The motto of 2018: GDPR
2017. October 04.

[vc_row][vc_column][vc_column_text]In our latest Newsletter we shall summarize what tasks will GDPR mean and how to prepare for its coming into effect.

What is GDPR?

GDPR (General Data Protection Regulation) is the new European data protection regulation, which will be valid in all EU from 25 May 2018. It will replace the currently applicable privacy policy, which has been in force since 1995 (Directive 95/46/EC), unifying the Member States’ data protection regulations.

However, in addition to complying with the text of the new regulation, the relevant national legislation shall also be followed with attention. The amendment to the relevant legislation has been submitted to the Hungarian Parliament.

Who does GPDR apply to?

Virtually it applies to all companies processing the personal data in a filing system (even if the company providing services is not established in the EU but its service is also available to persons staying in the EU).
So even if the company has only one employee – as a controller – GDPR shall be applicable to it. The scale will be widened if, for example, the company accepts job applications, concludes contracts, operates websites (or even a web shop), draws on payroll or accounting services, etc.

What are the 3 important features of GDPR?

How to prepare for the GDPR’s entry into force and thereafter?

This process can be divided into three main sections:

1) Exploration: This section starts with preparation and planning (definition of the scope, preparation of the project plan and scheduling).

2) Management: When we surveyed the current condition and see the differences required to comply with GDPR, it follows, inter alia:

– revision of the current processes;

– transformation of data protection, empowerment of data privacy and IT systems;

– making data management records and various internal regulations;

– creation of an action plan related to data protection incidents

3) Protection Development of security processes and monitoring related to the detection, prevention and management of the risks of data management and data protection incidents.

What can be obtained from the preparation?

If at first glance perhaps only the serious challenge and magnitude of the required resources are striking, we should not forget that surely we can count on the following advantages in the preparation for the application of GDPR.

Of the three types of expertise necessary to manage GDPR you have the knowledge relevant to the organization/processes for which we are happy to provide information security, legal expertise and experience.

If you have any questions relating to the above-mentioned issues, our staff is happy to help.

 

[/vc_column_text][/vc_column][/vc_row][vc_row][vc_column width=”1/3″][vc_column_text]Ferenc Smohay
Partner, Risk & Compliance Services
ferenc.smohay@abt.hu[/vc_column_text][/vc_column][vc_column width=”1/3″][vc_column_text]dr. Péter Czifra
Czifra & Neményi Law Office
peter.czifra@abt.hu[/vc_column_text][/vc_column][vc_column width=”1/3″][vc_column_text]József Láng
tax expert, manager
jozsef.lang@abt.hu[/vc_column_text][/vc_column][/vc_row]

The above summary is provided for information purposes only. We recommend that you consult our experts before making any decision based on this information.