Key components of GDPR Flashcards
Harmonization across and beyond the EU
Making it simpler and cheaper for organizations to do business across the Union
The Regulation separates responsibilities and
duties of data controllers and processors
obligate controllers to engage only those processors that provide “sufficient guarantees to implement appropriate technical and organisational measures” to meet the Regulation’s requirements and protect data subjects’ rights.
regulation suggestion for appropriate securities
- pseudonymization and/or encryption of personal data
- ensure CIA, & Resilience of systems & services processing personal data
- restore the availability and access to data in a timely manner in an event of an incident
- a process for regularly testing, assessing, & evaluating the effectiveness of technical & organizational measures for ensuring the security of the processing
Regulators now have the authority to issue fines for violations of record-keeping, security, breach notification, & privacy impact assessment obligations
10 million Euros or 2% of your global revenue
GDPR violation, related to the legal justification for processing (cross data transfers, data subject rights)
20 mil Euro or 4% of global revenue
breach notification
not later than 72 hours