From 25 May 2018, the GDPR will provide uniform and direct regulation of data protection law within the EU. Who is affected, and what does it cover? 

An overview of the key provisions of the GDPR

The data protection directives currently in force will be replaced by the Regulation; the Federal Data Protection Act and all other national data protection regulations will, to a large extent, be superseded. As the rules have been adopted in the form of a Regulation, they apply uniformly across EU Member States, but are also enshrined in national legislation.

CTA Box GDPR

Here are the key facts:

  • The General Data Protection Regulation (GDPR) explicitly applies to providers based outside the EU as well, provided that their services are directed at EU citizens (such as Facebook and Google). The location where the data is processed is no longer relevant.
  • Every organisation must be able to demonstrate that it has an overall strategy for ensuring compliance with data protection regulations („accountability“). It must also review this strategy regularly and refine it where necessary.
  • Data subjects must be provided with more comprehensive information than before regarding data processing and their rights. To this end, details such as the retention period and the contact details of the data protection officer must be published. If the balancing of interests is used as the legal basis, the „legitimate interests“ must also be listed.
  • Almost any breach of the GDPR is liable to penalties. The range of fines has been significantly increased and may amount to up to EUR 20 million or 4 per cent of total worldwide annual turnover, whichever is higher.
  • The existing prior check is to be expanded into a risk and impact assessment. The requirement for regular audits is intended to minimise the risk of data protection breaches.
  • There is still no „group privilege“, but data processing within corporate groups is being simplified. On the one hand, transfers for internal administrative purposes are recognised as ‘legitimate’. On the other hand, several bodies may join forces to process data jointly – in which case they act and are liable as joint controllers.
  • In future, all data breaches must be reported, regardless of the type of data, provided there is a risk to data protection. The report must be submitted to the supervisory authority within 72 hours of the breach coming to light. Those affected must also be notified „without undue delay“.

Data protection? Opti.Tax!

Whether you wish to deal with the matter of data protection documentation yourself or have appointed a data protection officer, The solution is called Opti.Tax.

With the Opti.Tax taxonomy software, you’re not just getting a stand-alone solution; you’re getting a powerful tool that can be expanded over the long term. Practical and fair: you don’t have to buy the whole package straight away; you can tailor your licence to suit your needs.