aternio uses cookies to ensure the functioning of our website, to enable the sharing of our articles on social media and to enable the collection analytical data on the use of our website. aternio utilizes services provided for by third parties, when enabling these cookies your data will be shared with the respective third party. Please consult our Cookie Policy for more information.

Accept Set my preferences

Set my preferences

Essential cookies Always turned on
Functional cookies
Analytical cookies
Marketing cookies
Save and accept

Essential cookies

Essential cookies are necessary for the website to function, and to facilitate communication over the internet. Without these cookies, our website will not function in the way we intend it to, or we will not be able to provide you with the services and function you request. Therefore it is not possible to decline the use of these cookies on our website.

In case you delete or block these cookies by means of your browser settings, our website or parts thereof will not function as intended.

Back to overview

Functional cookies

Functional cookies are used to provide additional functionalities and services on our website, that are not essential to the base function of our website. On our website, you can share certain articles via social media. Our website makes use of cookies provided by third parties. Aternio has no control over these cookies and is not responsible for the way these third party providers collect and handle your personal data.

When refusing these cookies, certain parts of the website might not function as intended.

Back to overview

Analytical cookies

When you visit our website, cookies can be placed to collect information on the use of our website. This information allows the assessment and improvement of the functioning of the website. The collected information is made anonymous as much as possible. Your IP-address is specifically not provided. Our website makes use of Google Analytics provided for by the American company Google. aternio does not control and is therefore not responsible for the way Google collects and handles your personal data.

When refusing these cookies, your visit to our website will not be taken into account in the statistics of our website.

Back to overview

Marketing cookies

When you visit our website, third party (LinkedIn and Facebook) cookies can be placed on your device. These cookies, provided for by the respective third party, are used to set up a personal profile based on your behaviour. The third parties will, on the basis of this profile, provide you with relevant advertisements on other websites. aternio does not control these cookies and is therefore not responsible for the way these third parties handle your personal data. You need to consult the relevant third party website for more information about these cookies.

When refusing these cookies, the respective third party will not be able to follow you on our website.

Back to overview
About services identity partners offices
News finance tax legal profit non-profit private individuals seminars
Jobs culture job openings hiring process
find us
en
nl
Aternio finance Alg Voorw NL 01 2023
Alg Voorw legal NL 01 2023
Privacy policy
Legal information
Disclaimer
en
nl
aternio
news
Download PDF
Share
Email
language error?
Aternio 112 rood
GDPR, the clock will
GDPR, the clock will
GDPR, the clock will still be ticking
still be ticking

we make the road

GDPR, the clock will still be ticking after 25 May 2018.
after 25 May 2018.

GDPR, the clock will still be ticking after 25 May 2018.

finance, tax and legal

GDPR, the clock will still be ticking after 25 May 2018.

news
finance,
26 July 2018

For many companies, GDPR is a word they don't know or prefer not to hear. However, every company will need to be GDPR compliant as of 25 May 2018. Therefore, it is important that you are aware of the obligations and the sanctions that the GDPR contains.

GDPR, what is it and why?

GDPR is the abbreviation for “General Data Protection Regulation”. It concerns a European regulation that aims to protect the personal data of natural persons. The GDPR was established because of the digitalisation of our world. Protection of personal data is very important in this matter. Companies like Facebook and Google process a lot of personal data, but they are not alone. We can be quite sure that almost every company does this.

The second reason why the European regulation was established is for uniformity. Before the regulation there was already a European guideline. This was converted into national law in every member state, with too many differences between the member states. For this reason the European Union chose to issue a regulation. This regulation is applicable immediately in every member state.

Scope of the GDPR

The regulation is applicable as soon as the personal data of a natural person is electronically processed or is arranged in order (alphabetically, chronologically). Processing should be interpreted broadly. Examples are ordering, collecting, storing and processing.

The regulation also provides some exceptions to the scope of application. The processing of personal data in the context of activities which are outside the scope of Union Law, or activities carried out by a natural person in the course of purely personal or household activity, do not fall within the scope of application. Also, the processing by a member state in the context of the policy for border control, asylum and immigration is not targeted by the regulation.

Regarding the territorial authority, this extends beyond the EU. First of all, the controllers and processors who are in the EU must comply with the regulation. The regulation also has an impact on the controllers and processors outside the EU. They must always comply with the regulation to the extent that they process personal data of people who are in the Union.

More rights for the data subjects

The big aim of the regulation is to provide more protection to the natural person regarding his personal data. This protection is associated with providing information, exercising control as well as granting rights.

The data subject, whose personal data is processed, must obtain transparency. This means that the data subject must be informed in good, clear and understandable language. The regulation itself provides explicitly what must be included in this information. (Art. 13 and 14 GDPR)

In addition, the regulation foresees that the data subject has more control over the processing of his personal data. This is achieved by the rights which are granted to the data subject. These rights are: transparency, rectification, inspection, deletion, limitation, objection, free transfer and automated decision-making. By means of being able to exercise these rights, the data subject has the possibility to control the processing of his personal data and possibly taking action.

If all this is not enough, the data subject can lodge a complaint with a supervisory authority or apply to the courts. For Belgium the supervisory authority is Privacy Commission.

Obligations arising from the GDPR

In addition to the protection of personal data of the data subject, there are more and more stringent obligations for the controller (and processor). First the controller must be able to show that they are GDPR compliant. This means that the burden of proof regarding the compliance of the obligations rests with the controller. In order to show this, the controller must establish an internal policy.

This internal policy ensures that the other obligations of the regulation are complied with. These other obligations are the guarantees of the rights, procedures regarding data leaks and the exercise of rights by the people concerned, establishing a register of processing activities, privacy declarations, making contracts conform (employees, customers, suppliers, ... ), improving the security of the IT systems, etc.

Is this not going too far?

Despite the best intentions of the regulation, this is all very far reaching. Everybody agrees that the protection of personal data is essential in a digital world. However, the regulation has also dragged small companies into its gigantic web of obligations. Think about the baker just around the corner, who processes your personal data with the objective of preparing your order or binging it to your home. He is also subject to the regulation.

The fact that the regulation provides for proportionality, is only a meagre consolation. The regulation certainly allows that the obligations only have to be complied with in proportion to the possibilities of the company. However, compliance remains a difficult feat for many companies.

Conclusion

The GDPR applies to almost everyone. You cannot afford to ignore the regulation as the sanctions are not small. The administrative fines can amount to EUR 20,000,000 or 4% of the global revenue of the previous fiscal period if this is higher. The Privacy Commission will perform the audits using investigation and prosecution powers. The risk of an audit increases indeed if a data subject files a complaint.

If you so wish, aternio can assist you in making your company GDPR compliant.

Follow aternio on LinkedIn for more finance and legal news.

Nesrine Jelti

info@atern.io
Primeglobal logo
aternio antwerpen
Mechelsesteenweg 180
2018 Antwerp
+32 3 454 30 00
antwerpen.finance@atern.io antwerpen.legal@atern.io
aternio hamme
Zwaarveld 41D
9220 Hamme
+32 52 478 241
hamme.finance@atern.io hamme.legal@atern.io
aternio brussel
Terhulpensesteenweg 185
1170 Brussels
+32 2 709 20 20
brussels.finance@atern.io brussels.legal@atern.io
© aternio 2023
Aternio finance Alg Voorw NL 01 2023
Alg Voorw legal NL 01 2023
Privacy policy
Legal information
Disclaimer
we make the road
Primeglobal logo