The GDPR significantly increases potential penalties for non-compliance, with fines up to 20 Million Euros or 4% of annual global turnover, a substantial increase from the previous 3 Million Euros maximum under the 1978 French law.
02
Data Protection Officers (DPOs) are not held responsible for GDPR non-compliance; the data controller or processor bears this responsibility. DPOs cannot be penalized for performing their duties due to their independence, though they can be dismissed for reasons unrelated to their DPO role.
03
Consent under GDPR must be a free, specific, informed, and unambiguous indication of the data subject's wishes, given by a statement or clear affirmative action, and the data controller must be able to prove valid consent.
04
Processing 'sensitive data' (special categories of personal data) is generally prohibited unless specific exceptions apply, such as explicit consent from the data subject for defined purposes.
05
Data controllers must facilitate the exercise of data subjects' rights (access, rectification, erasure, etc.), responding within one month (or two for complex cases) and providing reasons if a request is denied, with these services generally being free unless requests are unfounded or repetitive.
06
Data Protection Impact Assessments (DPIAs) are mandatory for processing operations likely to result in a high risk to individuals' rights and freedoms, aiming to describe, assess necessity and proportionality, and manage risks.
07
When transferring data outside the EU, data controllers must anticipate these operations and implement processes to document the safeguards provided, potentially requiring authorization from a control authority or explicit consent from the data subject after informing them of risks.
Insights
01
The GDPR significantly increases potential penalties for non-compliance, with fines up to 20 Million Euros or 4% of annual global turnover, a substantial increase from the previous 3 Million Euros maximum under the 1978 French law.
02
Data Protection Officers (DPOs) are not held responsible for GDPR non-compliance; the data controller or processor bears this responsibility. DPOs cannot be penalized for performing their duties due to their independence, though they can be dismissed for reasons unrelated to their DPO role.
03
Consent under GDPR must be a free, specific, informed, and unambiguous indication of the data subject's wishes, given by a statement or clear affirmative action, and the data controller must be able to prove valid consent.
04
Processing 'sensitive data' (special categories of personal data) is generally prohibited unless specific exceptions apply, such as explicit consent from the data subject for defined purposes.
05
Data controllers must facilitate the exercise of data subjects' rights (access, rectification, erasure, etc.), responding within one month (or two for complex cases) and providing reasons if a request is denied, with these services generally being free unless requests are unfounded or repetitive.
06
Data Protection Impact Assessments (DPIAs) are mandatory for processing operations likely to result in a high risk to individuals' rights and freedoms, aiming to describe, assess necessity and proportionality, and manage risks.
07
When transferring data outside the EU, data controllers must anticipate these operations and implement processes to document the safeguards provided, potentially requiring authorization from a control authority or explicit consent from the data subject after informing them of risks.