Privacy Policy and GDPR: What To Update

Privacy Policy and GDPR: What To Update

The General Data Protection Regulation (GDPR) requires organisations, processing personal data as controllers, to provide the individuals concerned with a privacy notice. This document must explain to the individuals how their personal information is processed.  

Although it was already a requirement under the former legislation, the GDPR requires controllers to provide more detailed privacy notice whose content may differ slightly depending on whether or not the personal data have been collected directly from the individuals. 

Does GDPR apply to your business?

Does GDPR apply to your business?

The territorial scope of the new data protection regulation applicable from May 2018 (GDPR) is much wider than the one of the current directive 95/46/CE. 

As a consequence, the new data protection rules may apply to any business whether or not it is located within the EU if certain conditions are met.

Below a questionnaire/guidance that should help  consider whether or not the GDPR applies to a specific activity. However, given the complexity of some definitions,  a detailed analysis of the activities might be necessary to answer accurately some of the questions.

What’s GDPR?

What’s GDPR?

The General Data Protection Regulation (“GDPR”) is a European regulation applicable since May 25, 2018. It is aimed at strengthening the protection of individuals’ personal information by providing them with more control over their personal data and making organisations processing these data more accountable than under the previous legal regime (i.e. the directive 95/46/EC).

The purpose of this article is to provide an overview of what the GDPR consists of and what the main changes are compared to the previous applicable legislation.