Go to main contentGo to footer
GDPR
|
06 July 20

GDPR: the stranger that protects our personal data

Although the General Data Protection Regulation (better known by its acronym, GDPR) has been in force for more than 4 years and enforceable for more than 2, its purpose and workings are still not widely understood.

In this article I'll walk through its key points, mainly from the point of view of those it protects: all of us EU citizens (and others, as we'll see).

Matteo NicolettiUX designer, Frontend Dev

From what I've seen, reactions to the GDPR vary, but almost all of them lean toward what a psychologist would call avoidance: they range from a kind of allergy to the subject, handing it off to a privacy consultant in the hope that it bothers us as little as possible, to pretending the problem doesn't exist, at most relying on some off-the-shelf solution (like the ones provided by Iubenda) in the hope that it alone will make us compliant.
Unfortunately, the second path isn't enough on its own. Not because Iubenda falls short — on the contrary, it provides excellent tools to support a company's data protection strategy — but because automated systems (probably installed only on the website) can't come into the company and organize how the personal data collected is processed and stored.

But let's take it one step at a time, starting with the fundamentals.

What is personal data?

Personal data is any information relating to an identified or identifiable natural person (called the "data subject"); a person is considered identifiable if they can be identified directly or indirectly.
In other words, any information that, alone or combined with other information, makes it possible to trace the identity of the data subject is personal data.
For example, a photo is personal data. If I have a photo of you and somewhere else I find another photo of you tagged with your first and last name (say, on Facebook), I can trace your identity, so it's personal data.

Personal data is the inalienable property of the natural person it identifies.

What is the GDPR?

The GDPR, or General Data Protection Regulation, is Regulation (EU) 2016/679 of May 4, 2016, which entered into force on May 24 of the same year and has applied since May 25, 2018. It sets out how the personal data of natural persons must be processed.
It extends what in Italy is called the privacy law, bringing it in line with today's pervasive information economy.

GDPR territorial scope and data ownership

The GDPR states that personal data processed in Europe — whoever it belongs to, EU citizen or not — belongs to that person and is protected, so any company operating in the EU is bound by the GDPR.

The owners of personal data have the right to know how it is processed and that it is processed correctly, and they have the right to change their minds and object to its processing at any time.

Who controls the processing of personal data

Unlike the old privacy law, the GDPR provides no indemnity: you can no longer offload responsibility for processing personal data onto whoever processes it, as was done before by appointing a privacy officer.
Under the GDPR, the responsible party is the controller (the Data Controller), and the controller is the CEO, or in any case whoever has the final say on company decisions.
The controller can appoint others to work on the data (Data Processors), but responsibility for the processing does not pass to them.
The Data Processor is still responsible for processing the data according to the procedures agreed with the Data Controller.
In this respect, you might appoint a DPO (Data Protection Officer), known in Italian as the Responsabile della protezione dati. The DPO is an advisory role whose job is to advise management, oversee what management does and act as the point of contact with the authority (the data protection authority).

If personal data is no longer needed for its original purpose, it must be deleted; but if the law requires it to be retained, that becomes the purpose of the processing and the data can be kept.

By accepting a service, such as Gmail, you consent to the processing of all personal data needed to provide that service: in other words, if I use Gmail, my email address is a necessary part of the service, so I consent to Google processing my email address. But, for example, analyzing the content of my emails is not necessary to provide me with the service, and if Google wants to process it for its own specific purposes (which it must tell me explicitly), it has to get my consent.
Consent must be informed and freely given, and withdrawing it must be as easy as giving it.
Informed means the privacy notice must explain the purposes of the processing in plain, clear language.
Freely given means completely free: if I give you something in exchange for your consent, it isn't free. In our example, if Gmail promised me 50 GB of extra storage for consenting to the analysis of my email content and sending patterns, that would not be freely given consent.
So to obtain a user's consent, we (as a company providing a service) must establish a contract with them stating exactly what will be done with their personal data and for what purposes. Once it's accepted, we are bound by the GDPR and by that contract.

Penalties

The penalties are, shall we say, astronomical.
The text states that penalties must in every case be effective, proportionate and dissuasive, and nonprofit organizations are allowed to bring class actions on behalf of citizens.
The GDPR provides for administrative fines of up to €20,000,000 or, for companies, up to 4% of total worldwide annual turnover for the previous financial year, whichever is higher.

Conclusions

At Cantiere, of course, we have our fair share of allergy, but we're convinced that processing personal data in line with the GDPR is the right thing to do, because personal data is part of people's fundamental rights, and also because the penalties are a strong deterrent.
If you need help, we can make sure the applications you build with us are fully compliant.

Credits

Some of the information in this article comes from the podcast DataKnightmare, specifically the episode GDPR: cinque pezzi facili, used under the terms of the CC BY-SA license.

Article updated on July 7, 2020 to correct an inaccuracy about the territorial scope of the GDPR.

footer