logo text

Showing posts with label One Stop Shop. Show all posts
Showing posts with label One Stop Shop. Show all posts

Thursday, 5 May 2016

May the fourth be with you GDPR - finally approved and in force from 25 May 2016!

The European Parliament formally adopted the General Data Protection Regulation ("GDPR") and it was then published in the EU Official Journal on 4th May 2016. Star Wars fans and data protection geeks alike were no doubt cheering 'May the fourth be with you' all day yesterday.  From today, 5th May 2016, the 20 day countdown period commenced and the GDPR will come into force on 25 May 2016. After the 2 year implementation period, it will become directly applicable and enforceable in all Member States from 25 May 2018.

Organisations must therefore now begin ensuring that new policies, procedures and systems are in place to ensure compliance.

The ICO has created a micro-site dedicated to updates on the GDPR and aims to ensure that all relevant GDPR guidance and any guidance updated in light of the GDPR will be added to that site. The ICO's initial posting on the site sets out a useful guide on 12 suggested steps to take now in order to prepare for the GDPR.

The EU Article 29 Working Party ("Art29 WP") has also published its action plan outlining how the GDPR should be implemented. The Art29 WP highlights 4 priority areas:
  1. Setting up the European Data Protection Board ("EDPB") structure and its administration;
  2. Preparing the One-Stop-Shop and the consistency mechanism;
  3. Issuing guidance for data controllers and processors; and
  4. Communication around the EDPB and the GDPR.

Many of our clients have begun asking us for bespoke advice on how the GDPR will affect them and have asked us to carry out data protection compliance and gap analysis audits, highlighting increased compliance risks under the proposed GDPR changes.  If we can assist you with this also, please do contact us.

Friday, 2 October 2015

ECJ Weltimmo Case: More obligations for Pan European Operators



On the 1st October 2015, the European Court of Justice made a landmark ruling that all international organisations should abide by the data protection legislation that exists in all the jurisdictions in which they operate.  
This decision centered on the outcome of the ECJ Weltimmo case, which was brought by the Hungarian data protection authority against property website Weltimmo. Weltimmo ran a property advertising service in Hungary even though it was based in Slovakia.  The Court found that cross border activity by the Slovakian company sharing information with debt collection agencies, was deemed to have breached data protection laws in Hungary, ruling that:  
  • No matter what size of operation exists in each member state, companies must apply the data protection legislation of that member state to all of its activities if it has an establishment within that country.  If, for example, the organisation operates a service in the native language of a country, has offices or bank accounts in that country or has representatives registered in that country;
  • Organisations are then regulated by the relevant EU countries’ national data protection authorities even if the organisation is not headquartered in the country of that Regulator.  That means those Regulators can impose fines where those exist.  In the Weltimmo case, this means they could be liable for the 10m Hungarian forint fine (£23,650) which had been issued by the Hungarian data protection authority;
  • If it cannot be shown that an “establishment” exists in that EU member state, then the relevant local data protection authority in that member state would not be able to issue fines and/or enforcement action and would have to instead rely on the data protection authority or the relevant member state where the organisation was based.
In practical terms, this Case means that all organisations will need to ensure they keep abreast of the relevant legislative variations across Europe and this will of course place considerable additional administrative burdens on organisations and raise their compliance costs dramatically.  For example, the costs and potential adverse repercussions of not getting on top of your requirements if you market to a number of different organisations via your sales website or similar, could be huge.
Whilst there has been much talk of the impact of this case on the big technology companies like Facebook and Google, who process data here in Europe, it is clear that in the age of the multinational, costs for remaining compliant will dramatically increase for all sorts of organisations – especially those that are consumer-facing and those that operate in EU Member States that have a stronger appetite for enforcement. 
Previously, companies only had to adhere to the data protection legislative requirements of one county, and a lot of multinationals chose to create the nominated establishment in either the UK or Ireland where the laws and practices were more relaxed.  
If you require advice on data protection compliance and privacy matters, or to understand how any of the recent ECJ judgements might affect the operations of your organisation, please do not hesitate to reach out to Pritchetts for tailored advice.