{"id":17628,"date":"2018-04-10T14:28:05","date_gmt":"2018-04-10T17:28:05","guid":{"rendered":"https:\/\/www.navegg.com\/?p=17628"},"modified":"2018-04-11T12:33:23","modified_gmt":"2018-04-11T15:33:23","slug":"gdpr-everything-about-the-general-data-protection-regulation","status":"publish","type":"post","link":"https:\/\/www2.navegg.com\/en\/blog\/news\/gdpr-everything-about-the-general-data-protection-regulation\/","title":{"rendered":"GDPR: Everything about the General Data Protection Regulation"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">In 2016, with the objective of protecting the privacy of European user&#8217;s data, the General Data Protection Regulation (GDPR) was published &#8211; and comes into force on May 25th, 2018. This decision made by the European Union will impact the entire world, and companies need to be prepared. <\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">What is GDPR? <\/span><\/h2>\n<p><span style=\"font-weight: 400;\">GDPR is a set of rules that must be adopted by all companies which operate using data from European citizens. <\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Why was GDPR created? <\/span><\/h2>\n<p><span style=\"font-weight: 400;\">When it comes to users&#8217; personal data, there is a lot of concern about how it should be protected. To address this, the EU-GDPR was established to watch over the freedoms and rights of users. <\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Are these standards restricted to Europe? <\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Every business that operates in Europe with data collecting or data processing is required to conform to these standards. This would involve market giants &#8211; such as Amazon, Google, Facebook and Adobe \u2013 and since they operate in Europe, they will be required to comply with the standards. This will require that other companies also adopt GDPR standards. In other words, the standards that were born in Europe will become a reference for good practices around the globe. <\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">What is the role of anyone involved with GDPR?<\/span><\/h2>\n<table>\n<tbody>\n<tr>\n<td>\n<p style=\"text-align: center;\"><strong><span style=\"color: #0ca4de;\">Users<\/span><\/strong><\/p>\n<\/td>\n<td>\n<p style=\"text-align: center;\"><strong><span style=\"color: #0ca4de;\">Controller<\/span><\/strong><\/p>\n<\/td>\n<td>\n<p style=\"text-align: center;\"><strong><span style=\"color: #0ca4de;\">Data Processor<\/span><\/strong><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Users will have the right to access, edit and\/or delete their data.<\/span><\/td>\n<td><span style=\"font-weight: 400;\">If you work with data usage, this directly impacts your business. If you operate in Europe, you are obliged to follow such regulations and make them explicit in your privacy policy. If not, it is prudent to use such regulations as a guide to good practices.<\/span><\/td>\n<td><span style=\"font-weight: 400;\">As Data Processor, Navegg&#8217;s role is to follow the GDPR guidelines that apply. In addition, Navegg is a partner of its customers in this adaptation, offering information and technology.<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">In a tweet: what do the GDPR standards say? <\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The GDPR standards detail the rights of users, ensuring access to and the right to edit their data. <\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">What do the GDPR standards say? <\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The entire regulation contains 11 chapters which are available on the <\/span><strong><span style=\"color: #0ca4de;\"><a style=\"color: #0ca4de;\" href=\"https:\/\/gdpr-info.eu\/\">GDPR<\/a><\/span><\/strong><span style=\"font-weight: 400;\"> website. See below the main points of GDPR. <\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Provide the identity and contact details of the controller*; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Provide the contact details of the data protection company**, if any; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Detail the motives for data processing and the legal basis for this; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">List the recipients of the data (or categories of recipients), if any; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Cite the period for which the personal data will be stored or \u2013 if this is not possible \u2013 the criteria used to determine this period; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Explain the possible consequences for the lack of data provision; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Detail the source of the data, if it came from a public source and wasn&#8217;t collected directly from the user; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Grant the user the right to rectify their data; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Grant the user the right to withdraw consent to processing of their data at any time; <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Collecting sensitive data (revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data or sexual orientation data can only be collected from one person) only is permitted when processing is necessary for preventive or occupational medicine purposes, for the assessment of the working capacity of the employee, medical diagnosis, health or social care delivery, or treatment or the management of health and social care systems and services on the bases of Union or Member State law or by contract with a health professional. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The processing of a child&#8217;s data is legal when the child is at least 16 years old. In cases where the child is less than 16 years of age, processing shall be lawful only if and to the extent that consent is given or authorized by a parent or legal guardian of the child, provided that the child is not under the age of 13 years old. <\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">*Controller is the company that determines the purposes and means of data processing. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">**They are responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR requirements. <\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Navegg and GDPR <\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Navegg company has always been concerned with following good market practices and will incorporate GDPR as a reference. In fact, many of the points addressed by GDPR have already been adopted by Navegg. Check below to see which points have been adopted and how Navegg is adapting to those which hadn\u2019t already been adopted. <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">1. Provide the identity and contact details of the controller*; <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">2. Provide the contact details of the data protection company**, if any; <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">3. Detail the motives for data processing and the legal basis for this; <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">4. List the recipients of the data (or categories of recipients), if any; <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">5. Cite the period for which the data will be stored or \u2013 if this is not possible \u2013 the criteria used to determine this period; <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">6. Explain the possible consequences for the lack of data provision; <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">7. Detail the source of the data, if it came from a public source and wasn&#8217;t collected directly from the user; <\/span><\/p>\n<p><span style=\"font-weight: 400;\">From the very beginning, <strong><span style=\"color: #0ca4de;\"><a style=\"color: #0ca4de;\" href=\"http:\/\/bit.ly\/2JASN5q\">Navegg&#8217;s privacy policy<\/a><\/span><\/strong> included the information of points 1, 3, 4, 5, 6 and 7. The point 2 is in charge of our clients: they must quote us in their privacy policies.\u00a0<\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">8. Grant the user the right to rectify their data; <\/span><\/p>\n<p><span style=\"font-weight: 400;\">From the outset, Navegg made available the <strong><span style=\"color: #0ca4de;\"><a style=\"color: #0ca4de;\" href=\"http:\/\/bit.ly\/2GTFyPK\">Your Profile on the Navegg&#8217;s Network<\/a><\/span><\/strong> page so that users can see how they are being classified by Navegg and, for 9 years, the <strong><span style=\"color: #0ca4de;\"><a style=\"color: #0ca4de;\" href=\"http:\/\/bit.ly\/2GPWrXo\">Edit Your Profile<\/a><\/span><\/strong> page so that the information contained therein can be edited. <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">9. Grant the user the right to withdraw consent to processing of their personal data at any time; <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Just as Navegg provides a plug-in to include the opt-in on your site, from the outset, the <strong><span style=\"color: #0ca4de;\"><a style=\"color: #0ca4de;\" href=\"http:\/\/bit.ly\/2v4FDL3\">Opt-out page<\/a><\/span><\/strong> has been available to users who wish to opt-out from Navegg as well. <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">10. Collecting sensitive data (revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data or sexual orientation data can only be collected from one person only) is permitted when processing is necessary for preventive or occupational medicine purposes, for the assessment of the working capacity of the employee, medical diagnosis, health or social care delivery, or treatment or the management of health and social care systems and services on the, bases of Union or Member State law or by contract with a health professional. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">From the beginning of our operations, and as explained in our privacy policy, Navegg does not store or collect sensitive data. <\/span><\/p>\n<p style=\"padding-left: 30px;\"><span style=\"font-weight: 400; color: #999999;\">11. The processing of a child&#8217;s personal data is legal when the child is at least 16 years old. In cases where the child is less than 16 years of age, processing shall be lawful only if and to the extent that consent is given or authorized by a parent or legal guardian of the child, provided that the child is not under the age of 13 years old. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Navegg doesn&#8217;t collect personal data. Besides, there was a good practice in the market that allowed the collection of data from adolescents between 13 and 16 years old. However, since the decision of GDPR, this category was withdrawn and only those over 18 have their data collected by Navegg. Check out an example from Navegg&#8217;s dashboard demographic tab after such update.<\/span><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-17648\" src=\"https:\/\/www2.navegg.com\/nvgadm\/wp-content\/uploads\/2018\/04\/demografic-data-1.png\" alt=\"demografic-data\" width=\"1666\" height=\"429\" srcset=\"https:\/\/www2.navegg.com\/nvgadm\/wp-content\/uploads\/2018\/04\/demografic-data-1.png 1666w, https:\/\/www2.navegg.com\/nvgadm\/wp-content\/uploads\/2018\/04\/demografic-data-1-770x198.png 770w, https:\/\/www2.navegg.com\/nvgadm\/wp-content\/uploads\/2018\/04\/demografic-data-1-768x198.png 768w, https:\/\/www2.navegg.com\/nvgadm\/wp-content\/uploads\/2018\/04\/demografic-data-1-940x242.png 940w\" sizes=\"(max-width: 1666px) 100vw, 1666px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">How to create a standars-compliant data strategy?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Companies operating in Europe that do not comply with the regulations will be fined. The minimum penalty is as high as 10 million euros or 2% of overall turnover. On the other hand, companies that do not operate in Europe will not be fined. However, they put their companies&#8217; reputation in risk. In fact, regardless of where the company operates, a stain on reputation must be the concern of all. This may have a much higher price that the fine itself.<\/span><\/p>\n<p>Navegg completes 10 years of operation and concern with the market best practices. Tha&#8217;s why, it is the ideal partner to create a stands-compliant data strategy and help you understand and adapt to market news.<\/p>\n<p>If you have any doubt about GDPR, please, count on us and wite to <strong><span style=\"color: #0ca4de;\"><a style=\"color: #0ca4de;\" href=\"mailto:doubtsgdpr@navegg.com\">doubtsgdpr@navegg.com\u00a0<\/a><\/span><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Everything you need to know about GDPR (General Data Protection Regulation). Check out!<\/p>\n","protected":false},"author":57,"featured_media":17630,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"amp_status":"","_links_to":"","_links_to_target":""},"categories":[290],"tags":[235,429,430],"_links":{"self":[{"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/posts\/17628\/"}],"collection":[{"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/posts\/"}],"about":[{"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/types\/post\/"}],"author":[{"embeddable":true,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/users\/57\/"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/comments\/?post=17628"}],"version-history":[{"count":3,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/posts\/17628\/revisions\/"}],"predecessor-version":[{"id":17649,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/posts\/17628\/revisions\/17649\/"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/media\/17630\/"}],"wp:attachment":[{"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/media\/?parent=17628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/categories\/?post=17628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.navegg.com\/en\/wp-json\/wp\/v2\/tags\/?post=17628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}