05 February 2017 · Lukáš Steiniger

GDPR - Part 1: The most fundamental changes

GDPR - Part 1: The most fundamental changes
Legal status as of the publication date (05 February 2017). Later legislative changes may not be reflected in the text.

What preceded the reform

When the European Commission put forward the draft GDPR in 2012, the significance and importance of this legal instrument immediately resonated in professional circles. After four years of demanding negotiations and expert discussions, the draft GDPR was finally adopted in April 2016 in order to bring a regulatory response to today's digital economy.

The GDPR (General Data Protection Regulation), that is, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, will replace the outdated and currently applicable Directive 95/46/EC of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of data, whose rules were created at a time when the internet was used by roughly 1% of the European population.

The development of the internet and the arrival of social networks, accompanied by new business models and marketing tools, together with the related sharp increase in the use of IT technologies, called for a substantial change in the regulation of personal data protection. The aim of the approved reform is to return the lost control over personal data back into the hands of data subjects and thereby to strengthen the building of people's trust in the digital economy and in electronic services, which cannot function effectively without personal data.

The GDPR is intended to effectively offset the fact that the fundamental human right to the protection of privacy and personal data has become the de facto currency for the services of the modern digital economy, for example when using smartphone applications, wi-fi tracking, cookies, GPS monitoring or customer loyalty programmes. What practical effects the GDPR will have on people and businesses, as well as practical guidance on how to prepare for the GDPR, we will analyse in detail in a series of regular articles that we will bring you during the transitional period preceding the regulation's entry into effect.

An overview of the most fundamental changes

In the introductory part of our regular series, we will outline the most fundamental changes that the new personal data protection regulation brings:

1. The form of the legal instrument

The regulation of personal data protection has until now been governed in the form of a directive, which was transposed into the individual national legal orders of the Member States very differently. This often led to inconsistent application practice by supervisory authorities across Europe. The current form of the regulatory legal instrument is a regulation, which, unlike a directive, will be directly applicable in the Member States. This should prevent the emergence of fundamental differences in the legal framework at national levels and guarantee the same level of requirements for fulfilling the specific obligations laid down by the regulation. Likewise, there should be a unification of the approach of national supervisory authorities in enforcing the obligations laid down in the GDPR.  Specific legal instruments provided for by the regulation, such as the so-called consistency mechanism or the European Data Protection Board, should help with this. Even though it is an EU regulation, it must be expected that its actual incorporation into our legal order (reception) will be accompanied by the adoption of a new national act on the protection of personal data. Some elements will be left by the GDPR for Member States to regulate autonomously (e.g. the age of minors for granting consent to the processing of personal data), whereas other elements of personal data processing will not be regulated by the GDPR at all and will therefore need to be regulated at national level (e.g. the procedural process of supervisory authorities when imposing sanctions, or the exercise of inspection).

2. A broader scope of the regulatory rules

The GDPR will no longer apply only to natural persons resident, and legal persons established, in an EU Member State, or to entities that physically locate the means of processing personal data in the territory of an EU Member State; it will also apply to controllers and processors of data originating in third countries (outside the EU) who, for example, offer goods and services to residents or businesses within the EU or monitor the behaviour of their customers (private individuals) from the European Union;

3. One-stop-shop (the single point of contact principle)

During the drafting of the GDPR this was a very sharply and lengthily debated legal instrument, whose main purpose is to make it easier for data subjects as well as accountable entities to deal with a single, linguistically closest supervisory authority, even in cross-border cases of enforcing compliance with GDPR rules. This legal instrument rests on two main pillars: the determination of the main establishment in the EU (the so-called "main establishment") and the determination of the lead supervisory authority ("lead supervisory authority"). As an example one may cite a situation in which a Slovak citizen files a complaint with the Slovak Office for Personal Data Protection concerning cross-border processing of personal data carried out by a company established in Austria. The Austrian supervisory authority (Datenschutzbehörde) will in this case be regarded as the lead supervisory authority in relation to the processing of the Slovak citizen's personal data. The Slovak office will in this case inform the Austrian supervisory authority of the Slovak citizen's complaint, and the latter will decide whether to take it over and deal with it jointly with the Slovak office, or not to take the complaint over, in which case it will be handled at the Slovak level. If the Austrian supervisory authority decides to take the case over, it will cooperate with the Slovak office, both during the investigation and when issuing the decision on the matter itself (e.g. a decision imposing a fine). The functioning of this instrument will, however, be much more complex in practice, and we will therefore devote more attention to it in a separate article.

4. Clarification of the definition of personal data

The GDPR clarifies the concept of personal data such that various online identifiers of persons (for example an IP address, cookies) and other electronic identifiers (for example RFID technologies, or so-called traffic and location data) will now also be regarded as personal data.

5. Strengthening the accountability principle

The GDPR will also strengthen the already existing principle of accountability of entities processing personal data, that is, controllers, processors and joint controllers. At the same time, it develops this principle in the direction that, "taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation." It is precisely the ability of the business to demonstrate the adoption of appropriate security measures, as required by the regulation, that is key. In this respect the GDPR gives businesses several ways to demonstrate the internal compliance of their systems and processes with the GDPR. Specific measures for a business may be, for example, obtaining certification of appropriately configured internal processes and security measures, or adherence to approved and monitored codes of conduct, which will probably emerge over time in individual sectors. Another of the options will be, for example, creating an internal "Personal Data and Privacy Protection" policy (a so-called "Privacy Policy"), keeping documentation of processing operations, documentation of security incidents, carrying out data protection impact assessments, or appointing a personal data protection specialist to the role of data protection officer.

6. The obligation to report and document security incidents

The GDPR introduces an obligation, where certain conditions are met, to report every personal data breach to the supervisory authority within 72 hours of identifying the security incident. In the Slovak Republic, incidents will be reported to the Office for Personal Data Protection. Where a breach leads to a risk to the rights of data subjects (e.g. the compromise of identity and login credentials for using a service, or the leak of sensitive data), a business may also become obliged to notify this breach to each individual person who may be affected by it. Proper documentation of security incidents, their consequences and the measures adopted for remedy will likewise be a matter of course.

7. The opt-in form of the data subject's consent

Under the GDPR, consent to the processing of personal data will have to be expressed freely, specifically, in an informed manner and by an unambiguous indication of will. Such an act may include, for example, ticking a box (a so-called checkbox) when visiting a website, choosing technical settings when using an electronic shop, or any other declaration or act of the data subject which, in the given context, will clearly signify that the data subject consents to the processing of their personal data. Silence, "pre-ticked" boxes or inactivity on the part of the data subject will therefore no longer be capable of being regarded as consent to the processing of personal data. The granting of consent in the form of acceptance of general terms and conditions that contain a provision on granting consent to the processing of personal data will therefore not be sufficient under the GDPR. With this approach, the GDPR formalises the current application practice of supervisory authorities.

8. New rules on consent by minor data subjects

The GDPR clearly provides that the processing of the personal data of minors in the context of information society services (for example when using various online services, social networks or when shopping in an e-shop) will be lawful only where the minor is at least 16 years of age. The GDPR does not set a minimum age limit here; individual Member States will be able to set it differently. If the minor is younger, the processing of their personal data will be lawful only under the condition, and to the extent, that consent to the processing of their personal data is expressed or approved by their legal representative.

9. Restriction of automated processing of personal data

The GDPR strengthens the position of data subjects also in that data subjects will be able to challenge, and not be subject to, decisions of the controller that are based solely on so-called profiling, that is, the automated processing of their personal data (for example the automatic rejection of an online loan application, or electronic recruitment procedures without any human intervention). Decision-making by businesses based on profiling will, however, be permitted in cases expressly allowed by EU law (e.g. AML programmes for assessing a client's risk behaviour, which are commonly used in the financial sector).

10. A preference for the pseudonymisation of personal data

Among other things, the GDPR also encourages businesses processing personal data to pseudonymise that data to the greatest extent possible. Under the GDPR, the pseudonymisation of personal data will be regarded as an appropriate security measure for the protection of personal data. Pseudonymised personal data can be understood as any encrypted data which, although it does not allow the direct identification of the data subject, will, after being decrypted with an adequate key, once again become "raw" and identifiable personal data. The use of pseudonymisation (for example in the form of so-called IP masking) may be key, for instance, when using various online services to track users and display behavioural advertising.

11. Data protection by default and by design

The GDPR creates, side by side, two basic levels of approach to the issue of the security of personal data processing. The first concept is so-called data protection by default ("data protection by default"). Under this concept, businesses must in all circumstances ensure, that is, actually adopt, security measures which, in terms of the amount, extent and duration of processing, minimise the "package" of data containing personal data to the necessary minimum that the particular business needs to achieve the processing purposes it has set. In practical terms, these will be cases of processing personal data only to the extent necessary for the purposes of carrying on the particular business's object of activity (e.g. the process of managing data contained in an order of goods from its collection, its disclosure to partners during delivery and its renewed collection when handling a complaint, through to its erasure). The default concept necessarily concerns every business processing personal data. The second concept is data protection by design ("data protection by design"). This concept requires businesses processing personal data to implement, already when determining the means of processing personal data (that is, already in the phase of developing a new application or introducing a new service), technical and security measures which, having regard to the state of the art ("state of art") and the cost of their implementation, will be functional throughout the entire process of personal data processing. When adopting security measures, every business will have to take into account the nature, scope, context and purposes of the processing of personal data as well as the risks of interference with such personal data. The recitals of the GDPR ("recitals"), which serve as a kind of interpretative guide to the regulation, place emphasis in this connection on the earliest possible pseudonymisation of data, transparency towards data subjects, data minimisation and the flexibility of the business in terms of its ability to add to and improve security features.

12. A risk-based approach

The GDPR strengthens its regulatory influence to a heightened degree over entities that carry out processing operations on personal data likely to result in a high risk to the rights and freedoms of natural persons. Based on the wording of the GDPR, high-risk processing operations can be spoken of especially in connection with so-called profiling, or the extensive and systematic monitoring of public spaces, or the large-scale processing of sensitive personal data. Such factors then give rise to specific obligations, such as, for example, carrying out prior consultation with the supervisory authority, drawing up a Data Protection Impact Assessment, or appointing a suitable person to the role of Data Protection Officer.

13. Changes in informing data subjects

Already under Directive 95/46/EC, or our current national act on the protection of personal data, it is necessary, when collecting personal data, in certain cases to provide data subjects with several essential legal pieces of information concerning the processing of their personal data. In this respect the GDPR brings certain changes in the content of this information. From the perspective of the GDPR, the transparency of the business towards data subjects will likewise be key, accompanied by the provision of concise, comprehensible and easily accessible information at the right time and in an appropriate manner. The position of minors will need to be taken into account in particular when processing their personal data.

14. The rights of data subjects

The main motive for adopting the GDPR was the strengthening of the rights of data subjects. It is therefore not surprising that the GDPR introduces entirely new rights of data subjects. One of them is the so-called "right to be forgotten", which extends the already existing right to the erasure of personal data, or the right to the portability of data in a machine-readable format to another (new) controller. It is precisely these rights that will have a fundamental impact on businesses, which will have to adapt their internal processes and systems and ensure the protection and enforceability of these rights for the benefit of data subjects.

15. Cross-border transfers of personal data

The GDPR in principle preserves the current form of the principles, legal instruments and mechanisms that are already used today for the cross-border transfer of personal data. It will, however, also bring several changes, additions and clarifications. The GDPR will, for example, restrict transfers of personal data to third countries unless they are secured and governed by existing legal documents such as, for example, standard contractual clauses or binding corporate rules. It is new that approved certification mechanisms (e.g. data protection seals and marks issued by a certified body) will also be able to be used to carry out cross-border transfers of personal data. Another novelty will be that, under the GDPR, approval of a cross-border transfer by the national supervisory authority before it is carried out (so-called prior authorisation) will no longer be required.

16. Sanctions

The changes that the GDPR brings in the area of sanctions for breaching the regulation of personal data protection are fundamental. First of all, there will be a strengthening of the powers and international cooperation between national supervisory authorities. Secondly, the limits of the sanctions have been enormously increased compared with the present, together with the mandatory principle of imposing them. For the most serious administrative offences, supervisory authorities will impose fines of up to EUR 20,000,000, or up to 4% of the total worldwide annual turnover of the business for the preceding financial year, whichever amount is higher. In addition to the substantial increase in the upper limits of the fines, supervisory authorities may therefore also reach for a progressive model of administrative penalty, which can be regarded as a raised warning finger even to the largest technology giants that profit most from the processing of personal data (e.g. Google, Facebook).

Why should businesses concern themselves with the GDPR already now?

The GDPR will apply from 25 May 2018. By this date, businesses will have to review their internal processes and their legal and security documentation and gradually adapt them to the requirements of the GDPR. The degree of regulatory impact on particular businesses will vary, with its "weight" depending especially on the nature, quantity and sensitivity of the personal data processed by the particular business, together with the associated risks. The process of adapting current personal data protection systems and processes may thus, for some businesses, be a fairly complex and time-consuming process. It is therefore advisable for businesses to begin preparing for the new personal data protection regulation as soon as possible.