GDPR compliance refers to your privacy policy’s compliance with the General Data Protection Regulation (EU) 2016/679. Let’s take a look at what it means for the privacy policy of your business.

A privacy policy for your website or business is required by law. Its purpose is to clearly explain what data is collected, how it’s collected, used, and stored, and what rights users have over it. So what does this have to do with GDPR?

General Data Protection Regulation: what is it?

GDPR is an acronym for General Data Protection Regulation, a regulation on data, in EU law, that aims to protect the privacy of the personal data and information relating to each individual citizen of the European Union and the European Economic Area.

The key principles of GDPR compliance

There are seven key principles for how data is to be protected under the GDPR:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

Let’s take a closer look at each.

Lawfulness, fairness and transparency

Personal data of the individual is required to be processed in a lawful, fair and transparent manner.

Purpose limitation

Personal data is only to be collected for explicit, specific and legitimate purposes. There is to be no further processing of the collected data for any incompatible uses beyond its initial purpose. Archiving for public interest, scientific or historical research, or statistical purposes is not considered incompatible.

Data minimisation

Personal data is to be relevant, sufficient, and limited to the purpose it is being processed for.

Accuracy

Personal data needs to be as accurate and relevant as possible, and any incorrect data should be deleted or rectified without delay.

Storage limitation

Personal data is to be stored in a way that identifies data subjects for the least amount of time necessary. Data may be held for longer where it is used solely for archiving in the public interest, or for scientific, historical, or statistical purposes, as long as it’s stored in a way that safeguards individuals’ rights and freedoms under the GDPR.

Integrity and confidentiality (security)

Personal data must be processed in a way that safeguards its security, including protection against unlawful processing, accidental loss, destruction, or damage.

Accountability

Whoever is responsible for safeguarding the personal data must be able to demonstrate compliance with the six principles above.

These seven principles are the backbone of the GDPR and represent good data practice generally. Failure to comply may incur a significant fine.

The rights of the individual

The GDPR sets out the following rights for individuals:

  1. The right to be informed
  2. The right of access
  3. The right to rectification
  4. The right to erasure
  5. The right to restrict processing
  6. The right to data portability
  7. The right to object
  8. Rights related to automated decision making and profiling

Let’s look at each in turn.

1. The right to be informed

This means providing your users with information about how you use the personal data you collect from them, how long you retain it, and who it’s shared with.

Table listing the privacy information you should supply to your users under the GDPR

2. The right of access

Also known as subject access: the right of individuals to access their personal data if they choose. Requests must be in written form, and in most cases can’t be charged for.

3. The right to rectification

Individuals have the right to have incorrect information corrected as soon as possible.

4. The right to erasure

Also called the right to be forgotten: individuals have the right to have their personal data erased under certain circumstances.

5. The right to restrict processing

Individuals can have their personal data restricted or suppressed in certain circumstances, limiting how an organisation can use it.

6. The right to data portability

Individuals have the right to obtain, use, and move their personal data to another environment for reuse. Data must be transferred in a safe, secure manner.

7. The right to object

Individuals can object to the processing of their personal data in certain circumstances, including stopping their data being used for direct marketing.

8. Rights to automated decision making and profiling

There must be a lawful basis for using an individual’s personal data for profiling or automated decision making. Individuals must be informed of how their data is used, and linked to the privacy policy if their data was obtained indirectly.

Detect, secure, investigate, and notify

Your policy should include a clause outlining your ability to detect and protect against data breaches, investigate them, and report them to the relevant data subject or supervisory authority within 72 hours.

How does the GDPR apply to you?

So now you understand the importance of a GDPR-compliant privacy policy, how does this affect you?

The GDPR was put in place to protect the rights of EU citizens, but its principles apply to any company, organisation, or website, whether inside or outside the EU, that obtains personal data from residents within the EU. This is known as the extra-territorial effect, and it’s made explicit in Article 3 of the GDPR.

Article 3 of the GDPR: territorial scope

Benefits of GDPR compliance

The benefits of GDPR compliance and having a GDPR-compliant privacy policy include greater customer confidence and trust, and staying aligned with technological and regulatory expectations.

Are you GDPR compliant? Generate your GDPR-compliant privacy policy using our privacy policy generator.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.