{"id":8713,"date":"2020-01-06T14:13:39","date_gmt":"2020-01-06T22:13:39","guid":{"rendered":"https:\/\/www.knowledgecity.com\/blog\/?p=8713"},"modified":"2024-04-05T10:47:32","modified_gmt":"2024-04-05T17:47:32","slug":"compliance-general-data-protection-regulation","status":"publish","type":"post","link":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/","title":{"rendered":"How to be in Compliance with the General Data Protection Regulation"},"content":{"rendered":"<p>If you do any business that could gather information from citizens of the European Union, you must make sure that your organization is in compliance or face hefty fines.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter wp-image-8720 size-full\" src=\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg\" alt=\"IT professionals working in server room with GDPR compliance logo visible.\" width=\"804\" height=\"387\" srcset=\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg 804w, https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR-600x289.jpg 600w, https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR-300x144.jpg 300w, https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR-768x370.jpg 768w\" sizes=\"(max-width: 804px) 100vw, 804px\" \/><\/p>\n<p><strong>What is the GDPR?<\/strong><\/p>\n<p>The General Data Protection Regulation serves to protect several <a href=\"https:\/\/www.csoonline.com\/article\/3202771\/general-data-protection-regulation-gdpr-requirements-deadlines-and-facts.html\">types of personal data<\/a> including name, address, identification numbers, location and IP addresses, cookie data, and personal information (racial and ethnic data, health and genetic data, biometrics, political affiliations, gender and identity, etc.).<\/p>\n<p><strong>Personal and Sensitive Data<\/strong><\/p>\n<p>The European Union <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-personal-data_en\">defines personal data<\/a> as \u201cany information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.\u201d The GDPR protects personal data of all residents of the European Union regardless of the technology used to process that data. Regardless of how data is gathered, stored, or processed, it is protected by the GDPR.<\/p>\n<p><strong>\u00a0<\/strong><strong>Who Must Comply?<\/strong><\/p>\n<p>The GDPR <a href=\"https:\/\/digitalguardian.com\/blog\/what-gdpr-general-data-protection-regulation-understanding-and-complying-gdpr-data-protection\">applies to<\/a> all members of the European Union, as well as any company outside of the EU that markets goods or services to EU citizens. As a result, the GDPR affects global data protection requirements. Most companies that do international business must be compliant with GDPR because of this.<\/p>\n<p><strong>\u00a0<\/strong><strong>How This Affects You and Your Business<\/strong><\/p>\n<p>The GDPR mandates that equal liability is applied to data controllers (the organizations that own the data) and data processors (organizations that manage the data). If your organization uses the services of a third-party data processor that is not in compliance, then your organization is <a href=\"https:\/\/www.csoonline.com\/article\/3202771\/general-data-protection-regulation-gdpr-requirements-deadlines-and-facts.html\">not in compliance<\/a>. It is important to revise contracts with third party data processors that define how data should be managed and protected, as well as how breaches of data security should be handled.<\/p>\n<p>For <a href=\"https:\/\/www.forbes.com\/sites\/theyec\/2018\/08\/10\/what-is-the-general-data-protection-regulation-and-should-you-care\/#401d8cc0408b\">U.S.-based businesses<\/a>, there is an increased need to evaluate consent. GDPR pushes companies to make updates that give consumers greater control over their personal data, including how it is shared and gathered. Furthermore, minors under the age of 16 need parental consent to share personal data, meaning that companies need to be mindful of adding age clauses to their privacy policies.<\/p>\n<p>The GDPR imposes fines on companies that control and process data that are found to be non-compliant. <a href=\"https:\/\/gdpr-info.eu\/issues\/fines-penalties\/\">Fines<\/a> are determined based on the following criteria:<\/p>\n<ul>\n<li>Nature of infringement<\/li>\n<li>Intention<\/li>\n<li>Mitigation<\/li>\n<li>Preventative measures<\/li>\n<li>History<\/li>\n<li>Cooperation<\/li>\n<li>Data type<\/li>\n<li>Notification<\/li>\n<li>Certification<\/li>\n<\/ul>\n<p>Organizations that are found to be non-compliant face fines as high as <a href=\"https:\/\/www.forbes.com\/sites\/theyec\/2018\/08\/10\/what-is-the-general-data-protection-regulation-and-should-you-care\/#401d8cc0408b\">4 percent<\/a> of the company\u2019s annual revenue.<\/p>\n<p><strong>GDPR Requirements<\/strong><\/p>\n<p><strong>\u00a0<\/strong>There are specific requirements that organizations must meet to be compliant with the GDPR. These include:<\/p>\n<ul>\n<li>Need for consent from individuals \u2013 <a href=\"https:\/\/gdpr-info.eu\/issues\/consent\/\">Consent<\/a> requires that individuals opt-in to allow data processing with their information. The individual must have the right to revoke consent at any time. A child under 16 years of age cannot give consent and parental consent may be required on behalf of the minor<\/li>\n<li>Providing notification in the case of a data breach \u2013 In the case of a <a href=\"https:\/\/gdpr-info.eu\/art-33-gdpr\/\">data breach<\/a>, the GDPR requires a report to be made to a supervisory authority within 72 hours of becoming aware of the breach. If the breach causes individuals to be put at risk, they must notify all potentially affected individuals<\/li>\n<li>Safe transferring of data \u2013 A <a href=\"https:\/\/gdpr.eu\/data-protection-impact-assessment-template\/\">data protection impact assessment<\/a> is required to be done if the transfer of any highly sensitive data has occurred. This includes information such as systematic and extensive profiling with significant effects, special categories of data including criminal history. Additionally, the assessment requires that organizations systematically monitor places that are publicly accessible on a large scale<\/li>\n<li>Establishment of data protection officers \u2013 The GDPR has provisions for organizations that are not based in the EU which require them to appoint a <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/accountability-and-governance\/data-protection-officers\/\">GDPR representative<\/a> that is based in the EU and to whom supervisory authorities report to if there is a violation<\/li>\n<\/ul>\n<p><strong>Individual\u2019s Rights<\/strong><\/p>\n<p>The GDPR has specified 8 major <a href=\"https:\/\/www.itgovernance.co.uk\/blog\/what-are-the-data-subject-rights-under-the-gdpr\">Rights for individuals<\/a>:<\/p>\n<ul>\n<li>Right to be informed \u2013 Individuals are allowed information about the collection and use of their data, the purpose for processing their data, how long the data will be stored, who the data is shared with and data breaches<\/li>\n<li>Right to access \u2013 Individuals can access their data. Individuals can receive confirmation that a business is collecting data and can receive a copy of that data<\/li>\n<li>Right to rectification \u2013 Individuals can have their data changed if there are inaccuracies<\/li>\n<li>Right to restrict processing \u2013 Individuals can work with organizations to restrict the processing of their personal data but only in <a href=\"https:\/\/gdpr-info.eu\/art-18-gdpr\/\">certain cases<\/a><\/li>\n<li>Right to be forgotten \u2013 Individuals can request to have their information removed but only under <a href=\"https:\/\/gdpr-info.eu\/art-17-gdpr\/\">certain circumstances<\/a><\/li>\n<li>Right to object \u2013 Individuals can object to having their data processed by an organization<\/li>\n<li>Right to data portability \u2013 Data portability gives individuals the ability to reuse their information as they determine to be appropriate as long as consent was given to collect the data<\/li>\n<li>Right to refuse automated decision making \u2013 Individuals have the right that decisions not be made solely on automatic processing in cases where there would be legal (or similar) effects<\/li>\n<\/ul>\n<p><strong>Enforcement<\/strong><\/p>\n<p>Since the GDPR does not have a single agency in charge of enforcing rules, each EU country must have <a href=\"https:\/\/gdpr-info.eu\/art-51-gdpr\/\">supervisory authorities<\/a> that work to enforce the regulations in the GDPR and impose fines for violations.<\/p>\n<p>The duties of supervisory authorities include:<\/p>\n<ul>\n<li>Monitoring and enforcing regulations<\/li>\n<li>Handle and investigate complaints<\/li>\n<li>Keeping the public aware of risks, rules, protections and individual rights<\/li>\n<li>Monitoring the development of information and communication technologies<\/li>\n<li>Issue warnings, fines and bans for any violations found<\/li>\n<\/ul>\n<p><strong>GDPR Audit<\/strong><\/p>\n<p>Your Organization needs to <a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-data-audit\/\">conduct an audit<\/a> to determine whether or not you are in compliance with the GDPR. An audit can help you identify areas that require improvement and keep you compliant.<\/p>\n<p>Questions to ask during an audit include:<\/p>\n<ul>\n<li>How and where does your organization move and store data?<\/li>\n<li>Do you have a data protection officer?<\/li>\n<li>Who has access to the data your organization stores?<\/li>\n<li>Is your organization aware of GDPR notification requirements?<\/li>\n<li>Are your organization\u2019s notifications clear?<\/li>\n<li>Is there a legal basis for processing and collecting data?<\/li>\n<li>Is there documented proof of your organization\u2019s legal basis?<\/li>\n<li>What is your organization doing to manage data risks?<\/li>\n<li>What data does your organization have?<\/li>\n<li>What does your organization use the data for?<\/li>\n<\/ul>\n<p><strong>Next Steps<\/strong><\/p>\n<p>As you can see, it is crucial to make sure that your business is in compliance with the GDPR if you do any type of business that affects any citizen of the European Union. Fight the urge to convince yourself that since your company is not in the EU, the changes to the GDPR do not affect the way you do business. In a rapidly changing online world, data protections are changing to keep up with potential problems and challenges. Protect yourself and your organization by taking KnowledgeCity\u2019s <a href=\"https:\/\/www.knowledgecity.com\/en\/library\/69827\/course\/general-data-protection-regulation\">online course<\/a> \u201cGeneral Data Protection Regulation\u201d to help you more fully understand what individuals are entitled to with their data and how your organization can make key changes that will keep you in compliance with the GDPR.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you do any business that could gather information from citizens of the European Union, you must make sure that your organization is in compliance or&#8230;<\/p>\n","protected":false},"author":5,"featured_media":8720,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":""},"categories":[3954],"tags":[3540,474,387,3539,3538],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to be in Compliance with the General Data Protection Regulation - KnowledgeCity<\/title>\n<meta name=\"description\" content=\"Learn key strategies to ensure your organization is fully compliant with GDPR regulations.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to be in Compliance with the General Data Protection Regulation - KnowledgeCity\" \/>\n<meta property=\"og:description\" content=\"Learn key strategies to ensure your organization is fully compliant with GDPR regulations.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/\" \/>\n<meta property=\"og:site_name\" content=\"KnowledgeCity\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/KnowledgeCity\/\" \/>\n<meta property=\"article:published_time\" content=\"2020-01-06T22:13:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-05T17:47:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"804\" \/>\n\t<meta property=\"og:image:height\" content=\"387\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Knowledge_City\" \/>\n<meta name=\"twitter:site\" content=\"@Knowledge_City\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"KnowledgeCity\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/#website\",\"url\":\"https:\/\/www.knowledgecity.com\/blog\/\",\"name\":\"KnowledgeCity\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.knowledgecity.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg\",\"contentUrl\":\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg\",\"width\":804,\"height\":387},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#webpage\",\"url\":\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/\",\"name\":\"How to be in Compliance with the General Data Protection Regulation - KnowledgeCity\",\"isPartOf\":{\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#primaryimage\"},\"datePublished\":\"2020-01-06T22:13:39+00:00\",\"dateModified\":\"2024-04-05T17:47:32+00:00\",\"author\":{\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/#\/schema\/person\/b9b8256f9b75ae1e344f74de240a4edd\"},\"description\":\"Learn key strategies to ensure your organization is fully compliant with GDPR regulations.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/\"]}]},{\"@type\":\"BreadcrumbList\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@id\":\"https:\/\/www.knowledgecity.com\",\"name\":\"KnowledgeCity\"}},{\"@type\":\"ListItem\",\"position\":2,\"item\":{\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/\",\"name\":\"Blog\"}},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"How to be in Compliance with the General Data Protection Regulation\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/#\/schema\/person\/b9b8256f9b75ae1e344f74de240a4edd\",\"name\":\"KnowledgeCity\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.knowledgecity.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2023\/06\/user-96x96.png\",\"contentUrl\":\"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2023\/06\/user-96x96.png\",\"caption\":\"KnowledgeCity\"},\"sameAs\":[\"http:\/\/knowledgecity.com\"],\"url\":\"https:\/\/www.knowledgecity.com\/blog\/author\/raynie\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to be in Compliance with the General Data Protection Regulation - KnowledgeCity","description":"Learn key strategies to ensure your organization is fully compliant with GDPR regulations.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/","og_locale":"en_US","og_type":"article","og_title":"How to be in Compliance with the General Data Protection Regulation - KnowledgeCity","og_description":"Learn key strategies to ensure your organization is fully compliant with GDPR regulations.","og_url":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/","og_site_name":"KnowledgeCity","article_publisher":"https:\/\/www.facebook.com\/KnowledgeCity\/","article_published_time":"2020-01-06T22:13:39+00:00","article_modified_time":"2024-04-05T17:47:32+00:00","og_image":[{"width":804,"height":387,"url":"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_creator":"@Knowledge_City","twitter_site":"@Knowledge_City","twitter_misc":{"Written by":"KnowledgeCity","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.knowledgecity.com\/blog\/#website","url":"https:\/\/www.knowledgecity.com\/blog\/","name":"KnowledgeCity","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.knowledgecity.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg","contentUrl":"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2020\/01\/GDPR.jpg","width":804,"height":387},{"@type":"WebPage","@id":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#webpage","url":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/","name":"How to be in Compliance with the General Data Protection Regulation - KnowledgeCity","isPartOf":{"@id":"https:\/\/www.knowledgecity.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#primaryimage"},"datePublished":"2020-01-06T22:13:39+00:00","dateModified":"2024-04-05T17:47:32+00:00","author":{"@id":"https:\/\/www.knowledgecity.com\/blog\/#\/schema\/person\/b9b8256f9b75ae1e344f74de240a4edd"},"description":"Learn key strategies to ensure your organization is fully compliant with GDPR regulations.","breadcrumb":{"@id":"https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.knowledgecity.com\/blog\/compliance-general-data-protection-regulation\/"]}]},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"https:\/\/www.knowledgecity.com","name":"KnowledgeCity"}},{"@type":"ListItem","position":2,"item":{"@id":"https:\/\/www.knowledgecity.com\/blog\/","name":"Blog"}},{"@type":"ListItem","position":3,"name":"How to be in Compliance with the General Data Protection Regulation"}]},{"@type":"Person","@id":"https:\/\/www.knowledgecity.com\/blog\/#\/schema\/person\/b9b8256f9b75ae1e344f74de240a4edd","name":"KnowledgeCity","image":{"@type":"ImageObject","@id":"https:\/\/www.knowledgecity.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2023\/06\/user-96x96.png","contentUrl":"https:\/\/www.knowledgecity.com\/blog\/wp-content\/uploads\/2023\/06\/user-96x96.png","caption":"KnowledgeCity"},"sameAs":["http:\/\/knowledgecity.com"],"url":"https:\/\/www.knowledgecity.com\/blog\/author\/raynie\/"}]}},"_links":{"self":[{"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/posts\/8713"}],"collection":[{"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/comments?post=8713"}],"version-history":[{"count":9,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/posts\/8713\/revisions"}],"predecessor-version":[{"id":22827,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/posts\/8713\/revisions\/22827"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/media\/8720"}],"wp:attachment":[{"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/media?parent=8713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/categories?post=8713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.knowledgecity.com\/blog\/wp-json\/wp\/v2\/tags?post=8713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}