Everything You Wanted to Know about GDPR (But Were Afraid to Ask)

Written By: Cudy

23rd April 2023

Everything You Wanted to Know about GDPR (But Were Afraid to Ask)

This is a quick introduction to the General Data Protection Regulation (GDPR) which comes into force on 25 May 2018. The new regulation replaces the current Data Protection Act 1998.

It affects any organization that processes personal data about individuals or offers goods or services to them.

Why Does GDPR Matter?

Under the current Data Protection Act, fines for non-compliance can be up to £500,000. The maximum fine under GDPR will be €20 million (£17 million) or 4% of global turnover, whichever is greater.

In addition, they can fine organizations up to €10 million (£8.8 million) or 2% of global turnover for not having their records in order (for example, failing to keep proper employee records).

grayscale photo of person using MacBook
Photo by Sergey Zolkin on Unsplash.

What Has Changed?

GDPR sets out several key changes that make it easier for businesses and organizations to comply with data protection laws and principles:

The GDPR will replace the Data Protection Act 1998. It applies to all companies processing the personal data of EU citizens, regardless of where the company is based.

GDPR is technology-neutral. This means that it will apply to any business that uses technology, from apps and websites to CCTV systems and databases.

GDPR clarifies that data protection laws apply not just to ‘personal data' but also to ‘special' categories of data, such as genetic or biometric data.

It also clarifies the definition of ‘sensitive personal data’, which can be about criminal offenses or convictions.

For example, names and addresses are likely to be sensitive personal data because they can identify an individual.

Rules Relating to Children Under 16-Year-Old

As well as being more explicit about the definition of sensitive personal data, GDPR has strengthened provisions relating to children under 16 years old, particularly about online services such as social media platforms and online games.

In addition, it sets out stricter rules on consent for processing special categories of personal data or sensitive personal data. These rules include:

  • Individuals must give unambiguous consent before organizations can process their sensitive personal information (for example, ticking a box). This includes information relating to criminal convictions and offenses.
  • The organization must clarify what the individual is consenting to, for example, whether they are consenting to market materials or an app.
  • Individuals must be able to withdraw their consent at any time.
  • Wherever possible, the organization should use ‘granular’ opt-in consent mechanisms (for example, asking people to tick a box if they want to receive marketing materials from the organization).
  • Where it is not possible to use granular opt-in, then organizations must explain why it is not possible in their privacy notice. For example, they may need to provide an ‘opt-out’ option for those who do not want their data processed for marketing. They must also explain how individuals can withdraw their consent at any time.

Getting Consent from Individuals

The GDPR will introduce more stringent rules on obtaining consent from individuals before processing their personal data. In particular:

  • It will clarify that consent must be freely given, specific, informed, and unambiguous. They cannot assume it from silence, pre-ticked boxes, or inactivity.
  • It will also require organizations to keep evidence of consent (for example, by asking individuals to sign a form).

The GDPR is likely to have a significant impact on how organizations interact with their customers and business partners.

For example, if an organization has an app that requires location data for the app to work, then it may need to get explicit consent from users before collecting and using this data.

The same would apply if an organization wanted to send marketing materials via email or SMS text messages.

Organizations must get clear consent from individuals before collecting any sensitive personal data or special categories of personal data (such as criminal convictions).

They must also make sure that the individual understands what they are consenting to (for example whether they are agreeing to receive marketing materials).

person using laptop
Photo by Thomas Lefebvre on Unsplash.

Transparency about Information Usage

Organisations must provide transparent information about why they need the information and how it will be used. This includes:

  • The organizations that might use the data (for example, direct marketing companies or debt collection agencies). The type of processing that will take place (for example, using the data to send marketing materials or to conduct a credit check).
  • Individuals must be able to withdraw their consent.

The Right to be 'Forgotten'

The GDPR introduces a ‘right to be forgotten'. This gives individuals the right to have their personal data deleted in certain circumstances, for example, if it is no longer necessary for the purpose it was collected.

The GDPR also clarifies that individuals may ask an organization to transfer their personal data from one service provider to another.

Organizations must have a lawful basis for processing personal data. The most common lawful basis is ‘consent’, but there are other grounds for processing too, such as ‘contract’ and ‘legitimate interests. Organizations will need to make sure they have evidence of consent before collecting and using personal data, such as

  • Recording how and when individuals gave consent.
  • Where appropriate, keep evidence of consent in an accessible format (for example, by asking people to sign a form).
  • Organizations must keep accurate records of all personal data they hold. They must also make sure that the records are easily accessible and readable.

This will help them identify any personal data that they no longer need to process, or that is incorrect.

Read similar articles about Privacy Policy and other related internet security articles on the Cudy Blog page!


Written by

Cudy

Cudy is an online marketplace for real-time learning where students can achieve mastery over their subjects by learning live from educators who are passionate about providing the best learning experience for their students.

More stories

Education, Online Learning

Apakah kuliah online menurutmu itu efektif atau hanya sekadar formalitas saja?
Di masa modern kini, masyarakat banyak yang terpaksa melaksanakan kegiatan secara jarak jauh. Di antaranya adalah kuliah di rumah. Konsep kuliah online di rumah sudah banyak diperkenalkan oleh berbagai universitas ternama di dunia. Banyak pihak yang mempercayai bahwa kuliah online sangatlah efektif untuk mengembangkan potensi peserta didiknya. Dalam kuliah online di rumah, mata kuliah diadakan […]

Cudy

25th April 2023

Language, Online Learning

Belajar Bahasa Asing Daring
Belajar bahasa asing memang sangat penting untuk meningkatkan kualitas diri, dan di masa depan akan sangat membantu kita dalam memasuki dunia kerja. Selain itu bahasa asing juga bisa membantu kita dalam melakukan kegiatan komunikasi baik secara online maupun offline. Contohnya, dengan memiliki kemampuan belajar bahasa Inggris dan Mandarin yang baik, kita bisa memilih tempat kerja […]

Cudy

25th April 2023

EdTech, Online Learning, Tutor

How can an online tutor get international students?
Today's competitive world has opened new opportunities for Indians and their professional skills. Many Indians are working abroad in multinational companies. In this article, we will take a look at how Indians can get teaching opportunities and how to find international students to start your tutoring career. How can an Indian online tutor get international […]

Cudy

25th April 2023

EdTech, Online Learning, Online Tuition

What is the best site for accounting tutoring?
Accounting tutoring has become a popular service for students who want to learn accounting. Accounting is the analysis, acknowledgement or provision of assurance about economic information that helps administrators, investors, tax professionals, and others make judgments about allocating resources. The managerial accounting cycle is the fundamental process that describes the activities associated with recording, reporting […]

Cudy

25th April 2023

Subscribe to our blog