SlideShare a Scribd company logo
1 of 2
Download to read offline
34 | Baltic Transport Journal | 3-4/2018
F
irst and foremost, the GDPR pro-
vides a number of new rights to
European citizens. The most fun-
damental one is the legal basis for
data processing which is, in fact, the consent
of the person whose data is to be processed.
As provided in the art. 4(11), the consent
per se has to be given freely, unambiguously
by statement or clear affirmative action.
Permission from clients can be accepted in
several ways, e.g., in writing, electronically,
or verbally. Importantly, companies have to
ensure that it is as easy to withdraw the given
consent as it was to give it in the first place.
There’s a set of additional rights granted
under the GDPR, namely right to access data
(art. 15); right to rectify data (art. 16); right
to delete data (art. 17; known also as the
“right to be forgotten”); right to limit pro-
cessing (art. 18); right to transfer data (art.
20); and right to object (art. 21). Moreover,
the GDPR sets out seven key principles that
should lie at the heart of data processing:
lawfulness, fairness, and transparency; pur-
pose limitation; data minimisation; accu-
racy; storage limitation; integrity and con-
fidentiality (security); and accountability.
At the moment, every company operat-
ing in the shipping industry worldwide has
The GDPR’s impact on the maritime industry
Are you compliant?
by Mateusz Romowicz, Legal Counsellor,
and Gabrielė Vilemo Gotkovič, Legal Assistant,
The Mateusz Romowicz Legal Consultancy
The General Data Protection Regulation (GDPR) entered into force on 25 May. By introducing a new standard
of data protection, it was designed to harmonize data privacy laws across the European Union. However,
this legal instrument has an extraterritorial effect and as such also concerns foreign companies operating
within the EU or process data of its citizens. Beyond doubt, maritime companies will be affected by the GDPR
as they deal with large volumes of personal data, including on employees, business contacts, passengers,
vessel crews, contractors, etc. The Regulation also entails stricter rules and higher fines.
to comply with the GDPR’s provisions when
EU citizen’s privacy rights are in question.
This will have a major impact on those com-
panies both time- and money-wise.
Bureaucracy, costs, and…
The companies that wish to be compatible
with the new law will be subject to an enor-
mous amount of formal requirements and
paperwork. All relevant activities should
be implemented by means of appropriate
internal procedures and duly documented.
For this purpose, it is recommended to pre-
pare appropriate documentation indicating
the measures taken to properly implement
and apply the GDPR (such documentation
may include, i.a., appropriate security cer-
tificates and certifying the competence of
persons having the access to personal data,
guidelines for employees, reports and risk
analysis, and certification of the measures
used to secure ICT systems).
The art. 30(1) of the GDPR obliges each
data administrator to keep a register of
personal data processing activities. At first
glance, this obligation binds only those com-
panies which have more than 250 employ-
ees. However, it may still apply to smaller
companies when data processing may cause
a risk of violation, is not occasional, or
includes specific categories of information
(e.g. race, trade union affiliation).
When the main activity of the admin-
istrator or processor consists of processing
operations which by their nature, scope, or
objectives require regular and systematic
#Inside
#GDPR#New rights#Key principles
#Implementation#Obligations
#Data Protection Officer
#Costs#Fines#Legal liability
#EU regulation#National legislation
Photos:pixabay.com
3-4/2018 | Baltic Transport Journal | 35
Legal
CYPRUS
GERMANY
POLAND
AUSTRIA
GREECE
ROMANIA
BULGARIA
HUNGARY
DENMARK
LITHUANIA
LATVIA
ESTONIA
FRANCE
ITALY
SLOVENIA
CROATIA
SLOWAKIA
CZECHIA
SPAIN
PORTUGAL
IRELAND
BELGIUM
LUXEMBURG
THE
NETHERLANDS
THE
UNITED
KINNGDOM
MALTA
SWEDEN
FINLAND
Passed law
Draft (incl. bill)
No draft
monitoring of data subjects on a large
scale, then appointing a Data Protection
Officer (DPO) is obligatory under the
GDPR. What’s more, the administrator is
required by the GDPR to carry out an analy-
sis whether it is obliged to appoint a DPO.
However, even if such an obligation does not
directly come from the GDPR, according to
the position of the GDPR Working Group
(the opinion-forming body that co-created
the Regulation’s contents), appointing an
inspector is strongly recommended. The
appointment of such a person gives addi-
tional security guarantees – it confirms that
the relevant body has acted with due dili-
gence as regards the protection of personal
data. The art. 37(5) provides that a DPO
should be designated on the basis of pro-
fessional qualities and, in particular, expert
knowledge of data protection law and prac-
tices, as well as the ability to fulfil the objec-
tives of the Regulation.
… even more expenses
As one can well imagine, these neces-
sary changes will be time-consuming and
will incur unavoidable costs. According to
the authors of the article It’ll Cost Billions
for Companies to Comply With Europe’s
New Data Law published in Bloomberg
Businessweek, the world’s 500 biggest cor-
porations are on track to spend a total of
$7.8b to comply with the GDPR.
The risk of non-compliance also entails
potentially very high costs. The regulators
will have the power to fine businesses which
breach GDPR requirements – up to 4% of
their worldwide turnover. In the event
of violation of the rights of individuals,
the administrator is exposed to civil and
administrative legal liability, too. In the
scope of the first type of liability, the GDPR
provides persons whose rights have been
violated with the possibility, i.a., to apply
to the court demanding that the adminis-
trator refrains from violating or ordering
specific behaviour, or for awarding dam-
ages. In addition, a data administrator is
also exposed to administrative sanctions,
taking the form of penalties. Specifically, it
can result in a fine of up to €10m, and in the
case of a company or group of companies
with a total worldwide turnover exceeding
€500m – up to 2% of total global turnover
from the previous year; or a fine of up to
€20m, and in the case of an enterprise or
group of companies with a total worldwide
turnover exceeding €500m euro – up to
4% of total global turnover from the pre-
vious year.
Who’s prepared?
Already in 1995, the EU legislated on the
protection of personal data. As such, the
GDPR is a legal instrument with roots in
the previous century (though, ever since the
Internet boom a lot of things have changed
regarding how personal data is targeted
by companies with more or less honest
intentions). Then again, barely a handful
of EU Member States was actually prepared
for the GDPR, implementing appropriate
national legislation in order to adjust their
legal systems to the Regulation.
However, it does not mean that other
countries have resigned from introduc-
ing national modifications (Fig. 1). The
majority of EU Member States have by
now drafted at least some kind legisla-
tion that’ll have to be passed in due time.
That said, it’s worth emphasizing that it
is not recommended for entrepreneurs to
refrain from adapting to the GDPR and
its policy until the adoption of the new
law on the protection of personal data in
their respective EU Member State. The
GDPR is a regulation – hierarchically the
most important legal act of the European
Union – which means that the provisions
of the GDPR are directly binding and
applicable, having an immediate effect.
In other words, as of 25 May this year, the
Regulation applies in full and entities that
perform the relevant activities, including
the collection and processing of personal
data, are forced to strictly comply with
these provisions. After all, non-compli-
ance can be very, very costly.  ‚
The Mateusz Romowicz Legal Consultancy was established in 2006 in
Gdynia. It began with offering legal consultation to natural persons,
especially Polish seafarers, and maritime workers and companies, to
extend its activities over time to provide nowadays a broad range of legal
services for numerous Polish and foreign entities. Today, the consultancy’s
core expertise covers maritime law, seafarers’ taxes and compensation,
and legal support of seafarers, shipowners, and shipbuilders.
Source: GDPR Resource Center

More Related Content

What's hot

GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India SadanandGahivare
 
IAB Europe position on the proposal for an ePrivacy regulation
IAB Europe position on the proposal for an ePrivacy regulationIAB Europe position on the proposal for an ePrivacy regulation
IAB Europe position on the proposal for an ePrivacy regulationIAB Europe
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social NetworkingDavid Erdos
 
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...Amministratore Bluefactor
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationJoseph V. Moreno
 
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...Amministratore Bluefactor
 
scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04Jan Dhont
 
GIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataGIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataIAB Europe
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Dr. Oliver Massmann
 
GDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the BankGDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the Bank"John "Jeb"" Beckwith
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for OpsKamil Rextin
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013IgorMate
 
GDPR A Privacy Regime
GDPR A Privacy RegimeGDPR A Privacy Regime
GDPR A Privacy Regimeijtsrd
 

What's hot (20)

Is Poland Ready for GDPR?
Is Poland Ready for GDPR? Is Poland Ready for GDPR?
Is Poland Ready for GDPR?
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India
 
IAB Europe position on the proposal for an ePrivacy regulation
IAB Europe position on the proposal for an ePrivacy regulationIAB Europe position on the proposal for an ePrivacy regulation
IAB Europe position on the proposal for an ePrivacy regulation
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
 
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
 
scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04
 
GIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataGIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal Data
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
 
GDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the BankGDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the Bank
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for Ops
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013
 
GDPR A Privacy Regime
GDPR A Privacy RegimeGDPR A Privacy Regime
GDPR A Privacy Regime
 

Similar to Are you compliant?

GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands legalandgeneral
 
GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookPlr-Printables
 
Aon GDPR white paper
Aon GDPR white paperAon GDPR white paper
Aon GDPR white paperGraeme Cross
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guideAngad Dayal
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Dryden Geary
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingJes Breslaw
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
Rollits Education Focus Summer 2017
Rollits Education Focus Summer 2017Rollits Education Focus Summer 2017
Rollits Education Focus Summer 2017Pat Coyle
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
GDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmGDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmChris White
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
The implementation of gdpr in greece (1)
The implementation of gdpr in greece (1)The implementation of gdpr in greece (1)
The implementation of gdpr in greece (1)FOTIOS ZYGOULIS
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?EngageHub
 
Data protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdData protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdCoadec
 

Similar to Are you compliant? (20)

GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 
GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e book
 
Aon GDPR white paper
Aon GDPR white paperAon GDPR white paper
Aon GDPR white paper
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-masking
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
Rollits Education Focus Summer 2017
Rollits Education Focus Summer 2017Rollits Education Focus Summer 2017
Rollits Education Focus Summer 2017
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
GDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmGDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, Ecosystm
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
[REPORT PREVIEW] GDPR Beyond May 25, 2018
[REPORT PREVIEW] GDPR Beyond May 25, 2018[REPORT PREVIEW] GDPR Beyond May 25, 2018
[REPORT PREVIEW] GDPR Beyond May 25, 2018
 
GDPR
GDPRGDPR
GDPR
 
The implementation of gdpr in greece (1)
The implementation of gdpr in greece (1)The implementation of gdpr in greece (1)
The implementation of gdpr in greece (1)
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
Quick guide gdpr
Quick guide gdprQuick guide gdpr
Quick guide gdpr
 
Data protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdData protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and Bird
 

More from Gabrielė Songin

More from Gabrielė Songin (8)

COVID-19 and force majeure
COVID-19 and force majeureCOVID-19 and force majeure
COVID-19 and force majeure
 
Do we have a Deal?
Do we have a Deal?Do we have a Deal?
Do we have a Deal?
 
Charge! @BalticTransportJournal
Charge! @BalticTransportJournalCharge! @BalticTransportJournal
Charge! @BalticTransportJournal
 
The albatross around climate's neck
The albatross around climate's neckThe albatross around climate's neck
The albatross around climate's neck
 
Step-by-step
Step-by-step Step-by-step
Step-by-step
 
The Swedish experience
The Swedish experience The Swedish experience
The Swedish experience
 
Off the blocks
Off the blocksOff the blocks
Off the blocks
 
UP AGAINST TRADE BARRIERS
UP AGAINST TRADE BARRIERSUP AGAINST TRADE BARRIERS
UP AGAINST TRADE BARRIERS
 

Recently uploaded

Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...shubhuc963
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxsrikarna235
 
Special Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementSpecial Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementShubhiSharma858417
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A HistoryJohn Hustaix
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceMichael Cicero
 
如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书Fir L
 
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书SD DS
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书SD DS
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书SD DS
 
Why Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdfWhy Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdfMilind Agarwal
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书SD DS
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesHome Tax Saver
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书FS LS
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书Fir sss
 

Recently uploaded (20)

Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
 
Special Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementSpecial Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreement
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A History
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
 
如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书
 
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
 
Why Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdfWhy Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdf
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax Rates
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书
 

Are you compliant?

  • 1. 34 | Baltic Transport Journal | 3-4/2018 F irst and foremost, the GDPR pro- vides a number of new rights to European citizens. The most fun- damental one is the legal basis for data processing which is, in fact, the consent of the person whose data is to be processed. As provided in the art. 4(11), the consent per se has to be given freely, unambiguously by statement or clear affirmative action. Permission from clients can be accepted in several ways, e.g., in writing, electronically, or verbally. Importantly, companies have to ensure that it is as easy to withdraw the given consent as it was to give it in the first place. There’s a set of additional rights granted under the GDPR, namely right to access data (art. 15); right to rectify data (art. 16); right to delete data (art. 17; known also as the “right to be forgotten”); right to limit pro- cessing (art. 18); right to transfer data (art. 20); and right to object (art. 21). Moreover, the GDPR sets out seven key principles that should lie at the heart of data processing: lawfulness, fairness, and transparency; pur- pose limitation; data minimisation; accu- racy; storage limitation; integrity and con- fidentiality (security); and accountability. At the moment, every company operat- ing in the shipping industry worldwide has The GDPR’s impact on the maritime industry Are you compliant? by Mateusz Romowicz, Legal Counsellor, and Gabrielė Vilemo Gotkovič, Legal Assistant, The Mateusz Romowicz Legal Consultancy The General Data Protection Regulation (GDPR) entered into force on 25 May. By introducing a new standard of data protection, it was designed to harmonize data privacy laws across the European Union. However, this legal instrument has an extraterritorial effect and as such also concerns foreign companies operating within the EU or process data of its citizens. Beyond doubt, maritime companies will be affected by the GDPR as they deal with large volumes of personal data, including on employees, business contacts, passengers, vessel crews, contractors, etc. The Regulation also entails stricter rules and higher fines. to comply with the GDPR’s provisions when EU citizen’s privacy rights are in question. This will have a major impact on those com- panies both time- and money-wise. Bureaucracy, costs, and… The companies that wish to be compatible with the new law will be subject to an enor- mous amount of formal requirements and paperwork. All relevant activities should be implemented by means of appropriate internal procedures and duly documented. For this purpose, it is recommended to pre- pare appropriate documentation indicating the measures taken to properly implement and apply the GDPR (such documentation may include, i.a., appropriate security cer- tificates and certifying the competence of persons having the access to personal data, guidelines for employees, reports and risk analysis, and certification of the measures used to secure ICT systems). The art. 30(1) of the GDPR obliges each data administrator to keep a register of personal data processing activities. At first glance, this obligation binds only those com- panies which have more than 250 employ- ees. However, it may still apply to smaller companies when data processing may cause a risk of violation, is not occasional, or includes specific categories of information (e.g. race, trade union affiliation). When the main activity of the admin- istrator or processor consists of processing operations which by their nature, scope, or objectives require regular and systematic #Inside #GDPR#New rights#Key principles #Implementation#Obligations #Data Protection Officer #Costs#Fines#Legal liability #EU regulation#National legislation Photos:pixabay.com
  • 2. 3-4/2018 | Baltic Transport Journal | 35 Legal CYPRUS GERMANY POLAND AUSTRIA GREECE ROMANIA BULGARIA HUNGARY DENMARK LITHUANIA LATVIA ESTONIA FRANCE ITALY SLOVENIA CROATIA SLOWAKIA CZECHIA SPAIN PORTUGAL IRELAND BELGIUM LUXEMBURG THE NETHERLANDS THE UNITED KINNGDOM MALTA SWEDEN FINLAND Passed law Draft (incl. bill) No draft monitoring of data subjects on a large scale, then appointing a Data Protection Officer (DPO) is obligatory under the GDPR. What’s more, the administrator is required by the GDPR to carry out an analy- sis whether it is obliged to appoint a DPO. However, even if such an obligation does not directly come from the GDPR, according to the position of the GDPR Working Group (the opinion-forming body that co-created the Regulation’s contents), appointing an inspector is strongly recommended. The appointment of such a person gives addi- tional security guarantees – it confirms that the relevant body has acted with due dili- gence as regards the protection of personal data. The art. 37(5) provides that a DPO should be designated on the basis of pro- fessional qualities and, in particular, expert knowledge of data protection law and prac- tices, as well as the ability to fulfil the objec- tives of the Regulation. … even more expenses As one can well imagine, these neces- sary changes will be time-consuming and will incur unavoidable costs. According to the authors of the article It’ll Cost Billions for Companies to Comply With Europe’s New Data Law published in Bloomberg Businessweek, the world’s 500 biggest cor- porations are on track to spend a total of $7.8b to comply with the GDPR. The risk of non-compliance also entails potentially very high costs. The regulators will have the power to fine businesses which breach GDPR requirements – up to 4% of their worldwide turnover. In the event of violation of the rights of individuals, the administrator is exposed to civil and administrative legal liability, too. In the scope of the first type of liability, the GDPR provides persons whose rights have been violated with the possibility, i.a., to apply to the court demanding that the adminis- trator refrains from violating or ordering specific behaviour, or for awarding dam- ages. In addition, a data administrator is also exposed to administrative sanctions, taking the form of penalties. Specifically, it can result in a fine of up to €10m, and in the case of a company or group of companies with a total worldwide turnover exceeding €500m – up to 2% of total global turnover from the previous year; or a fine of up to €20m, and in the case of an enterprise or group of companies with a total worldwide turnover exceeding €500m euro – up to 4% of total global turnover from the pre- vious year. Who’s prepared? Already in 1995, the EU legislated on the protection of personal data. As such, the GDPR is a legal instrument with roots in the previous century (though, ever since the Internet boom a lot of things have changed regarding how personal data is targeted by companies with more or less honest intentions). Then again, barely a handful of EU Member States was actually prepared for the GDPR, implementing appropriate national legislation in order to adjust their legal systems to the Regulation. However, it does not mean that other countries have resigned from introduc- ing national modifications (Fig. 1). The majority of EU Member States have by now drafted at least some kind legisla- tion that’ll have to be passed in due time. That said, it’s worth emphasizing that it is not recommended for entrepreneurs to refrain from adapting to the GDPR and its policy until the adoption of the new law on the protection of personal data in their respective EU Member State. The GDPR is a regulation – hierarchically the most important legal act of the European Union – which means that the provisions of the GDPR are directly binding and applicable, having an immediate effect. In other words, as of 25 May this year, the Regulation applies in full and entities that perform the relevant activities, including the collection and processing of personal data, are forced to strictly comply with these provisions. After all, non-compli- ance can be very, very costly.  ‚ The Mateusz Romowicz Legal Consultancy was established in 2006 in Gdynia. It began with offering legal consultation to natural persons, especially Polish seafarers, and maritime workers and companies, to extend its activities over time to provide nowadays a broad range of legal services for numerous Polish and foreign entities. Today, the consultancy’s core expertise covers maritime law, seafarers’ taxes and compensation, and legal support of seafarers, shipowners, and shipbuilders. Source: GDPR Resource Center