PRIVACY

GDPR 679/2016 – Legislative Decree 101/2018

I am able to manage all the obligations required for professionals and businesses by the new European Regulation 2016/679 (GDPR), starting from the analysis of the characteristics of the organization. I provide a series of guided procedures capable of speeding up and simplifying compliance with regulatory obligations. The user is then accompanied step by step in the creation and personalized printing of all the documents required by the new regulation (informative, letters of appointment, verbal, record, etc.).

First free appointment to understand the company structure and give you information on the treatments you carry out, this is because every company is unique and it is necessary to understand how to tailor the legislation to it, as not all requirements are necessary for all companies. After this evaluation I will send the estimate for compliance with privacy legislation.

GDPR was published in the European Official Journal on 4 maggio 2016 and entered into force on 25 May of the same year. From 25 maggio 2018, will start to take effect, replacing the Data Protection Directive (officially Directive 95/46/EC) established in 1995, and repealing the rules that are incompatible with the Code for the protection of personal data (dlgs.n. 196/2003) currently in force and subsequently modified by Legislative Decree no. 101/2018).

WHAT IS THE GDPR

GDPR is the Data Security Regulation that adapts to digital evolution. La Digital Transformation, Cloud computing and the Internet of Things are among the factors responsible for an exponential increase in data present on a global scale. It is estimated, indeed, which have been produced in the last two years 90% of data present on the Internet. This mass of data, which takes the name of “Big Data”, requires particular attention regarding Security and Privacy.

The European Commission has established a Regulation with which to fulfill this need: GDPR UE 2016/679, acronimo di General Data Protection Regulation. This Regulation has the following objectives:

1.      Make the protection of personal data of citizens and residents of the European Union more homogeneous, both inside and outside the borders of the European Union.

2.      Address the issue of exporting personal data outside the European Union.

3.      Optimize control of the personal data of citizens residing in the European Union, adapting the legislation based on the context concerning international affairs in which the data controller finds himself. Unlike the current directive, it is acceptable that the data controller is a company, agency, company or body with registered office outside the EU.

4.      Reduce cyber attacks that aim to cause corruption, of any nature, of the personal data of citizens referred to in point 3.

GDPR is important because it represents a useful and versatile tool available to data controllers that adapts to the context in which the company finds itself. This means that the GDPR is not a list of rigid rules to comply with, but on the other hand the company must pay particular attention to be able to achieve the objectives set in the Regulation.

The main purpose of the GDPR is to reduce cyber attacks by knowing the specific vulnerabilities of the company.

Precisely because of its versatility, heavy fines are also imposed in case of failure to comply with the Regulation itself.

THE NEW KEYWORDS

ACCOUNTABILITY: The data controller of personal data is the one who determines the purposes and means of the processing, and is responsible for the risks inherent to the rights and freedoms of natural persons, who must demonstrate that he has adopted the appropriate measures to guarantee that the processing actually complies with the Regulation. These measures, precisely because of the versatility of the GDPR, they adapt to the business context.

PRIVACY BY DESIGN:

Describes the need to design the IT systems that will use personal data in a way that protects the privacy of those interested in the processing. In this way, the management of the data life cycle is prepared which begins with collection and ends with deletion. Furthermore, accuracy must be taken into account, the integrity and confidentiality of the data in question.

Al Data Protection Officer (DPO) o “Data Protection Officer” is responsible for planning (to design) and safely manage the IT system that processes personal data.

PRIVACY BY DEFAULT:

Describes the need to protect, as default, the privacy of those interested in the processing. In this way, only the personal data necessary for the purposes of the processing may be collected and used by the IT systems and data controllers, in a specific retention period.

HOW IT IS POSSIBLE TO COMPLY WITH THE GDPR BY 25 MAGGIO 2018?

What is required of data controllers is to demonstrate that they have adopted suitable security measures regarding the processing of data. To be able to prove it, you must produce a written and/or paper document consisting of no. 2 moduli:

1.      technological module: in which you must demonstrate that you have implemented all the necessary technical functions, come:

· Reduce IT infrastructure vulnerabilities, implementing technologies such as:

–        Antivirus

–        Cyber ​​threat reporting software, starting from the real and timely analysis of the situation of the company systems (company domain, specific email addresses, company IP address)

–        Firewall

–        Encryption of personal data (pseudonymisation and encryption of personal data)

–        Double-factor authentication in the case of VPN

–        Reliable data backup (ability to promptly restore data availability and access in the event of a physical or technical incident, inoltre AES256 bit encryption)

·Training of IT managers, of managers and staff, who must be aware of the GDPR Regulation and how personal data is used.

2.      legal form: in which having to demonstrate a legal adaptation in line with what is expressed by the GDPR, addressing issues such as:

· Privacy by default: The amount of personal data used must be reduced to the minimum necessary to be able to achieve the intended purposes in the period of time necessary for these purposes.

· Privacy by design: Placing the privacy of the data subject at the center of the project in question. In this way, we try to prevent any risks of incurring damage to the interested party, which then reflect on the company itself, in economic and image terms.

This document is called Assessment, in which the data controller includes the overall assessment of the current situation regarding the protection of personal data, in the points expressed by the GDPR.

ECONOMIC SANCTIONS

Anyone who suffers material or immaterial damage caused by a violation of this Regulation has the right to obtain compensation for the damage from the data controller - or from the data controller -, if and only if, the latter is unable to demonstrate that the damage in question is in no way attributable to him.

The Regulation, Therefore, provides for the attribution of one of the following economic sanctions:

· a fine of up to 10 million euros or up to 2% of the global turnover recorded in the previous year in the cases provided for by the Article 83, Paragraph 4 of the Regulation;

· until 20 million euros or up to 4% of the turnover in the cases provided for in the Paragraphs 5 e 6 of the Regulation.