GDPR & GDPR Assessment
The European Union General Data Protection Regulation (GDPR) comes into force on 25th May 2018. All organisations that process the Personally Identifiable information of EU residents will be required to abide by the provisions of the directive. Your company should conduct a GDPR preparation assessment as soon as possible.
It is essential to understand that GDPR applies to any company with clients in the EU - irrespective of whether your company is based in the EU or elsewhere.
Some of the key requirements to note are as follows:
- If your business is not in the EU, you still have to comply with the Regulation.
- The definition of personal data is broader, bringing more data into the regulated perimeter.
- Consent will be necessary to process children’s data.
- Changes to the rules for obtaining valid consent.
- The appointment of a data protection officer (DPO) will be mandatory for certain companies.
- The introduction of mandatory privacy risk impact assessments.
- New data breach notification requirements.
- The right to be forgotten.
- The international transfer of data.
- Data processor responsibilities.
- Data Portability.
- Privacy by Design.
- One stop shop for compliance.






