GDPR -
WHAT‘S NEXT?
Factory Works
18.06.2018
• Binding EU-law from 2016 (!)
• Effective since 25th of May 2018
• Relevant for all companies, process personal data from
citizens and residents in the EU
• Small opportunities for member states to individualize
specifications of the GDPR (e.g. age for consent to data
processing)
GDPR IN A NUTSHELL
• Legal basis for processing (Art. 6 (1) GDPR)
– Explicit consent
– Fulfillment of contractual obligations
– Legitimate interests of a data controller
– Vital interests
– Public interest or in official authority
– Legal obligations
• Data transfer outside the EU (Art. 44 ff. GDPR)
– Adequate protection according to EU commission (US-EU-Privacy
Shield), or
– Consent
• Privacy by design, privacy by default
GDPR BASICS
• “Window Dressing”
– New privacy policies for websites
– Adjustments of GTC, resp.
– Adjustments of ToS
• Records of processing activities (Art. 30 GDPR)
– Maintained record of all processing activities (mainly for internal use)
• Data processing agreements (DPA, Art. 28 GDPR)
– Processing is carried out by third party
– Assurance of technical and organisational measures
• Clarification of DPO requirement (Art. 37 GDPR)
– 10 or more employees
GDPR - FIRST MEASURES
• … a new privacy policy for my website? – Yes.
• … to inform my customers about my new privacy policy? –
No.
• … to inform my subscribers about my new privacy
regulations? – No.
• … I need to translate my privacy policy into the different
languages on my website? – Yes.
GDPR - DO I NEED…
• Cease-and-desist orders from competitor
– Current status: unlikely (for now!)
• Cease-and-desist orders from organisations
– Current status: unknown
• Fines from authorities (Art. 51 GDPR ff.)
– Current status: unlikely (for now!)
• Claims from data subjects
– Information requests, deletion requests, etc.
– Current status: likely
GDPR-NIGHTMARES
• Data transfer to the USA
– Status of EU–US Privacy Shield due to Cloud Act unsure
• ePrivacy Regulation
– Covers all online communication (esp. online marketing)
– In effect in 2019 (?)
• Court decisions
• Adoptions of member states
GDPR – WHAT’S NEXT? UPCOMING ISSUES
Certified lawyer for IT-law
Certified lawyer for Media Law
• Mail: kontakt@medienrechtberlin.de
• Web: www.medienrechtberlin.de
• Blog: www.lawbster.de
• LinkedIn: www.linkedin.com/in/dramburg/
SEBASTIAN DRAMBURG, LL. M.

GDPR

  • 1.
  • 2.
    • Binding EU-lawfrom 2016 (!) • Effective since 25th of May 2018 • Relevant for all companies, process personal data from citizens and residents in the EU • Small opportunities for member states to individualize specifications of the GDPR (e.g. age for consent to data processing) GDPR IN A NUTSHELL
  • 3.
    • Legal basisfor processing (Art. 6 (1) GDPR) – Explicit consent – Fulfillment of contractual obligations – Legitimate interests of a data controller – Vital interests – Public interest or in official authority – Legal obligations • Data transfer outside the EU (Art. 44 ff. GDPR) – Adequate protection according to EU commission (US-EU-Privacy Shield), or – Consent • Privacy by design, privacy by default GDPR BASICS
  • 4.
    • “Window Dressing” –New privacy policies for websites – Adjustments of GTC, resp. – Adjustments of ToS • Records of processing activities (Art. 30 GDPR) – Maintained record of all processing activities (mainly for internal use) • Data processing agreements (DPA, Art. 28 GDPR) – Processing is carried out by third party – Assurance of technical and organisational measures • Clarification of DPO requirement (Art. 37 GDPR) – 10 or more employees GDPR - FIRST MEASURES
  • 5.
    • … anew privacy policy for my website? – Yes. • … to inform my customers about my new privacy policy? – No. • … to inform my subscribers about my new privacy regulations? – No. • … I need to translate my privacy policy into the different languages on my website? – Yes. GDPR - DO I NEED…
  • 6.
    • Cease-and-desist ordersfrom competitor – Current status: unlikely (for now!) • Cease-and-desist orders from organisations – Current status: unknown • Fines from authorities (Art. 51 GDPR ff.) – Current status: unlikely (for now!) • Claims from data subjects – Information requests, deletion requests, etc. – Current status: likely GDPR-NIGHTMARES
  • 7.
    • Data transferto the USA – Status of EU–US Privacy Shield due to Cloud Act unsure • ePrivacy Regulation – Covers all online communication (esp. online marketing) – In effect in 2019 (?) • Court decisions • Adoptions of member states GDPR – WHAT’S NEXT? UPCOMING ISSUES
  • 8.
    Certified lawyer forIT-law Certified lawyer for Media Law • Mail: kontakt@medienrechtberlin.de • Web: www.medienrechtberlin.de • Blog: www.lawbster.de • LinkedIn: www.linkedin.com/in/dramburg/ SEBASTIAN DRAMBURG, LL. M.