none

EUROPEAN DATA LAW TO HIT CLOSE TO HOME

10-05-2018
by 
in 

As if the latest Australian data security legislation wasn’t enough to get your head around, it now seems that we all need to look to Europe and take note of the EU’s new General Data Protection Regulation, or GDPR, which comes into force on 25th May.

If there’s one thing that the European Union does well, it’s framing laws, and the GDPR is probably the most comprehensive piece of data security legislation the world has ever seen. And as it is a “regulation” rather than a “directive” it will immediately become law in all member states on 25th May, rather than needing enactment in each member state.

The GDPR replaces Directive 95/46/EC, which was enacted more or less intact by all member states in 1995.

And while the main principles on privacy are still the same, the new regulations are framed for the modern world – bearing in mind that in 1995 social media and cloud storage did not exist and only about 1% of the European population was using the Internet.

In case you’re wondering what this has to do with Australia, the GDPR will not only apply to organisations located within the EU but also to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU residents (or “data subjects” as defined in the regulation).

So it applies to all companies processing and holding the personal data of European Union residents, regardless of the company’s location – and regardless of the location of the data (so the cloud is not a get-out clause!).

Among a raft of additions to the previous directive, the regulation also greatly strengthens the rights of the “data subject” in terms of access to any data held and in the right to be “forgotten” – effectively to have all data removed from any given database.

Perhaps the biggest change is in the penalties that can be enforced, with the potential for organisations to be fined up to 4% of their global turnover (or Eur20 million) for the most serious breaches.

While it will be interesting to see whether the EU will be able to enforce such penalties on companies that operate outside its jurisdiction, organisations worldwide should pay heed to the requirements of the GDPR.

The scope and framing of the legislation really do provide a framework that should be viewed as “world’s best practice” for data security.

Related news & editorials

  1. 27.04.2020
    27.04.2020
    by      In
    COVID-19 has exposed what everybody already knew, but for years was too polite to mention: that much of the first world is over-reliant on supply chains out of China.
    But who could have predicted such a death toll, such a sudden restriction in global trade, such demand for products such as medical... Read More
  2. 25.02.2020
    25.02.2020
    by      In
    It’s one of the most chilling lines from the movies of the 20th century. My namesake and hometown hero Sir Laurence Olivier repeatedly asked Dustin Hoffman “Is it safe?” while torturing him in a dentist’s chair in the movie classic Marathon Man.
    Hoffman’s character’s problem was that he didn’t know... Read More
  3. 12.11.2019
    12.11.2019
    by      In
    Looking at the recently released Safe Work Australia work-related traumatic injuries and fatalities statistics I have become rather alarmed at the prevalence of injuries and fatalities among older workers.
    While the figures, which have just been released for 2018, do show a continual decline in... Read More
  4. 08.10.2019
    08.10.2019
    by      In
    These are strange days in which we live. So many of the great trading nations of the world have begun to “shut up shop” that the accepted global economic paradigms are beginning to have a very hollow ring.
    The post-WWII acceptance that free trade does more to bring nations together and to generate... Read More