Remove 12
article thumbnail

List of mandatory documents required by the GDPR

IT Governance

The documentation of processing activities is a new legal requirement under the EU GDPR (General Data Protection Regulation). Documenting your processing activities can also support good data governance, and help you to demonstrate your compliance with other aspects of the GDPR. Privacy Notice (Articles 12, 13, and 14).

GDPR 74
article thumbnail

EDPB publishes guidance on calculating GDPR fines

Data Protection Report

On 12 May 2022 EDPB adopted Guidelines on the calculation of administrative fines (the Guidelines ). The Guidelines supplement the Article 29 Working Party’s Guidelines on the application and setting of administrative fines ( WP253 ) adopted in October 2017 and recommends that the two are read together. 2) Seriousness of infringement.

GDPR 52
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

How the PCI DSS can help you meet the requirements of the GDPR

IT Governance

With less than 6 months until the General Data Protection Regulation ( GDPR ) is enforced, organisations across Europe must consider how the far-reaching changes introduced by the Regulation will affect how they handle and protect personal data. People come to me and say, ‘How do I achieve GDPR compliance?’…

GDPR 78
article thumbnail

Article 29 Working Party Published Guidelines on Transparency under the GDPR

Hunton Privacy

On December 12, 2017, the Article 29 Working Party (“Working Party”) published its guidelines on transparency under Regulation 2016/679 (the “Guidelines”). The Guidelines aim to provide practical guidance and clarification on the transparency obligations introduced by the EU General Data Protection Regulation (“GDPR”).

GDPR 62
article thumbnail

EU Council Agrees on Proposed ePrivacy Regulation

Data Matters

The first draft of the ePrivacy Regulation was approved by the European Commission in 2017 and has since been under discussion in the Council. The GDPR also supplements the ePrivacy rules on the protection of personal data. Organizations subject to the ePrivacy Regulation on a purely extraterritorial basis (i.e.,

GDPR 68
article thumbnail

UK data protection after Brexit – UK government Statement of Intent contains few surprises

Data Protection Report

On the 7 th August 2017, the UK’s Government Department for Digital, Culture, Media and Sport issued a Statement of Intent (the Statement ) outlining its planned reforms of the UK’s data protection laws which are to be implemented by the Data Protection Bill (the Bill ). The Statement summarises some of the notable derogations from the GDPR.

article thumbnail

FRANCE: ONE MORE STEP TO ENSURE CONSISTENCY OF THE NEW FRENCH DATA PROTECTION LAW

DLA Piper Privacy Matters

On 12 December 2018, the French Government issued an ordinance [1] finalizing, at the legislative level [2] , the alignment of the French Data Protection Law (“FDPL”) with the General Data Protection Regulation [3] (“GDPR”) and the Directive 2016/680 [4]. Following-up the adoption of the GDPR, the French Law No.

GDPR 49