Security and the GDPR

The General Data Protection Regulation (GDPR) will enter into force 25 May 2018. One important principle of the regulation is that personal data shall be handled with integrity and confidentiality to ensure appropriate security of the personal data. This means for example protection against unauthorized processing and against accidental loss as well as destruction or damage.

The GDPR has tougher sanctions for noncompliance, such as liability for damage suffered as well as fines. A ‘controller’, the one who determines the purposes and means of the processing of personal data, have a responsibility to implement appropriate organizational and technical measures  to make sure there is a level of security that is appropriate to the risk. The measures can for example include pseudonymization and encryption of personal data; the ability to restore the access and availability if there is an incident; regularly testing the effectiveness of the security measure; and the ability to ensure ongoing confidentiality, availability and resilience of processing systems and services. As well as securities measures, the controller shall also take data protection measures by design and by default. Data protection by design and by default means that privacy requirement shall be a top priority and implemented in all processes, products or services by the controller – also when new services etc are developed.

With hackers constantly trying to stay one step ahead, it is important for organizations to be prepared in case they are subject to a personal data breach. A personal data breach means that there is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. In case of a personal data breach, the controller have to notify the supervisory authority without due delay and when feasible within 72 hours. The notification shall include a description of the nature of the personal data breach; the contact point where the authority can collect more information about the breach; the likely consequences of the personal data breach and the proposed or taken measures to address the personal data breach. In some cases, when the breach is likely to result in a high risk to the rights and freedoms of natural persons , the data subject shall also be notified in a clear and plain language.

For further information, please contact Ida Häggström or Niels Dahl-Nielsen

News and Insights
Blog Posts

ANONYMISATION AND PSEUDONYMISATION OF PERSONAL DATA

29/11/2019

This blog post is written by Erik Myrberg, lawyer at Synch Recital 26 of the GDPR clarifies that the principles of data protection should not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject […]

Press release

Synch has acted as legal advisor to Zington AB

22/11/2019

Synch has acted as legal advisor to Claremont AB (under name change to Zington AB) with trademark strategy work in connection with its expansion plans to becoming a global brand.

Blog Posts

ABOUT THE NEW PROPOSITION ON GENERAL ADVICE FOR CONSUMER CREDITS

14/11/2019

The rules on how consumer credits can be granted and marketed are spread out in several different acts and regulations.

Blog Posts

Strong customer authentication – about the new rules on electronic payments

08/11/2019

Strong customer authentication (SCA) means that a customer must verify his/her identity with two from each other independent factors when using electronic payment methods, for example when using a credit card. The rules, which are based on EU legislation, aims to increase the security of electronic payments and combat fraud. Generally speaking, the legislation does […]

Press release

3 SYNCH LAWYERS RANKED IN Who’s Who Legal

08/11/2019

Since 1996 Who’s Who Legal has identified the foremost legal practitioners in 34 areas of business law. Over 16,000 of the world’s leading private practice lawyers in over 100 countries are featured

Press release

SYNCH HAS ACTED LEGAL ADVISOR TO SKALL STUDIO IN CONNECTION WITH THE TRANSACTION

22/10/2019

Synch has assisted SKALL STUDIO with the transaction. Tobias Kisum has led the transaction.