News and developments
Cnpd Approves 10 Measures To Prepare For The General Data Protection Regulation
On 28th January, 2017, the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados/CNPD) published a document establishing 10 measures for entities to prepare for the application of the General Data Protection Regulation (“GDPR”).
Since the GDPR will apply from 25 May 2018 onwards, CNPD points out that both public and private entities should begin to implement internal procedures and mechanisms so as to ensure compliance with the new data processing.
CNPD highlights 10 main areas of intervention and provides some actions towards ensuring compliance, including the
following:
informative texts used should be reviewed and adjusted so as to include the additional information required by the
GDPR;
requests, including in what concerns the exercise of new rights (such as the right to portability and to be forgotten), so as to ensure compliance with the timings and formalities imposed by the GDPR;
be documented, through internal registries of data processing activities and through the implementation of other internal procedures. This is an essential measure towards ensuring that both data controllers and data processors are able to verify and demonstrate compliance with the GDPR;
vast set of information that the GDPR has deemed to be mandatory. Moreover, in the event of subcontracting by the data processors, the latter should not only check existing agreements, but also confirm whether or not this subcontracting was authorised by the controllers;
and internal measures, in order to ensure an adequate level of security associated with the processing. Organisations should also implement the measures deemed necessary in order to ensure and verify compliance with the GDPR;
subjects. Organisations will thus guarantee the application of the principles of data protection by design and by default, as set out in the GDPR;
between the controller and the processor, data protection officer involvement and, if applicable, notification to CNPD and to the data subjects.
The organisations which have not yet started implementing the GDPR should, as swiftly as possible, review and adapt
their internal proceedings regarding personal data protection, so as to ensure compliance with the GDPR by 25th May
2018. CNPD will continue to issue guidelines on the GDPR, in order to ensure that it is applied consistently by organisations.