- Introduction to GDPR:
- The General Data Protection Regulation (GDPR) came into effect on May 25, 2018 across Europe, aiming to enhance citizens’ control over their personal data and create consistent data protection rules across the EU.
- Key Principles:
- Transparency: Individuals can request copies of their personal data and receive clear explanations regarding its processing, purpose, and retention period.
- Privacy Notices: Organizations must ensure privacy notices are given when collecting personal data and clearly communicate the purpose and retention of the data.
- Changes Under GDPR:
- Greater Rights for Individuals:
- Right to Erasure/Rectification: The right to request corrections or deletion of personal data.
- Data Portability: The ability for individuals to request their data in a format that can be easily transferred.
- Stricter Consent: Organizations must meet higher standards for obtaining consent before processing personal data.
- Stronger Judicial Remedies: Individuals can claim against data processors for violations of their rights.
- Greater Rights for Individuals:
- The Rights of Data Subjects:
- Right to Be Informed: Individuals should know how and why their data is used.
- Right of Access: Individuals can request access to their personal data.
- Right to Rectification: Personal data can be corrected if inaccurate.
- Right to Erasure: Data can be deleted under certain conditions.
- Right to Restrict Processing: Data processing can be limited.
- Right to Data Portability: Individuals can move their data to other services.