Security and the GDPR

The General Data Protection Regulation (GDPR) will enter into force 25 May 2018. One important principle of the regulation is that personal data shall be handled with integrity and confidentiality to ensure appropriate security of the personal data. This means for example protection against unauthorized processing and against accidental loss as well as destruction or damage.

The GDPR has tougher sanctions for noncompliance, such as liability for damage suffered as well as fines. A ‘controller’, the one who determines the purposes and means of the processing of personal data, have a responsibility to implement appropriate organizational and technical measures  to make sure there is a level of security that is appropriate to the risk. The measures can for example include pseudonymization and encryption of personal data; the ability to restore the access and availability if there is an incident; regularly testing the effectiveness of the security measure; and the ability to ensure ongoing confidentiality, availability and resilience of processing systems and services. As well as securities measures, the controller shall also take data protection measures by design and by default. Data protection by design and by default means that privacy requirement shall be a top priority and implemented in all processes, products or services by the controller – also when new services etc are developed.

With hackers constantly trying to stay one step ahead, it is important for organizations to be prepared in case they are subject to a personal data breach. A personal data breach means that there is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. In case of a personal data breach, the controller have to notify the supervisory authority without due delay and when feasible within 72 hours. The notification shall include a description of the nature of the personal data breach; the contact point where the authority can collect more information about the breach; the likely consequences of the personal data breach and the proposed or taken measures to address the personal data breach. In some cases, when the breach is likely to result in a high risk to the rights and freedoms of natural persons , the data subject shall also be notified in a clear and plain language.

For further information, please contact Ida Häggström or Niels Dahl-Nielsen

News and Insights
Press release

Synch legal advisor in connection with IPO of Triboron International AB

03/04/2019

The first day of trading will be on 8 April 2019.

Press release

Synch signs as Nordic Legal Tech’s first Nordic corporate partner        

28/03/2019

We are very pleased to announce that Synch has joined as Nordic Legal Tech’s first Nordic corporate partner.

News

Do lawyers need to learn to code?

22/03/2019

Sergii Shcherbak, Head of Software Development, interviewed by Legal Tech Weekly.

News

Synch highly ranked in Chambers Europe and Global 2019

12/03/2019

Chambers & Partners’ rankings are based on extensive research work and, among other things, interviews with both clients and lawyers in the practice areas.

News

Armed Forces secret procurement shot down by experts

11/03/2019

Marianne Dragsten speaks about the Armed Forces’ purchase of drones from the United States.

News

Marianne Dragsten top ranked in Chambers 2019

08/03/2019

We are proud that Synch’s expert Marianne Dragsten is once again top-ranked in the category public procurement.