GDPR
General Data Protection Regulation er EU's databeskyttelseslov. Den regulerer hvordan personoplysninger om personer i EU indsamles, behandles, overføres og opbevares, med ekstraterritorial rækkevidde til enhver organisation der behandler disse data.
GDPR har været i kraft siden 25. maj 2018, og tilsynsmyndighederne har udstedt mere end 4 milliarder euro i akkumulerede bøder siden håndhævelsen begyndte. For en SMV er den daglige virkelighed dokumentationssættet: fortegnelse over behandlingsaktiviteter (ROPA), databehandleraftaler (DPA) med hver underdatabehandler, konsekvensanalyser (DPIA) for behandling med høj risiko, og en holdbar position på internationale overførsler. Undtagelsen i Artikel 30 for små organisationer er smallere end den fremstår og gælder næsten aldrig i praksis.
Definitioner
GDPR
The General Data Protection Regulation is the European Union’s data protection law, in force since 25 May 2018. Article 3 sets its extraterritorial reach: it applies to processing in the context of an EU establishment, and to any non-EU controller or processor that offers goods or services to people in the EU or monitors their behaviour within the EU.
Records of Processing Activities (ROPA)
A Record of Processing Activities is the written inventory of personal data processing operations required by Article 30 of the GDPR. Controllers and processors must maintain one, make it available to the supervisory authority on request, and keep it current.
Data Processing Agreement (DPA)
A Data Processing Agreement is the contract required by GDPR Article 28 whenever a controller engages a processor to process personal data on its behalf. It must set out the subject matter, duration, nature and purpose of processing, categories of data, controller obligations, and the processor’s commitments on security, confidentiality, sub-processors, and assistance.