GDPR — General Data Protection Regulation

What is GDPR

In late May 2018, the new EU General Data Protection Regulation (GDPR) will come into effect. It defines the purposes, processes, and technological requirements for processing personal data (both for clients and employees) and is binding for all organizations that process the data of EU citizens.

The General Data Protection Regulation is being implemented to harmonize the rules governing the protection of personal data across all EU member states and to increase individual control over personal data.

Compared to the current Personal Data Protection Law in force in Latvia, the regulation focuses more on best practice principles for personal data processing and imposes stricter obligations on all parties involved in the data processing chain (controllers, processors, and data protection officers).

The most significant improvements for individuals include the right to be forgotten and the right to be fully informed about what a data processor intends to do and/or is doing with their personal data (the purpose of processing, the method of collection, the duration of storage, and the data protection measures employed).

How GDPR affects your company

Every organization (company, NGO, or government institution) will be required to demonstrate compliance with the regulation's requirements, not only by presenting formally documented procedures but also by taking practical actions, such as maintaining records of data processing activities, implementing data pseudonymization, and reporting data breaches to the supervisory authority and the data subject.

The regulation establishes the principles of data minimization and privacy by default. This means that before developing products and services that require the use of personal data, companies must precisely evaluate and define the purposes and methods of data collection and processing.

How Jumis Pro implements GDPR requirements

Jumis Pro takes the protection of our clients' data, as mandated by the General Data Protection Regulation, very seriously. Consequently, we established an action plan in 2017 to ensure compliance with GDPR requirements. We have already completed numerous initiatives and will continue to prioritize the protection of our clients' data following the regulation's entry into force on May 25, 2018.

Progress to date:

  • We have conducted a detailed internal audit of our data and operational procedures;
  • As a result of the audit, we have mapped our data, organized data access rights, improved data protection, and established retention periods;
  • By engaging security experts, we have conducted an external audit of our information system security;
  • We have made the necessary changes to legal documents, as well as to our products and services;
  • We have updated our agreements with our partners and cloud service providers (Telia Latvia, Microsoft Azure, and Amazon Web Services);
  • We have improved our services privacy policies terms and conditions in accordance with GDPR;
  • We have created an informative page for our clients regarding GDPR compliance;
  • We have trained our employees on how to work in accordance with the new GDPR requirements

Our advice for your company

Three key areas where a company must ensure compliance:

  • Legal — contracts with clients and suppliers;
  • Procedures — workflows and data processing;
  • IT — systems, tools, auditing, and data protection

It is also important to understand that the entry into force of the regulation is only the beginning, as compliance must be maintained continuously across all IT and business projects moving forward.

Below, we have compiled some practical tips to help you implement a personal data storage and processing system that complies with GDPR requirements.

Start by building your knowledge—read the regulation and attend training courses or seminars.

Assess your current situation by conducting an internal audit and reviewing your products and services:

  • Identify which of your products or services collect and process personal data;
  • Identify what personal data the company holds, why it is held, and where it is located;
  • Verify that you have a legal basis for processing personal data;
  • Ensure that you can fulfill your obligations to your clients as required by the GDPR (e.g., rights of access and erasure);
  • Review contracts with clients and suppliers.

It is essential to understand your company's internal processes, how personal data is processed, and who has access to it. Experience shows that audits often reveal previously unidentified ways in which a company processes various types of data.

Assign roles and responsibilities:

  • Designate an employee within your organization to be responsible for data protection and privacy;
  • Consider whether you require a data protection officer;
  • Provide training for employees on personal data protection.

Ensure security:

  • Ensure that systems used to collect, process, and store personal data are secure;
  • Consider using cloud solutions, such as Jumis Pro, to ensure that all company data is stored in a certified data center.

Prepare documentation — develop or improve existing data processing policies.

View the GDPR as an opportunity to improve your company's competitiveness:

  • By implementing the GDPR, you review existing data collection, storage, and update processes within the company to make them more efficient and secure;
  • Review how communication with existing and potential clients is currently organized and demonstrate that you are genuinely committed to the security of their data and the quality of the services provided.

Additional resources on the GDPR

General Data Protection Regulation (EU) 2016/679 — https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679

Data State Inspectorate information materials — http://www.dvi.gov.lv/lv/datu-aizsardziba/organizacijam/ieteikumi/

Article 29 Working Party — an independent European advisory body on data protection and privacy — http://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/index_en.htm