How to comply with GDPR rules
The General Data Protection Regulation (GDPR) is the European privacy law for organisations that process personal data. The rules also apply to SME business owners and self-employed professionals. Do you, for example, process personal data for a newsletter, a price quotation, an invoice, or staff records? If so, use this checklist to make sure you are complying with the key GDPR obligations.
You may not invent a reason yourself. The GDPR sets out 6 reasons that are considered valid grounds. These 4 are important for business owners:
1. It is needed to carry out a contract
For example, you need to process address details to deliver your product to someone. This reason also applies if no contract has yet been agreed, but you need personal data to enter into a contract. For example, when drawing up a price quotation.
2. It is needed to comply with the law
For example, you must report your staff’s salary levels to the Netherlands Tax Administration.
3. You have consent
There are several requirements that consent must meet. For instance, people must actively give their consent, based on clear information.
4. It is needed for a legitimate interest
This means there is a reason that takes precedence over protecting a person’s privacy. For example, you want to prevent fraud or protect yourself against theft. You must meet several conditions if you want to process personal data due to a legitimate interest.
> Check if you have a good reason to process personal data (in Dutch)
For example: To send out a newsletter, you do need an email address, but you do not need a date of birth.
Privacy by default
Do not process more personal data than needed in the default settings of your products or services. For example:
- Do not allow an app to track a user’s location without a valid reason.
- If you have newsletter sign-up options at the checkout of your online shop, do not tick these options by default.
Are you designing new products or services? Then ensure that personal data is already properly protected from the design phase.
For example: You have asked for an email address to send an invoice. In that case, you must not use that email address to send advertising to a customer.
The GDPR does not set a fixed retention period. However, you must not keep personal data for longer than is necessary. The retention period depends on:
- how long you need the data for your services
- whether there are any statutory time limits you must comply with, such as the retention period for business records or the Public Records Act (Archiefwet)
For example:
- what data you store
- why
- for how long
Write the privacy statement in plain language and make sure it is easy to find.
> Find out how to draw up a privacy notice
Also tell your clients what their rights are
Your customers have many rights when it comes to privacy. You must ensure that they can easily exercise these rights. For example, your customers may:
- view, modify, and delete their data
- restrict and withdraw consent they have previously given
- request their data in some situations so that they can easily switch to another business. This is called the right to data portability (in Dutch).
Your customers may file a complaint with the Dutch Data Protection Authority (DPA). The DPA must process these complaints.
For example:
- Secure your website using secure protocols (HTTPS).
- Install software updates.
- Only send personal data to customers or other business contacts, for example, via a secure connection.
> Read more tips on securing personal data (in Dutch)
Examples of data leaks are:
- You lose a laptop, tablet, USB stick, or document that includes unencrypted personal data.
- You email personal data to the wrong person.
- The personal data you are processing is stolen in a cyberattack.
You must report all serious data breaches to the Dutch Data Protection Authority (DPA) within 72 hours. You must also document all data breaches, including internal leaks that you do not have to report.
For example:
- which personal data you process and why
- who you share the data with
- the date when you must delete the data. This is usually the end of the retention period
This overview falls under the so-called accountability principle. You must always be able to explain how you handle data.
You may want to share personal data with another business. For example:
- You work with an external call centre.
- You use an agency for your business administration.
You need consent from your customers to share their personal data with another business. Set this out in a customer agreement or contract that says what you will be sharing and why.
Data Protection Impact Assessment
Do you process data that carries a high privacy risk? If so, you must carry out a Data Protection Impact Assessment (DPIA). This is an extensive investigation to identify the risks of data processing. Based on this DPIA, you can take measures to reduce the privacy risks.
Carry out a Data Protection Impact Assessment (DPIA)
Data protection officer
Does your company process special categories of personal data? Or personal data on a large scale for a longer period? If so, check whether you are required to appoint a data protection officer (DPO). This is someone who monitors whether you are doing everything according to the GDPR within your organisation. Your organisation may also voluntarily appoint a DPO.
Who must follow the GDPR rules?
The GDPR applies to all businesses and organisations that process personal data, including freelancers and SME entrepreneurs. Personal data is information that allows you to identify a person. For example:
- name
- address
- telephone number
Processing includes everything an organisation can do with data. Think of collecting, storing, and forwarding it.
This means you will often be affected by the GDPR. For example, if you:
- send a newsletter
- send a price quotation
- hire staff
- send an invoice
- have a contact form on your website
> Read more about personal data and how you protect it
Personal data and staff
The GDPR also applies when you recruit staff. For example, in the following situations:
- job applications
- background checks
- processing of staff data
Find out what you need to keep in mind when recruiting staff (in Dutch).
What is the significance of the GDPR?
The GDPR is a European law designed to protect people’s privacy. The GDPR sets out what businesses and organisations are and are not permitted to do with the personal data of their customers, staff, and other individuals. In Dutch, the GDPR is known as AVG or Algemene Verordening Gegevensbescherming.