On 25 May 2018, the EU General Data Protection Regulation (GDPR) comes into force. It replaces the data protection legislation in force up to that point and brings with it a number of changes. To ensure continued compliance with the law in the face of the new regulations – which are no less complicated than the old ones – companies are advised to adopt a systematic approach.
Opti.Tax = GDPR-compliant
Opti.Tax Data Protection Documentation assists with implementation and provides taxonomies similar to those already used for the e-balance sheet. The data protection taxonomies form a framework within which each requirement of the GDPR is explained and its implementation within the organisation can be recorded. Data collection can also take place in interview mode, with the answers being entered into the taxonomy items. The task management function allows a taxonomy item to be forwarded to an employee for processing, with a deadline set. Live reporting generates a corresponding data protection report. Version control ensures that only changes need to be recorded in order to maintain both current and historical reports.
The status of implementation in the following areas is being reviewed:
- Organisational structure and accountability within the company
- Overview of processing operations
- Involvement of external parties
- Transparency, information requirements and safeguarding the rights of data subjects
- Accountability, managing risks
- Data breaches
It is planned that, once the EU General Data Protection Regulation comes into force, the supervisory authorities will use a questionnaire to assess the current state of implementation within the organisation.
The taxonomies set out the considerations required to prepare for the EU General Data Protection Regulation. Firstly, you should consider where legal texts relevant to data protection are used. Classic examples of this include privacy notices and consent forms on websites, in standard contracts with end customers, or even contracts between businesses. The obligations to provide evidence are also being revised. Under current legislation, a company must be shown to have breached data protection provisions if fines are to be imposed. Once the General Data Protection Regulation comes into force, a company that processes personal data must be able to demonstrate that it has complied with the principles governing the processing of personal data. It therefore makes sense for companies to give this matter careful consideration and to check whether personal data is adequately protected, both organisationally and technically, against access by unauthorised third parties. These checks must be documented.
Rights and obligations
As a business owner, you are obliged to provide information when enquiries are made. You should also check and document whether you are required to maintain a record of processing activities relating to the processing of personal data. Whilst this obligation does not apply to companies with fewer than 250 employees, there are exceptions to this rule. The EU General Data Protection Regulation (GDPR) will also bring further changes, all of which are set out in the data protection taxonomy. In any case, as the Regulation comes into force, it will become increasingly important to ensure compliance with data protection laws. The fines will be significantly increased.
As a business owner, you must be able to demonstrate that your data processing complies with data protection regulations. The extensive documentation requirements are designed to ensure this. The records serve as evidence for the data protection supervisory authority, in the event of judicial review proceedings, and for the purpose of providing information to data subjects at a later date. Opti.Tax Data Protection Documentation helps you to comply with the documentation requirements of the EU General Data Protection Regulation.






