ADVERTISEMENT

EU's tough new data protection rules

The EU's General Data Protection Regulation (GDPR), which takes effect on May 25, will simplify rules by replacing the current patchwork of national laws and creating a Europe-wide regulator to enforce them.

Facebook chief Mark Zuckerberg told US lawmakers on Tuesday the company plans to fall in line with GDPR rules as it seeks to rebuild its reputation after the Cambridge Analytica data breach.

US-British political research firm Cambridge Analytica plundered detailed personal data on 87 million users to be used in the 2016 US presidential election.

Here is a run-down of the key elements of the GDPR:

ADVERTISEMENT

Clear information

Companies gathering and processing personal data will have to tell their users who they are, what information they are using and why, how long it will be stored and who will have access to it.

The EU says the information must be "clear and understandable" and users have the right to access the personal data an organisation has on file about them.

Consent

Companies must ask for users' consent to process their data and clearly indicate how they will use it. The rules say this consent must be "an unambiguous indication of your wishes and be provided by an affirmative action.

ADVERTISEMENT

"Companies won't be able to hide behind long legalistic terms and conditions that you never read," the EU says in official guidance to citizens.

Users will have the right to opt out of direct marketing using their data, and companies must give extra protection to sensitive information on health, race, religion, sexual orientation and political beliefs.

Portability

Customers will have the right to access their data and have it transferred to another company, for example when they change from one cloud data storage provider to another.

The EU says this will make it easier for people to change providers for various online services and help new start-ups compete with existing social networks.

ADVERTISEMENT

Right to be forgotten

Customers will have the right to ask a company to delete their data if there is no legitimate reason for it to be kept.

There have been concerns this could be abused by public figures such as politicians to hide embarrassing incidents, but the EU insists it is "about protecting the privacy of individuals, not about erasing past events or restricting freedom of the press".

Timely reporting

Companies must inform users of data breaches "without undue delay" and tell authorities within 72 hours.

ADVERTISEMENT

Big fines

The GDPR includes a range of tools to enforce the new rules and punish companies for breaches. These include warnings and reprimands and stiff fines for more serious offences -- up to four percent of a company's worldwide turnover.

Enhance Your Pulse News Experience!

Get rewards worth up to $20 when selected to participate in our exclusive focus group. Your input will help us to make informed decisions that align with your needs and preferences.

I've got feedback!

JOIN OUR PULSE COMMUNITY!

Unblock notifications in browser settings.
ADVERTISEMENT

Eyewitness? Submit your stories now via social or:

Email: eyewitness@pulse.ng

Recommended articles

No Nigerian is denied access, we aim for friendship between countries - CGCC

No Nigerian is denied access, we aim for friendship between countries - CGCC

Reno Omokri labels Abuja Chinese Supermarket 'racist', demands Wike's action

Reno Omokri labels Abuja Chinese Supermarket 'racist', demands Wike's action

1,500 Ogun residents receive free surgeries, 80k students get ₦50k each

1,500 Ogun residents receive free surgeries, 80k students get ₦50k each

NERC shifts Enugu electricity market oversight to State commission

NERC shifts Enugu electricity market oversight to State commission

Gov Diri & his deputy, Ewhrudjakpo cleared of certificate forgery allegations

Gov Diri & his deputy, Ewhrudjakpo cleared of certificate forgery allegations

TCN towers vandalised, disrupting power supply to Gombe, Yola, Jalingo

TCN towers vandalised, disrupting power supply to Gombe, Yola, Jalingo

10 killed as 2 Malaysia military helicopters collide during training

10 killed as 2 Malaysia military helicopters collide during training

Joint Committee denies alleged relocation of equipment from NCAT Zaria

Joint Committee denies alleged relocation of equipment from NCAT Zaria

Adelabu says FG plans to increase power generation from 4k to 6k megawatts

Adelabu says FG plans to increase power generation from 4k to 6k megawatts

ADVERTISEMENT
ADVERTISEMENT