Drastic tightening due to the General Data Protection Regulation

December 2017

Categories: Client Information
HOMENewsDrastic tightening due to the General Data Protection Regulation
Drastic tightening due to the General Data Protection Regulation

25th May 2018 will mark the General Data Protection Regulation coming into force, which in Austria through the Data Protection Adjustment Act 2018 was implemented. Until then, the regulations of Data Protection Act 2000. The necessity for changes is also due to the constantly growing internal market and thus EU-wide exchange personal data attributable. Finally, rapid technological development (cloud computing, big data, etc.) and the challenges posed by Globalization better account will be taken. Companies are well advised to implement the measures for better data protection accordingly - also because very high penalties threaten. Companies (within the EU or from third countries, provided they offer services to EU citizens) are already affected by the new regulations if they, in any way, Personal data Process, including, for example, maintaining customer files, issuing invoices, or storing supplier data. After all, in the future no obligation to report more at the Data Protection Authority (Data processing register).

The right to data protection is a Fundamental right, which has constitutional status in Austria. It must be observed not only by the state but also between private individuals – the principle of "Prohibition subject to a reservation of permission"This is based on the strict principle that the processing of personal data is fundamentally prohibited, and may only be carried out if the law (exceptionally) permits it. The following are essential aspects or. New features shown.

Data protection through technical design and data protection-friendly default settings

By appropriate Technical and organisational measures and procedures must the Rights the affected individuals protected become. Data protection by default shall ensure that only such personal data are processed as are necessary for the respective specified Processing purpose required Thus. In practice, this means that personal data (of applicants, former employees, customers, etc.) must be protected more strictly and also Deleted to become must, when the Processing purpose fulfilled is happening. At the same time, it must more transparency in relation to supervisory authorities, customers and employees. Overall, when processing personal data, Principles Legality, Processing according to Good faith, Transparency (i.e. the data processing must be transparent and understandable for the data subject), Purpose limitation (pre-defined, clear and legitimate purpose), Data minimisation, Correctness (only factually correct data are to be processed - incorrect data must be deleted or corrected immediately), Memory limit as well Integrity and confidentiality Personal data must be protected against unauthorised/unlawful processing and also against accidental loss. fulfilled to be.

Register of Processing Activities

The register of processing activities, similar to current data protection officer notifications, alongside the Purpose of data processing further information to include, such as the Description the categories of data subjects affected by the processing People and the corresponding data (e.g. invoice and address details of customers and suppliers). The directory must also Recipient Categories containing personal data (e.g. social security, tax office, lawyer, tax advisor, etc.) including recipients in third countries or international organisations. The register will include the prescribed periods for the deletion of the different data categories as well as a description of technical and organisational Data security measures completed. Companies with fewer than 250 employees are exempt from the obligation to keep such registers only then freed, provided that the Data processing no risk to the rights and freedoms of the data subjects, processing occasionally takes place or the processing no sensitive data or contains data about criminal convictions.

Reporting of data breaches

Injuries protection of personal data must the national supervisory authorities as well as the communicated to the affected person as quickly as possible become. Exceptions to this apply if the infringement does not lead to a risk to personal rights and freedoms.

Data Protection Officer

For the company it must Compulsory one Data Protection Officer ordered, when the Core business of the company in processing operations which a extensive, regular, and systematic observation required from data subjects or, for example, particularly sensitive data concerning criminal convictions or offences is processed. When appointing the data protection officer, it should be borne in mind that the person uninstructed is, Protection against dismissal enjoys and unrestricted access rights into the processed data.

Obligations to inform and rights of data subjects

Diverse Information and data subject rights are promptly to provide or complete. This includes approximately Rights of access to information (also regarding the planned storage duration), the right to rectification, the right to erasure and to be "forgotten", the right to restrict processing, the obligation to inform all recipients of rectification, erasure or restriction, the right to data portability, and the right to object.

Hefty fines

Data protection improvements or new regulations are due to very high fines accompanied by violations. Thus, in the case of particularly serious violations, e.g. in the event of infringement of the data subject's rights or failure to comply with an instruction from the supervisory authority, Fines of up to €20 million or up to 4% of the previous year’s global turnover imposed. For less serious violations (e.g. breach of data security regulations) the maximum fine still €10 million or. 2% achieved worldwide Previous year's turnover.

Image: © .shock - Fotolia

Scroll to Top