DATA DAY

When was the GDPR deadline, what is on the compliance checklist and does it apply in the UK after Brexit?

THE General Data Protection Regulation – which has now come into force – is the biggest shakeup of personal data privacy rules since the birth of the internet.

It is aimed at curbing US tech giants like Facebook - but sole traders such as plumbing and window cleaners could face crippling fines if they fall foul of the law. Here's what you need to know.

Advertisement
Tech giants such as Mark Zuckerberg's Facebook are the main targets of the GDPRCredit: AP:Associated Press

What is GDPR and when does it take effect?

The General Data Protection Regulation is a piece of EU legislation passed by the European Parliament in 2016.

It became enforceable in all EU countries on Friday, May 25.

Punishing fines for data misuse and breaches can reach £18million or 4 per cent of global annual turnover, whichever is higher.

The GDPR aims to make it simpler for people to control how companies use their personal details.

Advertisement

Strict rules mean companies will not be allowed to collect and use personal information without the person's consent.

Data includes things like a person's name, email address and phone number, and also internet browsing habits collected by website cookies.

Firms must also report any data breaches - including cyber attacks and accidental leaks - to authorities within 72 hours.
Individuals can demand a copy of all data held about them, which must be supplied within 30 days.

And in some cases they can ask for any data to be deleted in a formal "right to be forgotten" law.

Advertisement

Privacy campaigners have hailed the regulation as a new step forward for online rights, but small firms are furious about the burden of complying with the law.

Breaches of cyber-security could result in multimillion-pound finesCredit: Alamy

Will GDPR still apply after Brexit?

The government says the same rules will continue to apply after the UK formally leaves the EU.

GDPR standards will soon be enshrined in UK statute in the Data Protection Bill currently going through Parliament.

Advertisement
Topics
Advertisement
machibet777.com