ITSM Readiness Checklist
12 min read
Get the checklist →A historical overview of the EU GDPR's scope, principles, data-subject rights, and security requirements.
The EU General Data Protection Regulation has applied since 25 May 2018. Its purpose is to harmonize privacy law across Europe. It covers organizations and establishments in the European Union that process personal data.
Under certain conditions, it also applies to organizations outside the EU when processing relates to offering goods or services to people in the Union or monitoring their behavior.
Organizations therefore need to understand the requirements for lawful processing, the obligations the regulation creates, and the potential consequences of non-compliance.
Supervisory authorities monitor and enforce application of the regulation. They handle questions and complaints from data subjects, raise awareness of controllers' obligations, and investigate whether requirements are being observed.
Their powers range from warnings to instructions intended to protect data-subject rights. Depending on the infringement, penalties can reach EUR 20 million or four percent of worldwide annual turnover in the preceding financial year.
The regulation is built around central principles for processing personal data. Data must be:
Security and protection against unauthorized or unlawful processing, accidental loss, destruction, or damage are equally important. Appropriate technical and organizational measures should safeguard these objectives. Controllers must be able to demonstrate compliance with the principles.
Processing may be based on the data subject's consent. Other possible legal bases include performance of a contract, compliance with a legal obligation, a task carried out in the public interest, and legitimate interests pursued by a controller or third party. The appropriate basis depends on the specific processing activity.
Data subjects have rights concerning their personal data, including:
Controllers must implement appropriate technical and organizational measures after considering the nature, scope, circumstances, and purpose of the processing. The measures should be proportionate to the activities and risks, while accounting for implementation costs and the state of the art.
The measures described include:
This article reflects the information available at the time of publication and does not constitute legal advice.
Talk to our experts about your specific challenges. We provide honest assessments and actionable recommendations.
Practical implementation
Discuss your current situation with heureka. Together, we can clarify priorities, ownership, and the most useful place to start.
12 min read
Get the checklist →16 min read
Get the whitepaper →5 min
Start assessment →