Short Reads

Countdown 3 weeks until GDPR : How are controllers and processors required to demonstrate its compliance with the GDPR and to whom?

Stibbe - How are controllers and processors required to demonstrate

Countdown 3 weeks until GDPR : How are controllers and processors required to demonstrate its compliance with the GDPR and to whom?

03.05.2018 BE law

Only 3 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

How are controllers and processors required to demonstrate its compliance with the GDPR and to whom?

Data controllers are required to demonstrate to the supervisory independent public authorities of the EU Member States that they comply with the GDPR. These authorities have investigative powers to verify the lawfulness of the data processing activities performed.

Such verifications are relevant because data controllers and processors are responsible (“principle of accountability”) for implementing - both at the time the means used for processing are determined and at the time of the processing itself - appropriate technical and organizational measures to ensure an effective level of protection of the processed personal data (known as “data protection by design and by default”).

The GDPR indicates various modalities that data controllers or processors can put in place for the purpose of demonstrating that their data processing is lawfully carried out. These include:

  • implementation of internal data protection policies;
  • adoption of codes of conduct approved by associations and other bodies representing categories of controllers or processors;
  • obtainment of data-protection certifications by certification bodies accredited by the supervisory independent public authorities of EU Member States;
  • compliance with guidelines issued by the European Data Protection Board; and/or
  • compliance with specific indications given by a data protection officer.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

12.10.2018 BE law
Ignace Vernimme and Michiel Van Roey speak on IP rightsduring Agoria's Research & Standardization Event

Speaking slot - On Thursday 25 October, Agoria's Regulatory and Standardization Expertise Center organizes its 5th information day about regulations and standards for topics including international trade, privacy and contract law, transport, Internet of Things and blockchain, eHealth, ... at regional, national and European level.

Read more

11.10.2018 NL law
Stibbe hosts NGB Extra Seminar about product development and counsel’s role at the interface of new technology and law

Seminar - On 11 October 2018, Stibbe will host the NGB (Dutch Association of Corporate Lawyers) Extra Seminar.  IT/IP lawyers Judica Krikke, Jasper Klopper, Marc Spuijbroek and Frederiek Fernhout will discuss the practical aspects of the development of innovative new products. 

Read more

12.10.2018 NL law
Tim Berners-Lee's Solid proposal: the future of data traffic?

Short Reads - The General Data Protection Regulation (GDPR) aims to strengthen the rights of individuals in respect of their personal data. Although this aim has been achieved to a certain extent, the fundamental framework of the way personal data is processed remains unchanged. Companies are still able to use large amounts of user data, in many cases without even obtaining their consent. Tim Berners-Lee, the inventor of the World Wide Web, has announced his plans for a decentralised web, in which users remain in control of their personal data.

Read more

10.10.2018 NL law
Ongevraagd advies Raad van State: normering van geautomatiseerde overheidsbesluitvorming

Short Reads - Op 31 augustus 2018 heeft de Afdeling advisering van de Raad van State (hierna: "Afdeling advisering") een 'Ongevraagd advies over de effecten van de digitalisering voor de rechtsstatelijke verhoudingen' betreffende de positie en de bescherming van de burger tegen een "iOverheid" uitgebracht. Het gebeurt niet vaak dat de Afdeling advisering zo een ongevraagd advies uitbrengt. Dit onderstreept het belang van de voortdurend in ontwikkeling zijnde technologie en digitalisering in relatie tot de verhouding tussen de overheid en de maatschappij.

Read more

Our website uses cookies: third party analytics cookies to best adapt our website to your needs & cookies to enable social media functionalities. For more information on the use of cookies, please check our Privacy and Cookie Policy. Please note that you can change your cookie opt-ins at any time via your browser settings.

Privacy – en cookieverklaring