Regulation 2016
GDPR (Regulation (EU) 2016/679)
Datenschutz-Grundverordnung (DSGVO)
Issued by Federal Commissioner for Data Protection and Freedom of Information
Effective: 27 Apr 2016
Last amended: 25 May 2018
Plain-English summary
The General Data Protection Regulation (GDPR) is the most robust privacy law globally since it provides individuals with total control of their personal information while ensuring there is a uniform digital privacy rulebook for modern companies. The regulation came into force in 2016 and began its implementation in 2018, replacing the outmoded 1995 Data Protection Directive and changing the global privacy landscape through the inclusion of extraterritoriality. This implies that the regulation is applicable strictly to any entity worldwide, processing, storing, or handling the personal information of EU citizens without considering the company’s physical location. The GDPR is enforced at the national level by independent data protection authorities, including the BfDI and state data protection bodies in Germany or CNIL in France. It ensures that data privacy is a basic human right with hefty administrative fines of up to €20 million or 4% of a company's global annual turnover being applied to entities failing to comply with the regulation.
Who it applies to
Banking · Insurance · Telecom & Tech · Healthcare & Pharma
Topics
Data Protection & Privacy
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| Lawful basis, notice and data subject rights | Ongoing | BfDI | source | |
Under this regulatory regime, it is required that there should be the perpetual establishment of a proper legal basis under which the statutory requirement shall be fulfilled under Article 6(1)(c) of the GDPR, and there should also be continuous provision of transparent privacy notices to the clients about monitoring and storage of data. This process of privacy data management is not something sporadic but is performed concurrently with customer monitoring. In addition, it includes specific time-bound benchmarks for performance, and companies are required to implement standard data processing policies and respond to data subject access requests, as well as investigations carried out by data protection authorities, within 1 month deadline (which can be extended to 3 months in cases of complicated architecture), except when limited under AML exemptions to avoid tipping off suspects. |
||||
| Personal data breach notification | Deadline 72 hours | BfDI | source | |
In accordance with GDPR and the BDSG, the obligation to report a personal data breach in Germany is an event-based one, which is characterized by a very strict and divided time value of 72 hours. The above-described legal requirement entails the following: when a company or a financial institution learns about any incident leading to the unauthorized access to, the altering, and the loss of the personal data, the reporting obligation arises. At that, the reporting entity should contact the respective regional State Data Protection Authority (Landesdatenschutzbehörde) within no more than 72 hours with the information about the breach, the type of data that was breached, and the measures taken in order to prevent further negative consequences. In case the reported incident poses a threat to individual rights and can lead to identity theft and financial fraud of the clients, the affected individuals have to be informed without any delays. |
||||
| No obligations match these filters. | ||||
Latest news
No related news yet. We publish updates as regulators act.