clear and plain language. The information must also be transparent and easily accessible.
Furthermore, data controllers are expected to help the consumers to exercise their data protection related rights. This includes that the request of the consumer to exercise his data protection related rights can only be refused if the controller proves that he cannot identify the consumer.
Data protection officer
The role of data protection officers is not entirely unfamiliar for Hungarian companies. Currently, employing a data protection officer is obligatory only in certain sectors, for example in case of financial institutions or electronic communication service providers. Small and medium enterprises are exempt from employing a data protection officer regardless of their activity.
The GDPR again brings changes concerning data protection officers. Both data controllers and data processors shall designate a data protection officer if their activity requires regular and systematic monitoring of data subjects or if they process special categories of data (eg. data concerning health). SMEs remain exempt from this obligation except they are processing sensitive data.
The data protection officer will need sufficient expert knowledge and he shall either be employed at the company or work under a service contract.
Recording & impact assessment
As a new obligation, data controllers need to maintain a record of data processing activities. The record shall include the categories of recipients to whom personal data will be disclosed. For example, in case you send the personal data of your employees to your lawyer for contract drafting or to your accountant who does the payroll, this needs to be included in your record.
Again, SMEs are not obliged to keep records, except the processing is not occasional or sensitive data is concerned.
Another important innovation is the so called data protection impact assessment. In case the data processing is likely to result in a high risk to the rights of natural persons, the data controller shall prior to the processing carry out an assessment of the impact of processing operations on the protection of personal data.
As you can see a lot of big changes are coming, thus it is worth to start re-examining your procedures and processes to ensure compliance with the GDPR. In our following article we will give you useful tips how you can be prepared when the GDPR will enter into force next year.
5 THING YOU SHOULD NOT MISS OUT FROM YOUR ONLINE SHOP TERM&CONDITIONS IN HUNGARY
Online shopping is more and more trendy. While it is a very good opportunity, it has more risks for consumers than traditional retail shopping. For example, you cannot see the product in reality, so what if the shirt you ordered for your father as a Christmas present does not fit? The European Union recognized the risks of online shopping and adopted several consumer protection rules. In this short article I collected 5 issues you must include in your terms&conditions if you operate an E-shop in Hungary. Please note that these rules only apply if your buyer is a consumer (a natural person who is not acting for business purposes).Read more »
HOW TO OPEN AN ONLINE SHOP IN HUNGARY?
Online shopping is more and more popular among customers for certain reasons: it is more convenient and often cheaper than traditional shopping. Online shopping is not only an attractive alternative for the shoppers but for the traders, too. By opening an online shop, you can remove the need for expensive retail premises and customer-facing staff. Another huge advantage is that you can expand your market beyond local customers very quickly. Here are 4 things that you need to clarify if you decided to open an online shop in Hungary.Read more »
INTERNATIONAL LAW FIRMS CONFERENCE IN CYPRUS
We are members of International Law Firms (ILF) a worldwide network of small & medium sized law forms around the world, with around 70 members from 50 jurisdictions. The goal of ILF is improving client service in cross border business legal issues. Every year there are annual and regional conferences where we can share our experiences, meet new people, new viewpoints, and make our community better.Read more »