Analysis of personal data protection regulations (GDPR) – 3. To whom the Regulation (EU) 2016/679 it is applied

Analysis of personal data protection regulations (GDPR) – 2. Preliminary explanations
February 15, 2018
Analysis of personal data protection regulations (GDPR) – 4. The obligations of operators who perform personal data processing activities
February 21, 2018

 

Regulation (EU) 2016/679 on the protection of individuals regarding the processing of personal data and the free movement of such data (GDPR) is applicable to personal data processed by an operator established in the European Union, irrespective of whether the data processing takes place on community territory.

 

Legal processing of personal data is therefore an activity of an operator, after obtaining the consent of a person, collects, records, organizes, structures, stores, modifies, extracts, consults, uses, transmits, deletes or destroys information about that person.

Among the data subject to processing, we enumerate, by example:

  • Surname, first name, SSN, address, ID serial number and number
  • Email, phone
  • Data on race, ethnicity, political affiliation
  • Data related to the health of the person concerned
  • Data relating to the economic situation of the the person concerned
  • Data entered in the criminal record of the the person concerned
  • Data that allows the person to be identified by electronic monitoring systems (GPS, access cards, etc.).

We present you further on some examples, very few, of personal data processing activities that determine the need for the company to meet the obligations that we will present in the article we will be publishing on the web site on Wednesday, February 21, 2018:

  1. Storing, on an outsourced server, of employees data (name, SSN, address).
  2. Assigning access cards to employees and storing time based on cards.
  3. Collecting CVs of people who will be invited to an interview.
  4. Tracking your own or rented trucks with GPS systems.
  5. Using commercial partners’ data (ex customers, suppliers, etc.) for any kind of marketing activities, from commercial information to vouchers.
  6. How to store e-mail messages on the server.
  7. Surveillance of their own spaces.
  8. Use personal data (either of your own employees or of other individuals) on your own site.
  9. Outsourcing accounting services, human resources, audit, etc.

These are just a schematic and succinct presentation of the provisions of the new GDPR Regulation. For any questions or clarifications, please contact us by email at office@paulopol.ro.

How can we help you to implement GDPR correctly

We present you further on just a few examples of services you can get from the Paulopol Attorneys and Counselors Law Firm by outsourcing the Data Protection Officer (DPO), in order for you to implement GDPR correctly:

  1. Specialized consulting on the protection of personal data.
  2. Drafting or reviewing internal policies and data protection rules
  3. Legal opinions on the measures to be taken in order to comply with the legal provisions.
  4. Data protection audit based on the analysis of all operating regulations and internal policies.
  5. Drawing up codes of conduct.
  6. Database management consulting.
  7. Drawing up the transfer policies of the databases.
  8. Drafting and consulting on the implementation of policies on the protection of employees personal data,

These are just some of the services we can offer you related to GDPR. For details and legal assistance, please contact us by email at office@paulopol.ro.