Short Reads

Countdown 2 weeks until GDPR : Will periodic data protection audits be mandatory under the GDPR?

Stibbe - Will periodic data protection audits be mandatory under the G

Countdown 2 weeks until GDPR : Will periodic data protection audits be mandatory under the GDPR?

09.05.2018 EU law

Only 2 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Will periodic data protection audits be mandatory under the GDPR?

Under Article 32.1.d of the GDPR, data controllers and data processors must implement appropriate technical and organizational measures to ensure a level of security that is appropriate for the risk and, among those measures, they must regularly test and evaluate the effectiveness of the measures adopted for ensuring security of files.

Having said this, the GDPR does not lay down specific procedures or a specific format for those review and evaluation tasks. Consequently, unless binding national regulations set forth otherwise, data controllers and data processors are not required to conduct a specific type of mandatory audit – as defined in national regulations adopted under Directive 95/46. On the contrary, the general rule would be that the data controller or processor has the discretion to define the procedures for review and evaluation, provided that those procedures ensure complete verification and assessment of risks connected with the security of files.

approach will differ if the data controller or processor has voluntarily adhered to a given code of conduct (which could define detailed procedures for testing and reviewing purposes) or if they are bound by national regulations that, being aligned with the GDPR anyway, impose specifically defined (and mandatory) audit procedures.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

02.07.2019 NL law
Debate night: HR Analytics: opportunity or threat?

Seminar - On 2 July 2019, Stibbe's Digital Economy Group will host a debate night in Amsterdam on the hot topic of HR analytics. During Stibbe's debate night, speakers from the world of business, politics, science and law will exchange views on HR analytics, how they can be used in practice, and their development in the context of employment and privacy law.

Read more

21.06.2019 NL law
Nieuw boetebeleid van de Autoriteit Persoonsgegevens

Short Reads - Op 14 maart 2019 zijn de nieuwe Boetebeleidsregels Autoriteit Persoonsgegevens 2019 ("Boetebeleidsregels") van de Autoriteit Persoonsgegevens ("AP") gepubliceerd. Dit boetebeleid heeft de AP opgesteld vanwege de inwerkingtreding van de Algemene verordening gegevensverwerking ("AVG") en omdat er op Europees niveau nog geen boeterichtsnoeren zijn opgesteld.

Read more

07.06.2019 BE law
Part three - GDPR and public law: To retroact or not?

Articles - Since the General Data Protection Regulation (“GDPR”) became applicable almost one year ago, multiple questions have arisen about its interaction with other fields of law. In this three-part blog series of “GDPR and public law”, we discuss three capita selecta of the interaction of GDPR with public law and government. In this blog we discuss the retroactive application of GDPR.

Read more

06.06.2019 BE law
TMT Roundtable: Getting a handle on software quality

Roundtable - Erik Valgaeren, TMT Partner at Stibbe Brussels, and his team organize a roundtable on software quality in our Brussels office on June 6th, 2019. Software quality is a recurring theme in many matters handled by our TMT team. Whether our assistance relates to preparing tender documents, contracting effectively, assessing proper performance or allocating ownership and accountability in challenging IT projects, questions concerning software quality always arise.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring