Accessibility Statement Skip Navigation
  • Resources
  • Blog
  • Journalists
  • +44 (0)20 7454 5110
  • Client Login
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All Public Company News
      • All Multimedia News
      • View All News Releases

      • Regulatory News

      • D/A/CH Regulatory News
      • UK Regulatory News
      • View All Regulatory News

  • Business & Money
      • Auto & Transportation

      • Aerospace & Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads & Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking & Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film & Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers & Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalisation
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls & Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil & Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defence
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation & Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking & Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers & Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines & Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics & Personal Care
      • Fashion
      • Food & Beverages
      • Furniture & Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewellery
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film & Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks & Tourist Attractions
      • Gambling & Casinos
      • Hotels & Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Animal Welfare
      • Corporate Social Responsibility
      • Economic News, Trends & Analysis
      • Education
      • Environmental
      • European Government
      • Labour & Union
      • Natural Disasters
      • Not For Profit
      • Public Safety
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Overview
  • Distribution
  • Paid Placement
  • Multimedia
  • Disclosure Services
  • SocialBoost
  • Rooms
    • MediaRoom
    • ESG Rooms
  • AI Tools
  • General Enquiries
  • Media Enquiries
  • Partnerships
  • Hamburger menu
  • Cision PR Newswire UK provides press release distribution, targeting, monitoring, and marketing services
  • Send a Release
    • Phone

    • +44 (0)20 7454 5110 from 8 AM - 5:30 PM GMT

    • ALL CONTACT INFO
    • Contact Us

      +44 (0)20 7454 5110
      from 8 AM - 5:30 PM GMT

  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists
  • News in Focus
    • Browse News Releases
    • Regulatory News
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
    • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists
  • Overview
  • Distribution
  • Paid Placement
  • Multimedia
  • Disclosure Services
  • Cision Communications Cloud®
  • AI Tools
  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists
  • General Enquiries
  • Media Enquiries
  • Partnerships
  • Client Login
  • Send a Release
  • Resources
  • Blog
  • Journalists

EU Data Protection Regulation: Where do businesses need to take action now?


News provided by

Buse Heberer Fromm Law Firm

30 Jun, 2016, 09:34 GMT

Share this article

Share toX

Share this article

Share toX

BERLIN, June 30, 2016 /PRNewswire/ --

Jan Tibor Lelley and Tobias Grambow 

After a protracted negotiation and design phase, the EU General Data Protection Regulation (GDPR) was adopted by the European Parliament on 04/14/2016 and entered into force on 05/24/2016. After 20 years, data protection law is at a whole new level and particularly uniform for the European Union.

This regulation will be in application as of 05/25/2018 and replace the EU Data Protection Directive (95/46/EC) which has been in force since 1995.

What are the major changes?  

  • Harmonization 

The Regulation aims to provide a unified data protection regime in the European Union, since it will be directly applied in all 28 EU Member States. Implementation by national legislation is not necessary. But there won't be complete harmonization. The GDPR contains opportunities for national, special, and exceptional regulations at more than 50 points within its over 99 articles. Data protection will therefore remain a hodgepodge, albeit one based on unified core values.

  • Scope of application 

The Regulation also applies to companies based outside the EU, insofar as such companies which are not seated in EU countries offer goods or services to EU citizens or monitor their behavior.

  • Sanctions 

In cases of violations of the Regulation, companies will face considerable penalties. The fines can amount to four percent of the global corporate turnover or € 20 million.

  • Consent  

With regard to actions that have the consent of the person affected in the processing of personal data, it must be a clearly acknowledged action which was assented to unambiguously, without constraint for the specific case and in knowledge of the facts and which must be revocable at any time with effect for the future.

  • Data Protection Officer 

Companies are required to appoint a Data Protection Officer, so far as their core activity requires extensive, regular, and systematic monitoring of persons concerned or extensive processing of particularly sensitive data (such as racial or ethnic origin, health data, etc.) due to their business purpose or its scope according to Art. 9, or data on criminal convictions or offenses according to Art. 10 of the GDPR. There will likely be no changes to the previous legal conditions in the Federal Republic of Germany under which a Data Protection Officer must be appointed. Art. 37 Para. (4) of the GDPR contains a corresponding clause for special arrangements by the Member States. It should be noted that in the future, the duty of the Data Protection Officer includes monitoring of compliance with the GDPR so that a significantly higher risk of liability is to be expected for the Data Protection Officer.

  • One-stop shop 

In the future, EU citizens and companies will need to contact only one Data Protection Authority throughout the EU. This office is obligated to achieve harmonization with the Data Protection Authorities of other countries in the case of transnational aspects of data protection.

  • Registration requirement     

The company responsible for processing the data must report any data breaches to the competent authority within 72 hours of becoming aware of the privacy violation.  

  • Privacy by design / privacy by default 

Companies need to design their product offers as data-efficiently as possible and offer privacy-friendly default settings.

  • Data protection impact assessment 

The data protection impact assessment consists of a detailed audit and risk assessment of data processing operations that involve a high potential risk to the rights and freedoms of the data subjects or persons affected. If such a data protection impact assessment shows an actually high risk, the person responsible must take appropriate protective measures or consult the supervisory authority.

  • Security obligation and burden of proof 

The person responsible for data processing must take and implement appropriate technical and organizational measures to ensure and to prove that the data processing is carried out in accordance with the GDPR. The supervisory authority may inspect the security of the data processing. The establishment of a data protection management system will be required as a rule.

What is now important for employers?  

Art. 88 Para. 1 GDPR contains a clause according to which more specific regulations on data protection in the employment context can be created by the national legislature itself. It is likely that § 32 BDSG (modified if necessary) will remain in force for now in the Federal Republic of Germany. A new attempt for detailed codified employment data protection seems unlikely in the near future. But with regard to employee data protection, national rules must comply with the principles of the GDPR, which can be considered a given in Germany due to numerous Higher Court decisions.

Furthermore, there is the possibility to process personal data on the basis of a collective agreement. In Germany, these are company agreements and collective agreements in particular. The most important way for personnel management to use company agreements as a permission event for data processing in companies is therefore kept open.

The GDPR also clarifies that consent is possible in the employment relationship as well. But it is always a prerequisite that the conclusion of an employment contract, its amendment or the promise of an employer's service is not made subject to a consent for data processing which is not required for this purpose.

To be an effective legal basis for data processing, company agreements must, however, meet certain requirements, and are accordingly being redesigned or tailored to the requirements of GDPR. This means that appropriate and specific measures to safeguard the human dignity, legitimate interests, and fundamental rights of the person concerned, especially with regard to the transparency of the processing and transfer of personal data within the corporation and the monitoring systems in the workplace, must be regulated.

Even if the time until the GDPR will actually be applied seems far away, companies should deal quickly with the changes in legislation. The substantial tightening of sanctions and resulting increased risk must be taken as an opportunity by companies to analyze the company's data protection systems and develop a suitable data protection management system for ensuring and demonstrating compliance with the GDPR. This is the only way to avoid more stringent requirements of the new regulation bill and existence-threatening fines.

From a labor law point of view, employment contracts and company agreements should be checked against and adapted to the EU General Data Protection Regulation.

Contact:

Dr. Jan Tibor Lelley, LL.M. (Suffolk University Law School)
Essen, Frankfurt/Main, Lonon
phone: +49-201-1758-0
mail: lelley@buse.de

Tobias Grambow
Berlin
phone: +49-30-327942-37
mail: grambow@buse.de

Modal title

Contact PR Newswire

  • +44 (0)20 7454 5110
    from 8 AM - 5:30 PM GMT
  • General Enquiries
  • Media Enquiries
  • Partnerships

Products

  • Content Distribution
  • Multimedia Services
  • Disclosure Services
  • Cision Communications Cloud®

About

  • About PR Newswire
  • About Cision
  • Partnering Opportunities
  • Careers
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United States
  • Vietnam

My Services

  • All News Releases
  • Customer Portal
  • Resources
  • Blog
  • Journalists
  • Data Privacy

Do not sell or share my personal information:

  • Submit via Privacy@cision.com 
  • Call Privacy toll-free: 877-297-8921

Contact PR Newswire

Products

About

My Services
  • All News Releases
  • Customer Portal
  • Resources
  • Blog
  • Journalists
+44 (0)20 7454 5110
from 8 AM - 5:30 PM GMT
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 PR Newswire Europe Limited. All Rights Reserved. A Cision company.