GDPR and Websites: The European Regulation on the Protection of Personal Data

gdpr websites european data protection regulation

Table of contents

On May 25, 2018, the GDPR Regulation No. 679/2016, the new European Regulation on the protection of personal data, will come into effect.

The main innovation introduced by the legislation is the strengthening of technical and organizational measures to ensure maximum data security, thereby reducing the risk of theft or accidental loss.

What is GDPR?

The new Regulation (EU) 2016/679 for Data Protection or GDPR (General Data Protection Regulation) sets out the “guidelines” to be adopted regarding the protection of natural persons with regard to the processing of personal data and the free movement of such data.
The complete text of the GDPR Regulation in PDF format (88 pages) is available at this address: GDPR (General Data Protection Regulation) EU 2016/679

The GDPR will be fully applicable starting from May 25, 2018. Its objective? To ensure adequate security of personal data at the moment they are processed, in order to avoid situations that could compromise privacy.

It is the most significant initiative in data protection in the last 20 years.

Who does GDPR apply to?

The GDPR must be respected both by organizations headquartered in the European Union and those that, although based outside the EU, process and collect data from citizens of one of the 28 member states.
Any organization in the world that addresses individuals in the European Union must comply with the new GDPR regulations.

ePrivacy Regulation

Included within the reform introduced by the European Commission’s GDPR is the ePrivacy Regulation, which concerns “respect for private life and the protection of personal data in electronic communications within the European Union“.

The ePrivacy Regulation includes special rules designed to significantly impact the behavior and rights of individuals who now routinely use electronic communication services, especially online services.

The most important points of the proposed ePrivacy Regulation are as follows:

  • Application of the rules: even OTTs (Over The Top, i.e., service providers like WhatsApp, Facebook, Messenger, and Skype) will be required to comply with European rules and ensure the same level of protection as traditional telecommunications operators.
  • Metadata: protection will not only apply to data but also to the content of communications and metadata, i.e., the ancillary or circumstantial elements of information. This means that metadata must be anonymized where possible and deleted if processed without consent or if they are no longer necessary for the purpose for which they were collected. It will be mandatory to request the consent of end users to provide ancillary services (such as antivirus or email keyword search) and for additional specific purposes that cannot be achieved using anonymous data. Furthermore, the proposal for the regulation provides that any interference with the device used requires the user’s consent.
  • IoT (Internet of Things): within the scope of the IoT (Internet of Things), the principle of confidentiality of communications will also be extended to machine-to-machine processing.
  • Cookies: users will be able to accept or reject the installation of cookies through a preliminary browser setting.
  • Telemarketing: telephone lines used for promotional calls must be identified by a unique identifying prefix that must be displayed in plain sight.
  • Information and consent acquisition: information and consent acquisition from the user must be made more user-friendly, including through the use of standardized icons.

The complete ePrivacy Regulation in PDF is available at this address: Article 29 Data Protection Working Party

Subscribe to our newsletter

And receive news, tips, and strategies to enhance your online presence.

    Consenso al trattamento dei dati personali Newsletter subscription

    GDPR and Websites: How to Behave?

    Clearly and comprehensively describe the purpose of collected data

    Each user must clearly and unequivocally understand the purposes for which their personal data are used and how they are processed.
    For this reason, it will be mandatory to clearly and comprehensively describe the cookies used on the website, listing the type of data collected, to whom they are transmitted, the purpose of their use, the expiration of cookies, etc.
    In addition to cookies, a website can also collect data through the contact form (such as newsletter subscription, registration for e-commerce, etc.). In these cases as well, the purpose of the collected data must be specified.

    Example
    If an email address is provided to receive the newsletter, it must be specified that it will be used only for sending newsletters and not transmitted to third parties, for example, for advertising purposes.

    Block cookies and request explicit user consent

    Obtaining consent for data processing is a key point of the regulation.

    GDPR establishes that every website that collects personal data, for any reason, must obtain explicit user consent (opt-in) for their use.

    It is possible to install only strictly necessary cookies before obtaining user consent, while others must be blocked obligatorily.

    Give users the option to revoke consent

    The General Data Protection Regulation stipulates that the user has the right to access their personal data, correct them, delete them, or limit their processing.

    In the case of a website, this means that the user must have the option to revoke consent in a simple manner even at a later time, by accessing the cookie settings of the website and changing their choice to accept or refuse them. The website must still function, even if the user refuses all cookies except those strictly necessary for the site to function.

    It is also mandatory to ensure people’s “right to be forgotten,” i.e., to delete personal data upon request.

    Record received consents

    GDPR requires maintaining a register of all consents received, to be used as proof that the user has indeed given their consent to data processing.

    Protect the collected data

    Furthermore, any sensitive data sent via a website must be encrypted to comply with GDPR: the use of a valid digital certificate and the HTTPS protocol are considered sufficient measures to comply with GDPR provisions.
    It is important to remember that, as stated in the Chromium blog, starting from version 68, the Chrome browser will label sites without an SSL certificate (the classic HTTP) as “not secure.”

    Inform the user about their rights and notify them of any breaches

    The visitor must be informed about their right to submit a complaint to the supervisory authority. Furthermore, in case of a breach, it is mandatory to report it within 72 hours to local security authorities and the affected users.

    GDPR Fines and Penalties

    Non-compliant organizations risk heavy fines of up to €20 million or 4% of the organization’s global annual turnover.

    Table of contents

    Share

    Related articles

    Subscribe to our newsletter

    Receive valuable content, insights, and advice to help you transform the web into a concrete resource for your work.