The General Data Protection Regulation of April 27, 2016, known as GDPR[1], entered into force on May 25, 2016, replacing the Personal Data Protection Directive adopted in 1995.
The provisions of the GDPR will be applicable in all 28 Member States of the European Union as of May 25, 2018.
The GDPR strengthens the rights of individuals at the individual level and imposes new obligations on data controllers.
Concerned by the GDPR are all large companies with more than 250 employees, VSEs and SMEs, which must comply by modifying existing procedures or by implementing secure personal data processing procedures; if they do not want to be severely sanctioned by regulatory authorities (for example: the CNIL).
What are the compliance steps? What are the essential points of the GDPR?
- Designate a Data Protection Officer (DPO)
The DPO has legal and technical skills. They are often presented as the conductor of compliance within a company. They guarantee compliance with regulations within a structure: they inform and advise the data controller and employees; they ensure compliance with the regulation regarding data protection and internal rules; they provide advice regarding data protection and cooperate with supervisory authorities (in this case the CNIL, in France) on issues relating to data processing.
The DPO represents a significant help for the company. They advise and assist the company in its procedures.
- Map and maintain processing records
It is necessary to identify all personal data processing, whether computerized or in the form of paper archives. It must be ensured that current processing complies with legal requirements regarding security, data retention and respect for individual rights.
This inventory work may be requested later by the CNIL.
The employer must map all processing related to human resources and marketing that use numerous nominative data.
Note that it is recommended to map, as of now, contracts signed with business partners and subcontractors since certain provisions of the GDPR will be mandatory in subcontracting contracts.
- Define the actions to be carried out
This involves defining the means available to the company to secure data (anonymization, encryption).
It is also necessary to determine the modalities for exercising individual rights regarding the collection of consent and the right to be forgotten.
The employer may only collect adequate, relevant data strictly necessary for the purpose of processing.
Similarly, within the company, a data retention period policy must be established providing for the possibility of deleting data as soon as it no longer serves any purpose in view of the objective pursued.
The entire privacy policy will have to be thoroughly revised in order to protect individual rights.
- Manage risks
Companies are asked to know how to manage risks and clearly identify data processing that could lead to significant risks for the rights and freedoms of individuals.
The GDPR sets up privacy and data protection impact assessments and establishes the principle of “accountability”.
- Manage the internal process
The company and the DPO must establish a compliance plan.
To do this, internal procedures must be revised and the flow of information within the company organized.
New internal procedures must prioritize data protection during all phases of processing (collection, management of requests for rectification or access, changes of service providers, modifications of collected data, security breaches, deletion).
- Raise employee awareness
Awareness consists of training employees on the new provisions provided by the GDPR and having complete documentation.
A register must therefore be kept by the DPO. The following will be listed: different data collections, categories of data processed, processing tools, data security verification procedures, security breaches, access authorizations.
A report must list all actions taken in favor of personal data protection.
At the same time, the employer must inform their employees or candidates for employment of the implementation of personal data processing, its purposes and implementation methods.
Information must be delivered clearly and appear on various supports (company website, internal documents, employment contracts, internal regulations).
Finally, before any collection of personal data, the employer must ensure they have previously obtained the consent of the employee or candidate (opt-in). To this end, they must provide collection systems such as written authorization or a form with check boxes.
What are the different sanctions provided for by the GDPR?
Administrative sanctions may consist of: “10,000,000 euros in fines or, in the case of a company, up to 2% of the total worldwide annual turnover of the previous financial year, the highest amount being retained” (article 83).
The GDPR provides for a combination of administrative and criminal sanctions.
The convicted company may be prohibited from continuing all or part of the processing of personal data, from using the data collected or from transferring them.
Finally, the victim may obtain compensation for their prejudice on a civil and/or administrative level by taking legal action.
Get compliant now!
[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016


