Support Technical

+351 255 926 773*

Contact us

+351 964 269 941**

Contact us

geral@activelink.pt

Send us a message

Remote Support

Instructions for starting an order:
1. Contact Activelink;
2. Follow the technician's instructions.

Learn the 10 commandments of the General Data Protection RegulationPublished by On


This new legal framework has the main objective of guaranteeing the privacy and integrity of EU consumers' data and defines that all citizens have the right to know how their data is being used, as well as the right to have their data completely erased if so requested.

Find out what will change with the entry into force of this new regulation and understand in which areas you should act to ensure your company is in compliance:

  1. Fines can reach 20 million euros or 4% of global turnover for companies in non-compliance.
  2. EU rules must apply if personal data is processed abroad by companies active in the EU market or if these organisations record the behaviour of individuals in the EU.
  3. Top management must understand the implications of the new regulation and create a transformation program to comply with GDPR, involving areas such as the Legal Department, Marketing or IT areas.
  4. Companies must carry out internal audits to define: what type of information they collect, how the information is stored, who can access the information and with whom it is shared.
  5. Consent for data collection must be explicit from the holder of the personal data and must be recorded.
  6. Service outsourcing contracts should be reviewed, as the GDPR also applies to subcontractors established in the EU.
  7. It must be SRI Directive complied with(Network and Information Security Directive), which imposes a minimum level of security for digital technologies, networks and services, and also requires (particularly for entities such as those in the health sector) to report incidents with a significant impact on the security of networks and information systems. Entities that are part of the NHS must notify the breach of personal data, whenever possible, within 72 hours of becoming aware of it.
  8. A data protection officer will be mandatory for some companies (for example, if they process sensitive data). This will be the person within the company responsible for complying with the obligations of the regulation.
  9. Companies will have to adopt data protection principlessince conception (privacy by design) and data protection by default (privacy by default).
  10. Organizations should carry out information security training actions aimed at all employees and create permission levels that restrict access to data according to the functions and needs of each employee.

Want to know more about the GDPR and how can PHC software help you comply with the regulation?  Click here to consult our information space about the GDPR

Legislation

Comments are disabled.