{"id":118247,"date":"2019-05-25T12:48:09","date_gmt":"2019-05-25T10:48:09","guid":{"rendered":"https:\/\/ceadigilaw.org\/georgia-governor-candidate-stacey-abrams-is-200000-in-debt-shes-not-alone\/"},"modified":"2026-07-17T21:34:07","modified_gmt":"2026-07-17T19:34:07","slug":"georgia-governor-candidate-stacey-abrams-is-200000-in-debt-shes-not-alone","status":"publish","type":"post","link":"https:\/\/ceadigilaw.org\/en\/blog\/georgia-governor-candidate-stacey-abrams-is-200000-in-debt-shes-not-alone\/","title":{"rendered":"GDPR: The First Anniversary"},"content":{"rendered":"\n<div class=\"entry-meta clearfix\"><span class=\"author vcard\"><i class=\"fa fa-aw fa-user\"><\/i>\u00a0<\/span>Last Saturday, May 25, marked the first anniversary of <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\">Regulation (EU) 2016\/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data<\/a> (General Data Protection Regulation).<\/div>\n<div class=\"entry-content\">\n\nWe have therefore considered this the ideal time to reflect on compliance with the Regulation over the past year. It is always advisable to analyze the results achieved through the application of new rules, especially rules as significant as the GDPR, so that we can face the future in the best possible way: correcting non-compliance and updating those aspects of the rules that have been applied correctly.\n\n<\/div>\n<h3>Level of compliance<\/h3>\nAll companies and entities subject to the GDPR have had a year to adapt to the changes required by the Regulation. A large number of rules and procedures had to be incorporated progressively. However, it appears that the vast majority of companies have acted reactively\u2014in other words, they have taken action only in response to alerts such as security incidents or complaints.\n\nNow that a year has passed since the new rules became applicable, however, it is time to demand full compliance. It is time to require proactive accountability from everyone subject to the GDPR. People&#8217;s privacy is at stake and must take precedence, particularly in view of the attacks on personal data that occur every day.\n\nThe Catalan Data Protection Authority has conducted a preventive audit of transparency portals and identified the main problems. Its purpose is to provide companies and entities with guidelines and recommendations for proper compliance. The primary deficiencies concern the principle of lawfulness, with personal data being included when no legal basis existed for doing so. Problems were also found with the publication of unnecessary and excessive data and, finally, with the retention of personal data on transparency portals. The data were considered to have been kept beyond the period necessary to achieve their purpose.\n<h3>Data Protection Officer<\/h3>\nThe new GDPR created a new role, the Data Protection Officer, whose main function is to ensure proper compliance with the rules and protect the data of the individuals concerned. The DPO&#8217;s tasks include informing and advising the controller or processor, as well as the employees who carry out processing, about their obligations under the Regulation and other Union or Member State data-protection provisions. They also include monitoring compliance with the Regulation, providing advice when requested regarding data-protection impact assessments and monitoring their implementation in accordance with Article 35, among many other duties.\n\nMany entities are required to appoint a DPO, but few have actually done so. The reasons may range from a lack of knowledge about the DPO&#8217;s functions to the need to contain costs, or even a mistaken view of the value of appointing a DPO.\n\nMunicipal councils are a clear example. These entities are required to appoint a DPO. At present, although municipal DPOs are registered with the supervisory authorities, no information is available on whether the DPO function is being performed properly.\n<h3>Recorded results<\/h3>\nThe <a href=\"https:\/\/www.aepd.es\/media\/memorias\/memoria-AEPD-2018.pdf\">AEPD<\/a> has published an analysis in recent days of the degree of compliance with the requirements imposed by the new GDPR during its first year. It highlighted the following data in particular:\n<ul>\n \t<li>Complaints received: 14,397<\/li>\n \t<li>Registered data protection officers: 34,193\n<ul>\n \t<li>908 from the private sector<\/li>\n \t<li>285 from the public sector<\/li>\n<\/ul>\n<\/li>\n \t<li>Data-breach notifications: 966<\/li>\n \t<li>Cases involving other European authorities: 1,029<\/li>\n<\/ul>\n<h3>Some final questions&#8230;<\/h3>\n<ul>\n \t<li>Do you really understand what the duty to appoint a Data Protection Officer entails, and what that officer&#8217;s functions are?<\/li>\n \t<li>Do you know what you need to do with the documents you hold to comply with the current rules?<\/li>\n \t<li>Are you actually applying security measures based on the risks identified?<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-columns alignwide is-layout-flex wp-container-core-columns-is-layout-89c98654 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<ul>\n \t<li>The vast majority of companies have acted reactively\u2014in other words, they have taken action only in response to alerts such as security incidents or complaints.<\/li>\n \t<li>The GDPR created a new role, the Data Protection Officer, whose main function is to ensure proper compliance with the rules and protect the data of the individuals concerned.<\/li>\n<\/ul>\n\n<\/div>\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<ul>\n \t<li>The <a href=\"https:\/\/www.aepd.es\/media\/memorias\/memoria-AEPD-2018.pdf\">AEPD<\/a> has published an analysis in recent days of the degree of compliance with the requirements imposed by the new GDPR during its first year.<\/li>\n \t<li>Do you really understand what the duty to appoint a Data Protection Officer entails, and what that officer&#8217;s functions are?<\/li>\n \t<li>Do you know what you need to do with the documents you hold to comply with the current rules?<\/li>\n \t<li>Are you actually applying security measures based on the risks identified?<\/li>\n<\/ul>\n&nbsp;\n\n&nbsp;\n\noriginally published on legal-data.net\n\n<\/div>\n<\/div>\n\n\n<div aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<h2 class=\"wp-block-heading\">Looking for a First-Class Business Plan Consultant?<\/h2>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0Last Saturday, May 25, marked the first anniversary of Regulation (EU) 2016\/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). We have therefore considered this [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4099,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wds_primary_category":0,"wds_primary_cea_women":0,"footnotes":""},"categories":[1107],"tags":[],"cea_women":[],"class_list":["post-118247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-privacy"],"acf":[],"_links":{"self":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/comments?post=118247"}],"version-history":[{"count":1,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118247\/revisions"}],"predecessor-version":[{"id":119293,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118247\/revisions\/119293"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media\/4099"}],"wp:attachment":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media?parent=118247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/categories?post=118247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/tags?post=118247"},{"taxonomy":"cea_women","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/cea_women?post=118247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}