{"id":6307,"date":"2019-06-10T08:27:30","date_gmt":"2019-06-10T06:27:30","guid":{"rendered":"https:\/\/www.gulliksson.se\/?p=6307"},"modified":"2019-06-10T08:28:29","modified_gmt":"2019-06-10T06:28:29","slug":"one-year-into-the-gdpr-the-gdpr-requires-a-continuous-and-systematic-approach","status":"publish","type":"post","link":"https:\/\/www.gulliksson.se\/en\/one-year-into-the-gdpr-the-gdpr-requires-a-continuous-and-systematic-approach\/","title":{"rendered":"One year into the GDPR: \u201cThe GDPR requires a continuous and systematic approach\u201d"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row][vc_column][vc_column_text]<strong>Greater responsibility, new documentation requirements and hefty administrative fines. These were some of the most important new provisions to be aware of when the GDPR came into force in May last year.<br \/>\n<\/strong><strong>&#8211; GDPR efforts did not end on 25 May 2018. It\u2019s extremely important for companies to have a systematic process for continuing efforts. Data protection is a continuous process and something companies need to work on regularly, says <a href=\"https:\/\/www.gulliksson.se\/en\/team\/mirja-ekdahl\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mirja Ekdahl<\/a>, a Gulliksson senior associate whose specializations include data protection and privacy matters. <\/strong><\/p>\n<p><span style=\"font-weight: 400;\">The General Data Protection Regulation (GDPR) entered into force throughout the EU with the aim of creating a uniform and comparable level of protection for personal data. \u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">&#8211; Although many of the provisions of the GDPR are similar to the provisions previously stipulated in our Swedish Personal Data Act, it was made very clear to companies that they needed to review and in many cases improve their procedures, says <a href=\"https:\/\/www.gulliksson.se\/en\/team\/mirja-ekdahl\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mirja Ekdahl<\/a>, who, along with her colleagues at Gulliksson, helped clients make adjustments to ensure their business was ready for and compliant with the legislation. \u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">&#8211; During the course of this work, we also saw an increase in awareness for how important it is to protect and respect personal privacy, <a href=\"https:\/\/www.gulliksson.se\/en\/team\/mirja-ekdahl\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mirja Ekdahl<\/a> explains as she highlights the recurring questions she asked when advising clients: \u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What personal data does the company process? Does the company process sensitive personal data? How does the company process this data? Does the company process the data based on consent, performance of a contract, a legitimate interest or another legal basis? Does the company provide sufficient information when collecting the data? Does the company have an adequate level of protection for the data? <\/span><\/p>\n<p><span style=\"font-weight: 400;\">&#8211; In addition to taking a holistic approach to the company&#8217;s processing of personal data, specific questions came up about details like whether it&#8217;s OK to send payslips and other sensitive information by email, says <a href=\"https:\/\/www.gulliksson.se\/en\/team\/karin-strandberg\/\" target=\"_blank\" rel=\"noopener noreferrer\">Karin Strandberg<\/a>, a Gulliksson partner whose specializations include labour law. \u00a0<\/span><\/p>\n<p><b>GDPR compliance is a must \u2013 procedures and follow-up are required<br \/>\n<\/b><span style=\"font-weight: 400;\">The Swedish Data Protection Authority can order companies in breach of the provisions of the GDPR to pay an administrative fine. The maximum amount of this fine is EUR 20 million or four percent of the company\u2019s total worldwide annual turnover, whichever is higher. The maximum amount for less severe breaches is EUR 10 million or two percent of the company\u2019s total worldwide annual turnover. \u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">&#8211; Being hit with an administrative fine has an impact that goes beyond the money \u2013 it creates badwill for the company. Although the Swedish Data Protection Authority has not yet ordered any administrative fines at this time, the GDPR is here to stay and compliance is a must,\u00a0 says <a href=\"https:\/\/www.gulliksson.se\/en\/team\/mirja-ekdahl\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mirja Ekdahl<\/a>. \u00a0<\/span><\/p>\n<p><b>Gulliksson provides ongoing support and advice<br \/>\n<\/b><span style=\"font-weight: 400;\">In addition to reviewing your processing of personal data and your data protection, Gulliksson can ensure that you are fully compliant and draft procedures and compliance documents. Feel free to contact Gulliksson for a no-obligation meeting to discuss your company\u2019s continuing GDPR efforts and specific needs. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Mirja Ekdahl, Senior Associate, Malm\u00f6<br \/>\n<\/span><span style=\"font-weight: 400;\">+46 (0)70-513 13 70<br \/>\n<\/span><span style=\"font-weight: 400;\">mirja.ekdahl@gulliksson.se <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Karin Strandberg, Partner, Malm\u00f6<br \/>\n<\/span><span style=\"font-weight: 400;\">+46 (0)70-819 06 52<br \/>\n<\/span><span style=\"font-weight: 400;\">karin.strandberg@gulliksson.se <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Magnus Friberg, Partner, Lund<br \/>\n<\/span><span style=\"font-weight: 400;\">+46 (0)73-519 59 49<br \/>\n<\/span><span style=\"font-weight: 400;\">magnus.friberg@gulliksson.se <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ulrika Nordenvik, Senior Associate, Lund<br \/>\n<\/span><span style=\"font-weight: 400;\">+46 (0)70-203 61 00<br \/>\n<\/span><span style=\"font-weight: 400;\">ulrika.nordenvik@gulliksson.se <\/span><\/p>\n<p><strong>The GDPR \u2013 some of the most important changes that entered into force in May 2018: <\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Greater responsibility for both controllers and processors <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">New documentation requirement for the processing of personal data: You must be able to demonstrate that you process personal data correctly <\/span><\/li>\n<\/ul>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Stronger position for data subjects, including: <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">&#8211; Stricter requirements to inform data subjects of which of their data is processed <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">&#8211; Clearer rights for data subjects \u201cto be forgotten\u201d (i.e. the right to have their personal data erased) <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">&#8211; The right to transfer their stored data to another company \u2013 data portability <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">&#8211; Stricter consent requirements <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">New data security requirements \u2013 with data protection by design and by default. In certain cases, the regulation requires that a data protection impact assessment be performed and that a data protection officer be appointed. The Swedish Data Protection Authority must be notified of personal data breaches (within 72 hours) in certain cases. <\/span><\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text]Greater responsibility, new documentation requirements and hefty administrative fines. These were some of the most important new provisions to be aware of when the GDPR came into force in May last year. &#8211; GDPR efforts did not end on 25 May 2018. It\u2019s extremely important for companies to have a systematic process for continuing efforts&#8230;.  <a class=\"excerpt-read-more\" href=\"https:\/\/www.gulliksson.se\/en\/one-year-into-the-gdpr-the-gdpr-requires-a-continuous-and-systematic-approach\/\" title=\"Read One year into the GDPR: \u201cThe GDPR requires a continuous and systematic approach\u201d\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":7,"featured_media":5699,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[157,120],"tags":[],"class_list":["post-6307","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-front-news-en","category-gulliksson-news"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/posts\/6307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/comments?post=6307"}],"version-history":[{"count":2,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/posts\/6307\/revisions"}],"predecessor-version":[{"id":6309,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/posts\/6307\/revisions\/6309"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/media\/5699"}],"wp:attachment":[{"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/media?parent=6307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/categories?post=6307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gulliksson.se\/en\/wp-json\/wp\/v2\/tags?post=6307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}