In short: From 25 May 2018, the EU General Data Protection Regulation (GDPR) applies. It strengthens individuals’ rights, requires organizations to demonstrate accountability, and introduces significant fines for non-compliance.
What are the key principles?
- Lawfulness, fairness and transparency
- Purpose limitation and data minimization
- Accuracy and storage limitation
- Integrity, confidentiality and accountability
What must organizations do?
- Maintain records of processing activities
- Establish a lawful basis for processing
- Respect data subject rights
- Report certain breaches within 72 hours
- Carry out data protection impact assessments where required
How do management systems help?
ISO/IEC 27001 and ISO/IEC 27701 provide structured frameworks to manage information security and privacy risks.
Key takeaways
- GDPR applies from 25 May 2018.
- Accountability must be demonstrated, not assumed.
- Management systems support compliance.
Frequently asked questions
Does GDPR apply outside the EU?
Yes, to organizations that offer goods or services to, or monitor, people in the EU.
What is a data breach notification?
Reporting certain personal data breaches to the supervisory authority, generally within 72 hours.
Is ISO/IEC 27001 enough for GDPR?
It helps with security, but GDPR also covers lawful processing and individuals’ rights.