Leave GDPR to us!
What is the new GDPR Regulation
On April 27th, 2016 the new EU Regulation “On the protection of natural persons with regard to the processing of personal data and on the free movement of such data” ccomes into effect. The regulation is mandatory for all companies, organizations and professionals that operate in the European Union. The regulation takes effect on May 25th, 2018.
What should Companies do?
- Adhere to the basic principles of personal data protection, collect, process and transmit only the data that are absolutely necessary and only for legally justifiable reasons
- Store personal data for the least possible time
- Obtain the clear and undisputed consent of the data subjects (private individuals) and let them be advised of their rights under the regulation
- Safeguard, secure and harden their information and telecommunication systems in order to deter any unauthorized access to them, hence…
- Provide complete security of personal data in their entire life-cycle and protect them from data leaks, theft, loss, unauthorized access by third parties or even by unauthorized individuals inside the organization
- Maintain full records of all incidents of compromise and inform the proper personal data authorities within 72 hours of any such breach. Also inform all affected individuals of any such breach
- Prove that they fulfill all requirements posed by the regulation
Does the Regulation pertain to me?
If you are a Company or a Professional that collects, processes and stores personal data or a Public Organization YES it does.
Examples :
- You own and operate a retail store and ask for and keep client data like : name, address, telephone number etc.
- You own and operate an e-shop
- You collect and process electronic data as a service to other entities and organizations
- You process data for advertising purposes
- You have employees
- You are a Lawyer, Doctor, Engineer and keep electronic client records
- All Public Sector Organizations
- etc
Is it urgent?
The effective date of the regulation, May 25th 2018, has passed, hence the imperativeness of the issue has increased considerably. Fortunately local authorities have granted an unofficial “grace” period. Nevertheless, if you do not address the issue on time, you may have to act on it hastily, get a non-optimal solution at a much higher cost.
What are the requirements?
This is a multifaceted issue. Simply speaking conformity with the regulation has a series of ramifications. These may be :
- Computational
- Organizational
- Managerial
- Legal
- Corporate Image
What must I do?
You must seek a specialized, trusted partner-consultant who will help you and guide you through all of the above issues in a spherical approach and not with a segment thereof.
Many companies and individuals offer to assist me. Why CYBERTECH?
Everybody claim that they know the subject and are in a position to help, but in principle they may want to promote specific products or services without bothering to consider whether these are suitable to your particular situation and needs; nor do they care to attack the problem in its entirety!
We at CYBERTECH do exactly the opposite. We study each and every case and suggest a comprehensive solution tailor made to your needs. Being a specialized consulting corporation we do not try to sell a piece of hardware, or software, or a specific process. Our consultants cooperate with our clients in a multitude of areas and offer a complete solution.
What kind of services would I need?
This question can only be answered after we study your specific situation. Nevertheless the services that are needed in principle fall into 6 categories :
- Analysis / assessment of the infrastructure and of the data stores
- Analysis / assessment of existing data handling procedures
- Comprehensive list of improvements resulting from the above
- Implementation of the proposed improvements (if needed)
- Regular monitoring – Data Protection Officer (DPO)
- Reporting to the proper authority in case of a mishap
What is the cost of all these?
Anybody who can give an immediate answer to this question is not doing his job properly. Our plan of action is to perform the assessment steps described above. Based on those we can estimate the amount of work and the procedures that need to be done and the corresponding cost.
Talk to us today about your company and your needs.
More about the Regulation
Legal Aspects of the Data Protection Officer – DPO