What is the GDPR regulation? Facts and fables in a row
The GDPR Regulation or AVG will come into force in the Netherlands on May 25, 2018. This regulation ensures that the same privacy rules apply throughout Europe. This law has many consequences for everyone who does business (online). Especially since the Netherlands is one of the last countries to implement these regulations, it is urgent. In this article we explain what the GDPR or AVG is, what you need to do to be prepared, what the consequences are if you do not comply with the regulation and what myths are circulating. After you have read this article, you can quickly get to work to comply with the GDPR. So read on quickly!
GDPR and AVG, what are these regulations?
There has been discussion about privacy on the Internet for a long(er) time. Until now, each country was allowed to decide for itself how to regulate the privacy of its citizens, but as of May 25, 2018, this is over, because then the GDPR comes into force across Europe. GDPR stands for General Data Protection Regulation. This regulation has been renamed for the Netherlands as General Data Protection Regulation (AVG). The Data Protection Act, which currently regulates the privacy of Dutch citizens, will expire on May 25. The AVG leaves room for countries to fill in things themselves, this is regulated in the Netherlands in the Implementation Act AVG.
How do I know whether the GDPR or AVG applies to me?
Your personal data must be protected everywhere within the European Union. So the protection applies to everyone. Whether you as a business owner need to provide protection depends on a few factors. The following four questions will help you determine this:
Do you process data?
Are these data personal data?
Do you process the personal data in whole or in part in an automated way, are these data included in a file or are they intended for this purpose?
Does your data processing fall within the regulation?
If you can answer 'yes' to these four questions, you are subject to the GDPR. If you have determined that this is so, you need to ask yourself whether you are a processor or a data controller. In a simple example, if you ask for customer name and address information on the site you are a processor, if you have Google Analytics installed then you are a data controller, as Google may process personal data from your site.
If you process data yourself you need to take a number of steps (see below). If you let someone else process data you have to enter into a so-called processing agreement.
What does the GDPR mean for me as an internet entrepreneur?
The idea behind the GDPR regulation is that consumers are and remain in charge of their own personal data. To ensure this, a number of rights have been defined for those whose data is used. In addition, there are a number of conditions for the processor.
The rights of the person in the GDPR regulation
The rights of the person whose data is collected are defined in 10 rules:
1.The right to information about the processing;
2.The right to access his or her data;
3.The right to correct inaccurate data;
4.The right to erasure of data;
5.the right to be forgotten;
6.the right to restriction of data processing;
7.the right to object to the data processing;
8.the right to transfer his or her data;
9.the right to withdraw consent to data use;
10.the right not to be subject to automated decision-making.
If someone invokes such a right, you must comply with it (with a few exceptions) within one month. You have the choice between refusing the request and giving reasons or supplying the data. If you communicate this within a month, you may take an additional 2 months to get the data. You may not charge for the request. In short, if you are not prepared, such a request can be an expensive 'joke'.
In addition, you may not just ask for personal data. This is subject to obligations.
The obligations of the processor under the GDPR
If you collect personal data you also have a number of obligations, for example you must:
1.Indicate which company is collecting the data under the GDPR regulation, who the contact person is and provide the details for reaching that contact person;
2.Explain the purpose for which you are collecting the personal data;
Explain why (on what basis) you are collecting the data and explain that basis;
3.Indicate whether you receive the data;
4.Explain whether the data will be provided to 'third countries' (countries outside the EU);
5.Explain what guarantees have been obtained for the provision of data and whether these guarantees can be inspected;
6.To indicate how long the data provided will be retained;
7.Clearly state what rights the party providing the data has;
8.Explaining that the provider has the right to submit a complaint about the processing to the Personal Data Authority;
9.Make clear how any automatic decision-making based on that data is regulated.
Myths about the GDPR regulation or AVG
1.The GDPR regulation will be introduced from 25 May 2018.
This is not true, the GDPR has already entered into force on April 27, 2016. Until May 25, a transitional arrangement applies and the Dutch law is still valid. After that, it will not;
2.It thus becomes impossible to work with parties from outside the EU!
The GDPR regulation only applies in Europe. Foreign collectors of data, such as Google or Facebook therefore have little to do with these regulations. Therefore, they will not want to make GDPR agreements with every website owner. The rumor is that you can get into trouble if you do work with Google Analytics, for example. This is not true. The European Union understands that you are not a party that can impose your will on Google. That is why they negotiate on behalf of all website owners. This also applies to other players from outside the EU. As long as you can show that your policy is in order, you have done everything to comply with the GDPR and did not know or should have known that data would be misused, it is allowed to work with those processors;
3.Cold acquisition or direct mailing is prohibited under the GDPR.
This is not true, you may just call general numbers and general email addresses. If you use a personal email address or direct phone number you must be able to show that you obtained that data properly and that the provider has given permission for use for acquisition purposes. That sounds like a tough requirement, but research shows that a free pizza is enough to get all the permission you want!