No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

What You Need to Know about GDPR

by Cecile Georges
July 24, 2017
in Data Privacy, Featured
black hourglass with white sand on red background

5 Key Changes on the Way

Although nearly a year away, the EU’s new General Data Protection Regulation (GDPR) is fast-approaching for multinational companies, and the clock is ticking to ensure compliance. The changes coming will have far-reaching implications for global businesses: any company operating in the EU must comply or face steep financial penalties.

It’s hard to believe that we’re now less than one year out from the implementation of a major change to data protection laws in Europe: The General Data Protection Regulation, or GDPR.  It is the result of four years’ work by the European Union (EU) to standardize privacy laws and protect residents of the EU from the misuse of their personal data and data breaches in an increasingly digital world.

Most of the personal data protection laws in the EU haven’t been updated since the 1995 Data Protection Directive. In 1995, only one percent of the European population was using the internet. Now, not only is the majority of the global economy digital, but many companies are operating globally and processing personal data across borders. The EU Parliament established the GDPR framework as a way to update and harmonize the laws specific to the usage of millions of individuals’ data.

With these regulations, which take effect on May 25, 2018, come a number of major implications that reach beyond the borders of the EU’s 28 member countries. In fact, any company that stores, processes or touches data coming from Europe will need to comply with GDPR. A recent survey by Compuware® found that 52 percent of large U.S. companies acknowledge they possess EU customer data, which means they’ll need to comply with GDPR even though they are based in the United States.

According to a global survey by Dell®, more than 60 percent of companies say they have not begun preparing for GDPR. This could be problematic. With GDPR, the onus largely will be on companies to ensure and demonstrate they are in compliance. It’s important for companies to understand what’s new about the law versus what was already required and implemented within their organizations in terms of data protection and privacy. Once you know that, you can determine current gaps and take the proper actions to be in compliance when GDPR goes into effect.

Here are the key changes of the regulation, along with what you need to know to ensure your company is prepared to comply:

Steeper Sanctions

Under GDPR, penalties for noncompliance will be much larger than they were in the past. Previously, noncompliance fines were managed on a country-by-country basis, where each penalty was assessed by the country in which the noncompliance occurred. GDPR harmonizes these regulations and fines. If you infringe upon the law, the fine could be up to €20 million or 4 percent of your company’s worldwide revenue, whichever is higher. Additionally, supervisory authorities in the EU will define consistent scaled layers of sanctions that will be delivered based on the severity of the offense.

Greater Accountability on the Part of the Company

Currently, companies that process data rely on the regulatory bodies of their country to check that they are meeting standards. Under GDPR, companies now will have to conduct their own self-assessments to ensure they are compliant with the law. No governing body will proactively tell a company, “Yes, you can move forward with this processing, it’s compliant.” Rather, it’s the responsibility of companies to ensure they are in compliance and to ensure their vendors, suppliers and other partners are complying with the law. Additionally, if something goes awry, companies will have to take the proper steps to prove they’ve done a data protection-impact assessment to show they adequately addressed the issue.

Greater Individual Rights and Breach Notification

GDPR will grant people more control over how their personal data is processed, used and retained. Additionally, the law will also implement mandatory breach notification, which is already in place in some states in the U.S. but is rare in Europe at the moment. If there is a data breach, companies will have to notify regulators (supervisory authorities in the EU) about the case and, depending on the level of risk, may also have to notify individuals.

Transferring Data Outside of the EU

Binding corporate rules are policies covering transfer of data to countries located outside of Europe that do not provide an adequate level of protection according to the European standards. Companies planning to or already using binding corporate rules will be showing their commitment to protect personal data in accordance with the standards required in the EU, regardless of where the European data is processed, accessed or hosted.

Facilitating Business Operations

There’s no doubt complying with GDPR will be demanding for companies; however, GDPR will benefit organizations due to the fact that harmonized regulation across Europe will help facilitate business operations and eliminate some paperwork. Globally, as the world moves toward greater individual data privacy rights, businesses already prepared to protect data are less likely to miss out on potential business from clients around the world.

While GDPR consists of 99 articles, in the end, all of the requirements won’t be entirely new to companies. If you’re still learning about GDPR, act now to ensure you fully understand the regulation, perform a gap analysis that inventories your organizations’ current data processing and then put in place measures to ensure you’ll be in compliance with GDPR on time and beyond May 2018.


Tags: Data BreachGDPR
Previous Post

Data Privacy and the EUGDPR 2017: A Survey of U.S. Privacy Professionals

Next Post

The Challenges of Auditing Corporate Risk Culture Explored in New Edition of “Internal Auditing Around the World” by Protiviti

Cecile Georges

Cecile Georges

Cécile Georges is the Chief Privacy Officer (CPO) of ADP. She has led the Privacy and Data Governance Team, which is part of the Global Compliance organization, since December 2016. The Team provides advice and operational guidance to all ADP business units globally, and is responsible for the design and implementation of ADP’s enterprise-wide compliance programs with respect to the protection of personal information. In her previous role as the lead lawyer for the Asia-Pacific region, Cecile relocated from Paris, France to Singapore, where she supported the geographical expansion of ADP in the Asia-Pacific region.  Cecile joined ADP in 1999 and was instrumental in building the Legal function in France. In 2006, she was appointed as the head of Legal for Europe and was promoted to VP, Assistant General Counsel. In 2011, her scope was expanded and she was responsible for all of Employer Services International Legal. Cécile has always been focused on the development of performance-driven teams that deliver excellent services to the business and ADP clients. Cécile holds a Magistère (Masters) in Information Technology Law and passed the Paris Bar.

Related Posts

new york and us flags

New York Tightens the Breach Clock: 30 Days to Notify

by Melissa Crespo and Reiley Porter
May 12, 2025

State joins growing national trend toward broader personal information definitions and stricter notification timelines for data compromises

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

gdpr website screenshot

In the World of JavaScript, GDPR Consent Forms Merely Scratching the Surface

by Rui Ribeiro
December 16, 2024

Consent forms alone don’t mean much when consumers are so tired of checking boxes they don’t even read the policies

Next Post
The Challenges of Auditing Corporate Risk Culture Explored in New Edition of “Internal Auditing Around the World” by Protiviti

The Challenges of Auditing Corporate Risk Culture Explored in New Edition of “Internal Auditing Around the World” by Protiviti

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights