GDPR: why it concerns all of us
The General Data Protection Regulation (GDPR) has been in effect since May 2018. It has profoundly transformed how organizations handle the personal data of European citizens.
What is the GDPR?
It is a European regulation aimed at protecting the personal data of EU citizens. It applies to any organization (public or private) that processes the data of EU citizens, wherever it is in the world.
Citizens' rights
Right to information
Any organization collecting your data must clearly inform you: - What data is collected - Why it is collected - How long it is kept - Who it is shared with
Right of access
You can request access to all personal data an organization holds on you at any time.
Right to rectification
If your data is inaccurate or incomplete, you can demand correction.
Right to erasure ("right to be forgotten")
You can request the deletion of your personal data, under certain conditions.
Right to data portability
You can retrieve your data in a standardized format and transfer it to another service.
Right to object
You can object to the processing of your data for certain purposes (notably advertising profiling).
What this changes in practice
For organizations
- Explicit consent: no more pre-checked boxes — consent must be freely given and informed
- Privacy by design: data protection must be integrated from the product design stage
- DPO: appointment of a Data Protection Officer (mandatory for certain organizations)
- Processing register: documentation of all data processing activities
- Breach notification: must notify the CNIL within 72 hours of a data breach
For citizens
- More control over your personal data
- The right to know who has your data and what they do with it
- The right to have your data deleted
- The right to lodge a complaint with the CNIL