GDPR – four letters that have been a major topic of discussion for businesses since the end of 2016. But, what is it exactly? Schellman & Company, one of the top leaders in the U.S. compliance industry, wrote a comprehensive blog post dedicated to demystifying this topic.
According to their post, the General Data Protection Regulation has been in effect since May 25, 2018 and was designed to uphold personal information rights of individuals and further unify the member states of the European Union (EU) in their endeavor to manage and protect data. So, the goal is to protect the information of EU citizens. Seems pretty simple, right? Well, not exactly. How GDPR affects U.S.-based businesses is an even bigger conversation and deserves further exploration in order to understand the rules for compliance.
The United States is directly affected by GDPR because this privacy law is applicable to any business in the world that works within the European market. The data breach notification requirements are more stringent and will require that most U.S. companies amend their policies in order to be compliant.
Naturally, the next question is how a US-based business becomes compliant? It is recommended to visit an official site, such as eugdpr.org, to learn about the process to become GDPR compliant. Since most of us are looking for straightforward points on how to do anything these days, Maureen Data Systems (MDS) summarizes GDPR compliance by asking these five questions:
Penalties and fines associated with this regulation can be in excess of 20 million Euro or 4% of your company’s net income. So, take action! The sooner you invest in these compliance measures the better for your clients – and your business!
Resources:
https://hub.schellman.com/blog/gdpr-what-it-means-for-us-based-companies-2
https://www.mdsny.com/how-to-meet-gdpr-in-5-steps/