Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 1

Special GDPR

Governance Enforcement Prosecution Resilience

Right to Privacy included in the Creation of Creation of European Data Protection Supervisor ( The DPAs decide whether or not to Board system (EDPB) with a
1950 European Convention on Human European Data EDPS) to monitor and ensure the protection of bring a GDPR related prosecution in the Supervisor (EDPS) and officers
Rights. It was updated in 1995 by the Protection Board personal data and privacy when EU institutions and Courts; it will usually notify the (DPO) with each institution and
European Data Protection Directive. (EDPB) to bodies process the personal information of individual concerned in writing of its bodies
Lately, passed in 2018, it was updated by promote individuals. It also advises EU institutions and intention to do so.  This would usually
Govern the General Data Protection Regulation cooperation bodies on all matters relating to the processing of be followed by a formal summons to
ment (GDPR). These represent a minimum and between the EU’s
data protection
personal data Court for trial.
some member-state can issue additional
elements. authorities. Each Institution needs to appoint a Data Protection Fines:
Officer (DPO) ensuring that the provisions of the The less severe fines could result in a
Enforcement regulation are correctly applied within the EU fine of up to €10 million, or 2% of
delegated to institutions and bodies global turnover
Member-state
Data Protection The more severe fines could result in a
Banks are considered like Healthcare to Authorities ( Banks need to appoint a Personal Data Controller fine of up to €20 million, or 4% of global
be in ‘special category data’ and a data DPA: CNIL in FR, and ensure that turnover.
processor. AEPD in ES) customer personal data is always under control.
Member states may add additional fines
Banks As processor they need to abide to 7 It is required to keeping track of who has access to and liabilities. For Instance, in France,
protection and accountability principles their customers' data, when and how the data is personal liabilities and criminal penalty
(Article 5.1-2). processed and protected. can be added (up to 5 years of prison
Banks need to show evidence of use of state-of-the- and €300,000 fine)
More on GDPR in financial services indus art technology to ensure the best possible data
try
protection.
.
A breach must be notified to the Companies can opt to appoint a Data Protection Major fines put on corporations
member-state supervisory authority Officer (DPO) unless a Member-state requires their
(DPA) without undue delay, a scrutiny appointment. Their task is to advice on carrying out Name and shame companies on medi
of not more than 72 hours may be data protection impact assessments, and in creating a, websites …
Private given if the company seen defined as a and keeping records of processing activities in an
Non-compliance leads to huge fines
data controller. organization.

Controllers are required to keep a Authorities enjoy investigative and corrective powers Provide Handbooks and
record of all data breaches and permit including the power to undertake on-site data Checklist for companies
audits of the record by the DPA protection audits and the power to issue public
warnings, reprimands. Offer the option to appoint a DPO

You might also like