SlideShare a Scribd company logo
1 of 4
Download to read offline
Why Is GDPR Essential
For Small Businesses?
© VISTA InfoSec ®
Having said that, here is a look at GDPR’s most important principles and their implica ons on your small-
scale business. This informa on will give you clarity on whether your business is exempted or not and its
inferences.
With the EU’s General Data Protec on Regula on now in place, UK is witnessing stringent regula ons
with tougher fines implemented, across all industries. GDPR is a compliance regula on that came into
effect on the 25 May 2018. Therea er within 6-8months down the meline, only 30% of the EU based
business became GDPR compliant. Despite being aware of the law and its implica ons, majority of the
business s ll remains to be non-compliant. While most might think GDPR doesn’t apply to them if they
are a small firm or a US-based firm, this isn’t necessarily the case. If people located in the EU can access
yourwebsite,GDPRappliestoyou,irrespec veofyourcompanysizeorloca on.
What is GDPR?
It is important for business owners to bear in mind that, GDPR applies to any business established in the
EU and may also be applicable to companies based outside of the EU who process personal data of EU
ci zensinanyway.
Ÿ Unifyregula onthatstandsacrosstheEuropeanUnion.
Ÿ Protectanindividual’sprivacy.
The European General Data Protec on Regula on (GDPR) is a compliance regula on and a data
protec onlawbuiltto–
Ÿ Givetheci zensandresidentsmorecontrolovertheirpersonaldata.
Ÿ Preventmisuseofpersonaldata.
Understanding GDPR Compliance
Ÿ Businesses who are involved in ‘regular or systema c’ processing of personal data, or involved in
processinglargevolumesof‘specialcategorydata’mustabidetotheGDPRCompliance.
Ÿ GDPR Compliance is applicable to any business that processes personal data of EU ci zens, including
those companies having less than 250 employees and those companies who are based outside of the
EU,whoprocesspersonaldataofEUci zensinanyway.
Ÿ BusinessesorcompanyownerswhofallunderthiscategoryareexpectedtoappointaDataProtec on
Officer (DPO) who shall ensure the company complies to the rules and regula ons as stated under
GDPR.
© VISTA InfoSec ®
Ÿ In case of a breach of confiden al data, the incident must be reported to the regulator (Informa on
Commissioner’sOffice)within24hoursoratleastwithin72hourswithareportincludinginforma on
regardingwhatledtothebreach,howitisbeingcontainedandtheirnextplanofac on
Ÿ As per the GDPR regula on, an individual has all the right to know how businesses use their data. The
individual also holds the ‘right to be forgo en’ if they no longer want the company to process their
personaldataandthecompanywillinthisregardhavenolegalgroundstokeepthedata.
Ÿ Failure to comply with the GDPR regula on will result in levying of harsh penal es. The penal es
leviedcouldbeupto€20million,orfourpercentofannualturnover,whicheverishigher
What constitutes a Special Category Data
under Article 9?
“SpecialCategoryData”coveredintheAr cle9ofGDPRincludesanyPersonalDatarela ngto-
As per the GDPR regula on “Special Category Data” is a personal data that is more sensi ve and could
put an individual at risk of unlawful discrimina on if misused or disclosed without authoriza on. When
processing the Special Category Data, businesses require to abide to the explicit legal rules in terms of
obtaining explicit consent from the subject. Explicit consent may be through a signed form with a higher
standardofconsent.
Ÿ Race
Ÿ Ethnicorigin
Ÿ Religion,
Ÿ Tradeunionmembership,
Ÿ Gene cs,
Ÿ Biometrics(whereusedforIDpurposes),
Ÿ Health,
Ÿ Sexualorienta on.
Ÿ Poli calaffilia on,
Data rela ng to criminal offense also comes under the Special Category Data, wherein businesses can
only keep a “comprehensive register of criminal convic ons” if they have legi mate grounds for the
sameandhaveGDPRcompliantprotec onsinplace.
Penalties for Non-Compliance for GDPR
Ÿ It has been clearly stated that non-compliance with GDPR will cost businesses a fine of up to €20
million or 4% of their global turnover, whichever is higher. However, these fines will only be applied in
extreme circumstances. Although EU authori es will be able to impose fines on a discre onary basis,
they can use other “correc ve powers and sanc ons” to encourage businesses to enhance GDPR
compliance.
Ÿ The Other “correc ve powers and sanc ons” include issuing a warning, imposing a ban on data
processing, ordering the rec fica on or dele on of data, and suspending data transfers to non-EU
countries.
Is GDPR regulation applicable to small business
and sole traders
© VISTA InfoSec ®
Ÿ Any non-compliant ac on or lack of ac on can result in a penalty. For this very reason, small
businesses need to be aware of the GDPR requirements, especially focusing on the “Special Category
Data”coveredinAr cle9ofGDPR.
Ÿ Stringent penal es will be imposed in case the company fails to comply with data collec on rules for
children, processing or sharing data without obtaining consent, and for maintaining data longer than
itslegalpurpose.
Ÿ Doesnotaffectanindividuals’rightandfreedom.
Ÿ DatadoesnotfallundertheGDPRAr cle9.
To set the record straight and clear, GDPR applies to any or every business that deals with collec on, or
processingofpersonaldataofpeoplefromtheEU.Thisholdstruewhetheryouareaone-manopera on
business or a business having offices across con nents. Having said that, one may not have to keep a
wri en record of their data processing ac vi es if they have less than 250 employees, and unless their
dataprocessingac vi es
Ÿ ThepersonaldatadoesnotfallundertheAr cle10rela ngtocriminaloffencesandconvic ons.
Ÿ Thepersonaldataprocessingac vi esareconductedonaregularbasis.
But by all means it is good to keep the records clear, even if one thinks they are exempt. A erall, it is
be ertobesafethansorry.
Implications of GDPR on small businesses
Ÿ It is important to note that if a company falls under one of the exemp ons, but deals with a larger
company that conducts large-scale processing, then in that case, you may be subject to the stringent
GDPR’sRegula on.
Ÿ A er all, it is much easier to follow the GDPR Regula on, than spend me figuring out how you can
avoidComplyingtothestandards.
Ÿ That apart, you would s ll want to ensure that your business is Compliant to the GDPR principles, for
yourbusinessfallsundertheGDPRCompliancecategoryforregularprocessingofpersonaldata.
Ÿ Being a small business does not mean you are exempted from the GDPR Compliance. However, such
businesses shall be recognized as businesses having fewer resources and pose less risk to data
protec on. In that case the business may see some leniency by the ICO in rela on to penalty in non-
compliance.
Our expert view on GDPR Regulation on small
businesses
It is very important for businesses to understand the spirit of GDPR. The legisla on came into existence,
having seen the way how personal data were misused. Most o en companies treated personal data as a
resource they could use without due regards to the rights of individual. Further, keeping aside the law,
responsible data handling is a good business prac ces. As a business owner, you are responsible for your
customersprivacyandanykindofdatabreachcouldpossiblycrushyourcustomerstrustonyou.
Summary
Do write to us your feedback, comments and queries or, if you have any requirements:
info@vistainfosec.com
You can reach us on:
USA
+1-415-513 5261
INDIA
+91 73045 57744
SINGAPORE
+65-3129-0397
© VISTA InfoSec ®
As an experienced professional of the industry, I believe GDPR shouldn’t be seen as a burden, but rather
be seen as adding value to your business. By proving your poten al and exis ng customers an assurance
that your organisa on is compliant with new law, you could win them into bringing in more business.
A er all, no one likes their data being lost, stolen, misused, or shared without proper consent. By being
compliant and doing everything you can to protect your customers personal details, can help build a
sense of trust which is also good for your business. I see it as a value addi on to your business wherein
the company is making an effort to protect client’s data and respects personal data, rather than le ng it
beusedwithoutanyconsent.
There are no two ways about it when it comes to the GDPR compliance for small businesses. While it
affectseverycompanyintheworld,beitsmall,mediumorlarge-scalecompanies,theGDPRregula onis
definitely seen as a posi ve step towards data protec on. GDPR compliance has a posi ve impact on
small businesses. Businesses have now taken their customers’ privacy more seriously. With this in place,
businesses have seen more loyalty and increased trust from consumers. So, clearly, GDPR is now seen
more than just as a bunch of rules to be followed to avoid penal es. By taking necessary measures to
achieve GDPR Compliance, one can definitely posi on their business as one that truly cares for their
customersandtheirprivatedata.
facebook.com/vistainfosec/ in.linkedin.com/company/vistainfosec twitter.com/VISTAINFOSEC

More Related Content

What's hot

The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To ConsiderSymantec
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018Human Capital Department
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Dryden Geary
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
How will GDPR affect small businesses?
How will GDPR affect small businesses?How will GDPR affect small businesses?
How will GDPR affect small businesses?AllBusinessTemplates
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteSilverTech
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisAngad Dayal
 
Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020TheCEOViews
 
GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?Samuel Pouyt
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Getting the Deal Through: Data Protection and Privacy, Ireland 2018
Getting the Deal Through: Data Protection and Privacy, Ireland 2018 Getting the Deal Through: Data Protection and Privacy, Ireland 2018
Getting the Deal Through: Data Protection and Privacy, Ireland 2018 Hazel Murray
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection RegulationPete S
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...Symantec
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018Shane Gray
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 

What's hot (20)

The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
Data Security Whitepaper
Data Security WhitepaperData Security Whitepaper
Data Security Whitepaper
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
How will GDPR affect small businesses?
How will GDPR affect small businesses?How will GDPR affect small businesses?
How will GDPR affect small businesses?
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with Varonis
 
Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020
 
GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
Getting the Deal Through: Data Protection and Privacy, Ireland 2018
Getting the Deal Through: Data Protection and Privacy, Ireland 2018 Getting the Deal Through: Data Protection and Privacy, Ireland 2018
Getting the Deal Through: Data Protection and Privacy, Ireland 2018
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 

Similar to Why is gdpr essential for small businesses with links

GDPR Explained - A Quick Guide for US Businesses
GDPR Explained - A Quick Guide for US BusinessesGDPR Explained - A Quick Guide for US Businesses
GDPR Explained - A Quick Guide for US BusinessesJessica Clark
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
GDPR Regulations in Malta
GDPR Regulations in MaltaGDPR Regulations in Malta
GDPR Regulations in MaltaBridgeWest.eu
 
Will GDPR Kill Outbound Marketing?
Will GDPR Kill Outbound Marketing?Will GDPR Kill Outbound Marketing?
Will GDPR Kill Outbound Marketing?MarketJoy Inc.
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands legalandgeneral
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance Tom Haynes
 
"If we're leaving the EU, does GDPR even matter?" And other FAQs
"If we're leaving the EU, does GDPR even matter?" And other FAQs"If we're leaving the EU, does GDPR even matter?" And other FAQs
"If we're leaving the EU, does GDPR even matter?" And other FAQsTech Data
 
GDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality OwnersGDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality OwnersBoostly
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. dan hyde
 
GDPR: Keep Your Website Out of Legal Trouble
GDPR: Keep Your Website Out of Legal TroubleGDPR: Keep Your Website Out of Legal Trouble
GDPR: Keep Your Website Out of Legal TroubleMickey Mellen
 
What is data protection and why it is important for business
What is data protection and why it is important for businessWhat is data protection and why it is important for business
What is data protection and why it is important for businessSameerShaik43
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperServersys
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoDaniel Smith
 
General Data Protection Regulations (GDPR) & Impact on Your Business
General Data Protection Regulations (GDPR) & Impact on Your Business General Data Protection Regulations (GDPR) & Impact on Your Business
General Data Protection Regulations (GDPR) & Impact on Your Business EquiCorp Associates
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolutionDan Brookman
 
GDPR - heads up!
GDPR - heads up!GDPR - heads up!
GDPR - heads up!Joe Mbaya
 

Similar to Why is gdpr essential for small businesses with links (20)

GDPR Explained - A Quick Guide for US Businesses
GDPR Explained - A Quick Guide for US BusinessesGDPR Explained - A Quick Guide for US Businesses
GDPR Explained - A Quick Guide for US Businesses
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
GDPR Regulations in Malta
GDPR Regulations in MaltaGDPR Regulations in Malta
GDPR Regulations in Malta
 
Will GDPR Kill Outbound Marketing?
Will GDPR Kill Outbound Marketing?Will GDPR Kill Outbound Marketing?
Will GDPR Kill Outbound Marketing?
 
The Basics of GDPR
The Basics of GDPR The Basics of GDPR
The Basics of GDPR
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 
"If we're leaving the EU, does GDPR even matter?" And other FAQs
"If we're leaving the EU, does GDPR even matter?" And other FAQs"If we're leaving the EU, does GDPR even matter?" And other FAQs
"If we're leaving the EU, does GDPR even matter?" And other FAQs
 
GDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality OwnersGDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality Owners
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
GDPR: Keep Your Website Out of Legal Trouble
GDPR: Keep Your Website Out of Legal TroubleGDPR: Keep Your Website Out of Legal Trouble
GDPR: Keep Your Website Out of Legal Trouble
 
What is data protection and why it is important for business
What is data protection and why it is important for businessWhat is data protection and why it is important for business
What is data protection and why it is important for business
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist Whitepaper
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
 
General Data Protection Regulations (GDPR) & Impact on Your Business
General Data Protection Regulations (GDPR) & Impact on Your Business General Data Protection Regulations (GDPR) & Impact on Your Business
General Data Protection Regulations (GDPR) & Impact on Your Business
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolution
 
GDPR - heads up!
GDPR - heads up!GDPR - heads up!
GDPR - heads up!
 

More from VISTA InfoSec

Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...VISTA InfoSec
 
CCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdfCCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdfVISTA InfoSec
 
HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022VISTA InfoSec
 
SOC2 Advisory and Attestation
SOC2 Advisory and AttestationSOC2 Advisory and Attestation
SOC2 Advisory and AttestationVISTA InfoSec
 
What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?VISTA InfoSec
 
Webinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableWebinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableVISTA InfoSec
 
Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates VISTA InfoSec
 
Webinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementWebinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementVISTA InfoSec
 
Reducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesReducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesVISTA InfoSec
 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy ActVISTA InfoSec
 
Guide on ISO 27001 Controls
Guide on ISO 27001 ControlsGuide on ISO 27001 Controls
Guide on ISO 27001 ControlsVISTA InfoSec
 
Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?VISTA InfoSec
 
Why should I do SOC2?
Why should I do SOC2?Why should I do SOC2?
Why should I do SOC2?VISTA InfoSec
 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow MappingVISTA InfoSec
 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?VISTA InfoSec
 
Which SOC Report Do I need?
Which SOC Report Do I need?Which SOC Report Do I need?
Which SOC Report Do I need?VISTA InfoSec
 
Key additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAKey additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAVISTA InfoSec
 
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery ProcessVISTA InfoSec
 
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! VISTA InfoSec
 
Pci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedPci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedVISTA InfoSec
 

More from VISTA InfoSec (20)

Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
 
CCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdfCCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdf
 
HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022
 
SOC2 Advisory and Attestation
SOC2 Advisory and AttestationSOC2 Advisory and Attestation
SOC2 Advisory and Attestation
 
What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?
 
Webinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableWebinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicable
 
Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates
 
Webinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementWebinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key management
 
Reducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesReducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniques
 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy Act
 
Guide on ISO 27001 Controls
Guide on ISO 27001 ControlsGuide on ISO 27001 Controls
Guide on ISO 27001 Controls
 
Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?
 
Why should I do SOC2?
Why should I do SOC2?Why should I do SOC2?
Why should I do SOC2?
 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow Mapping
 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?
 
Which SOC Report Do I need?
Which SOC Report Do I need?Which SOC Report Do I need?
Which SOC Report Do I need?
 
Key additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAKey additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRA
 
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
 
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
 
Pci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedPci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-converted
 

Recently uploaded

Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCRsoniya singh
 
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckPitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckHajeJanKamps
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewasmakika9823
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...lizamodels9
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedKaiNexus
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 

Recently uploaded (20)

Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
 
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckPitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 

Why is gdpr essential for small businesses with links

  • 1. Why Is GDPR Essential For Small Businesses? © VISTA InfoSec ® Having said that, here is a look at GDPR’s most important principles and their implica ons on your small- scale business. This informa on will give you clarity on whether your business is exempted or not and its inferences. With the EU’s General Data Protec on Regula on now in place, UK is witnessing stringent regula ons with tougher fines implemented, across all industries. GDPR is a compliance regula on that came into effect on the 25 May 2018. Therea er within 6-8months down the meline, only 30% of the EU based business became GDPR compliant. Despite being aware of the law and its implica ons, majority of the business s ll remains to be non-compliant. While most might think GDPR doesn’t apply to them if they are a small firm or a US-based firm, this isn’t necessarily the case. If people located in the EU can access yourwebsite,GDPRappliestoyou,irrespec veofyourcompanysizeorloca on. What is GDPR? It is important for business owners to bear in mind that, GDPR applies to any business established in the EU and may also be applicable to companies based outside of the EU who process personal data of EU ci zensinanyway. Ÿ Unifyregula onthatstandsacrosstheEuropeanUnion. Ÿ Protectanindividual’sprivacy. The European General Data Protec on Regula on (GDPR) is a compliance regula on and a data protec onlawbuiltto– Ÿ Givetheci zensandresidentsmorecontrolovertheirpersonaldata. Ÿ Preventmisuseofpersonaldata. Understanding GDPR Compliance Ÿ Businesses who are involved in ‘regular or systema c’ processing of personal data, or involved in processinglargevolumesof‘specialcategorydata’mustabidetotheGDPRCompliance. Ÿ GDPR Compliance is applicable to any business that processes personal data of EU ci zens, including those companies having less than 250 employees and those companies who are based outside of the EU,whoprocesspersonaldataofEUci zensinanyway. Ÿ BusinessesorcompanyownerswhofallunderthiscategoryareexpectedtoappointaDataProtec on Officer (DPO) who shall ensure the company complies to the rules and regula ons as stated under GDPR.
  • 2. © VISTA InfoSec ® Ÿ In case of a breach of confiden al data, the incident must be reported to the regulator (Informa on Commissioner’sOffice)within24hoursoratleastwithin72hourswithareportincludinginforma on regardingwhatledtothebreach,howitisbeingcontainedandtheirnextplanofac on Ÿ As per the GDPR regula on, an individual has all the right to know how businesses use their data. The individual also holds the ‘right to be forgo en’ if they no longer want the company to process their personaldataandthecompanywillinthisregardhavenolegalgroundstokeepthedata. Ÿ Failure to comply with the GDPR regula on will result in levying of harsh penal es. The penal es leviedcouldbeupto€20million,orfourpercentofannualturnover,whicheverishigher What constitutes a Special Category Data under Article 9? “SpecialCategoryData”coveredintheAr cle9ofGDPRincludesanyPersonalDatarela ngto- As per the GDPR regula on “Special Category Data” is a personal data that is more sensi ve and could put an individual at risk of unlawful discrimina on if misused or disclosed without authoriza on. When processing the Special Category Data, businesses require to abide to the explicit legal rules in terms of obtaining explicit consent from the subject. Explicit consent may be through a signed form with a higher standardofconsent. Ÿ Race Ÿ Ethnicorigin Ÿ Religion, Ÿ Tradeunionmembership, Ÿ Gene cs, Ÿ Biometrics(whereusedforIDpurposes), Ÿ Health, Ÿ Sexualorienta on. Ÿ Poli calaffilia on, Data rela ng to criminal offense also comes under the Special Category Data, wherein businesses can only keep a “comprehensive register of criminal convic ons” if they have legi mate grounds for the sameandhaveGDPRcompliantprotec onsinplace. Penalties for Non-Compliance for GDPR Ÿ It has been clearly stated that non-compliance with GDPR will cost businesses a fine of up to €20 million or 4% of their global turnover, whichever is higher. However, these fines will only be applied in extreme circumstances. Although EU authori es will be able to impose fines on a discre onary basis, they can use other “correc ve powers and sanc ons” to encourage businesses to enhance GDPR compliance. Ÿ The Other “correc ve powers and sanc ons” include issuing a warning, imposing a ban on data processing, ordering the rec fica on or dele on of data, and suspending data transfers to non-EU countries.
  • 3. Is GDPR regulation applicable to small business and sole traders © VISTA InfoSec ® Ÿ Any non-compliant ac on or lack of ac on can result in a penalty. For this very reason, small businesses need to be aware of the GDPR requirements, especially focusing on the “Special Category Data”coveredinAr cle9ofGDPR. Ÿ Stringent penal es will be imposed in case the company fails to comply with data collec on rules for children, processing or sharing data without obtaining consent, and for maintaining data longer than itslegalpurpose. Ÿ Doesnotaffectanindividuals’rightandfreedom. Ÿ DatadoesnotfallundertheGDPRAr cle9. To set the record straight and clear, GDPR applies to any or every business that deals with collec on, or processingofpersonaldataofpeoplefromtheEU.Thisholdstruewhetheryouareaone-manopera on business or a business having offices across con nents. Having said that, one may not have to keep a wri en record of their data processing ac vi es if they have less than 250 employees, and unless their dataprocessingac vi es Ÿ ThepersonaldatadoesnotfallundertheAr cle10rela ngtocriminaloffencesandconvic ons. Ÿ Thepersonaldataprocessingac vi esareconductedonaregularbasis. But by all means it is good to keep the records clear, even if one thinks they are exempt. A erall, it is be ertobesafethansorry. Implications of GDPR on small businesses Ÿ It is important to note that if a company falls under one of the exemp ons, but deals with a larger company that conducts large-scale processing, then in that case, you may be subject to the stringent GDPR’sRegula on. Ÿ A er all, it is much easier to follow the GDPR Regula on, than spend me figuring out how you can avoidComplyingtothestandards. Ÿ That apart, you would s ll want to ensure that your business is Compliant to the GDPR principles, for yourbusinessfallsundertheGDPRCompliancecategoryforregularprocessingofpersonaldata. Ÿ Being a small business does not mean you are exempted from the GDPR Compliance. However, such businesses shall be recognized as businesses having fewer resources and pose less risk to data protec on. In that case the business may see some leniency by the ICO in rela on to penalty in non- compliance. Our expert view on GDPR Regulation on small businesses It is very important for businesses to understand the spirit of GDPR. The legisla on came into existence, having seen the way how personal data were misused. Most o en companies treated personal data as a resource they could use without due regards to the rights of individual. Further, keeping aside the law, responsible data handling is a good business prac ces. As a business owner, you are responsible for your customersprivacyandanykindofdatabreachcouldpossiblycrushyourcustomerstrustonyou.
  • 4. Summary Do write to us your feedback, comments and queries or, if you have any requirements: info@vistainfosec.com You can reach us on: USA +1-415-513 5261 INDIA +91 73045 57744 SINGAPORE +65-3129-0397 © VISTA InfoSec ® As an experienced professional of the industry, I believe GDPR shouldn’t be seen as a burden, but rather be seen as adding value to your business. By proving your poten al and exis ng customers an assurance that your organisa on is compliant with new law, you could win them into bringing in more business. A er all, no one likes their data being lost, stolen, misused, or shared without proper consent. By being compliant and doing everything you can to protect your customers personal details, can help build a sense of trust which is also good for your business. I see it as a value addi on to your business wherein the company is making an effort to protect client’s data and respects personal data, rather than le ng it beusedwithoutanyconsent. There are no two ways about it when it comes to the GDPR compliance for small businesses. While it affectseverycompanyintheworld,beitsmall,mediumorlarge-scalecompanies,theGDPRregula onis definitely seen as a posi ve step towards data protec on. GDPR compliance has a posi ve impact on small businesses. Businesses have now taken their customers’ privacy more seriously. With this in place, businesses have seen more loyalty and increased trust from consumers. So, clearly, GDPR is now seen more than just as a bunch of rules to be followed to avoid penal es. By taking necessary measures to achieve GDPR Compliance, one can definitely posi on their business as one that truly cares for their customersandtheirprivatedata. facebook.com/vistainfosec/ in.linkedin.com/company/vistainfosec twitter.com/VISTAINFOSEC