GDPR compliance, meaning, rights

The GDPR (General Data Protection Regulation) is a new Regulation of the EU on personal data protection.

GDPR is not just a law; the Regulation is in force in more than twenty countries and potentially extends its regulatory significance even to those outside the EU who would like to participate in the EU internal market trade.

In addition, the GDPR is a global model of personal data protection, an example of good practice, and is followed by a number of updated national data privacy laws. In other words, even if the GDPR does not apply directly in your country, companies may still face the question of “how to comply with the GDPR” and “how to prepare for the GDPR”.

Interestingly, many outsourcers need a deployed GDPR compliance toolkit. We gladly advise on the GDPR-related matters, prepare the GDPR documents for a website or application, and conduct a GDPR audit. The GDPR service you need may well be available in our portfolio and be described in a separate article. We have a successful experience of handling the GDPR preparation in various fields.

In this blog, we tell a bit more about the GDPR compliance in general, as well as share secrets and build a solid GDPR plan for your case. Ensuring the ongoing GDPR compliance, drafting GDPR documents, and preparing for GDPR with our advice will become an easy and enjoyable experience. Even if you just want to explore the outcomes of your business processes, launch a new GDPR-compliant product, or enter the market covered by GDPR, our blog will be useful for you.

You can learn more about our offer on the GDPR compliance service page.

Dubas Kateryna

IT / privacy lawyer

DPIA – an underestimated privacy-friendly tool

DPIA – an underestimated privacy-friendly tool

A data protection impact assessment (DPIA) sounds like something big, complicated and problematic. Well, it is true. Especially considering that the text of the General Data Protection Regulation (GDPR) does not have any clue about…
Data Retention Policy: what is it, and why is it needed?

Data Retention Policy: what is it, and why is it needed?

In 2021, the French supervisory authority (CNIL) imposed a fine of €1,750,000 on SGAM AG2R LA MONDIALE.  CNIL said in the decision that the controller violated the storage limitation principle by processing the data of…

ChatGPT vs Italian Supervisory Authority: who wins?

In 2023 the real technological “boom” happened — products based on artificial intelligence flooded the market. They can accomplish different tasks: Midjourney generates text into images, Soundful allows you to create music, and SlidesAI can…

GDPR vs Meta Platforms: The Rest of the Story. User Consent Must Be Provided

Recently, we have already talked about the difficulties faced by the tech giant Meta Platforms with European supervisory authorities (Irish DPC, European EDPB) and the prospects for further litigation regarding the illegal processing of users’…

Employee monitoring: what employers should consider

Business efficiency is not only about properly configured business processes but also about personnel control. Today, employers use various tools to monitor their employees’ work, such as video surveillance in office premises (CCTV), GPS, traffic…

How to handle security incidents/data breaches under the LGPD

Introduction  In our previous articles, we have already drawn your attention to the Brazilian data protection legislation which is quite similar to the General Data Protection Regulation (GDPR). South America is one of the most…

TОР-7 fines of 2022 for violation of the GDPR rules

Is 1,000 EUR a lot for a business? What about 100,000 EUR? And 405,000,000 EUR? This is the amount of a fine paid by a well-known company for violating the rules of the European General…

The first GDPR certification in Luxembourg

Since the entry into force of the General Data Protection Regulation (GDPR), many companies processing the data of Europeans have faced the task of achieving the much desired GDPR-compliance. However, no one can say exactly…

GDPR compliance. What to prepare for in 2023?

Those who process personal data of EU residents should comply with the requirements of the General Data Protection Regulation or GDPR. Non-compliance with GDPR may result in hefty fines and reputational losses. For example, last…

USA adequacy decision draft

General Data Protection Regulation (GDPR) provides additional rules regarding data transferring outside the European Union. Data controllers and processors may transfer data abroad to countries that are expected to have an adequate level of data…