ARTICLE
17 April 2018

Cybersecurity, Privacy And Data Protection Alert: General Data Protection Regulation (GDPR)

PD
Phelps Dunbar LLP

Contributor

Phelps is a full-service Am Law 200 law firm, blending valuable traditions and progressive ideas to foster a culture of collaboration among our lawyers in Alabama, Florida, Louisiana, Mississippi, North Carolina, Tennessee, Texas, and London. The firm’s lawyers handle a broad range of sophisticated business needs regionally, nationally, and internationally.
Effective May 25, 2018, the enforcement provisions of the European Union's General Data Protection Regulation (GDPR) take effect.
United States Privacy
Walt Green’s articles from Phelps Dunbar LLP are most popular:
  • with readers working within the Healthcare and Law Firm industries

Effective May 25, 2018, the enforcement provisions of the European Union's General Data Protection Regulation (GDPR) take effect. Arguably, the GDPR is the most sweeping piece of data protection and privacy legislation to come into force.

This regulation applies both to companies located in the European Union (EU) that process personal data of its citizens and companies located outside the EU that process personal data of EU citizens under most conditions. As a result, regardless of location, companies should assume that the GDPR applies to their business if it uses or stores data from EU citizens.

While it is expected that all companies will comply with the provisions of the GDPR, there are exceptions to the most stringent requirements for companies with less than 250 employees. However, these exceptions are specific in nature and careful consideration must be given before a company decides whether these exceptions are applicable.

In terms of businesses in the United States, the United States Department of Commerce and European Commission has established a mechanism to allow for a self-certification process for transferring personal data from the EU to the United States.

The potential fines for not complying with GDPR are significant; maximum penalties are 4% of a company's global revenue or 20 million euros, whichever amount is greater.

Importantly, even if a company utilizes third party vendors to process personal data from EU citizens, a company should ensure that the vendor is GDPR compliant. One may assume that if a vendor is not GDPR compliant your company is not GDPR compliant.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More