Every organisation processes personal data: information about suppliers, patients, clients, employees and many more besides. Within the European Union, this is subject to very strict requirements under the General Data Protection Regulation (GDPR), which also applies in the Netherlands (where it is called the AVG). Other countries have their own rules and systems to protect personal data.
It is very important for companies to be compliant with those rules, both in how they process the data and what security they implement.
Data processing
Data processing covers every imaginable activity involving personal data, including collecting, adapting or altering, retrieving, disclosing and destroying information about natural persons.
Important issues
Under the GDPR, organisations are required to protect personal data. One of the key factors is being able to prove that they have implemented appropriate measures. Depending on the organisation and what personal data is processed, various questions need to be answered, for example:
- What personal data does the organisation share? Is this limited to the organisation itself, or are the data transferred elsewhere too?
- Does the organisation maintain a data processing register?
- Should it have a data protection officer?
- Does the organisation process data with a high privacy risk, for example from systematic CCTV surveillance? If so, has it conducted a privacy impact assessment?
Your partner in privacy
Our privacy law team advise organisations, government agencies and institutions on matters concerning privacy and data protection. We help them to answer all these questions, and to decide on appropriate measures. We approach each situation from multiple angles, so that the organisation is fully compliant with all privacy and data protection requirements.
Presentations, courses and workshops
To be fully GDPR-compliant, organisations and their people need to be constantly aware of privacy and the associated risks. Our team can help by organising courses and workshops, either online or at your place of business. Every course and workshop is designed specifically to suit the organisation’s needs and requirements, including:
- workshops on specific topics, e.g. data breaches or data subjects’ rights
- awareness training for the entire workforce