Title
EU General Data Protection Regulation: Changes and implications for personal data collecting companies
Abstract
The General Data Protection Regulation (GDPR) will come into force in the European Union (EU) in May 2018 to meet current challenges related to personal data protection and to harmonise data protection across the EU. Although the GDPR is anticipated to benefit companies by offering consistency in data protection activities and liabilities across the EU countries and by enabling more integrated EU-wide data protection policies, it poses new challenges to companies. They are not necessarily prepared for the changes and may lack awareness of the upcoming requirements and the GDPR's coercive measures. The implementation of the GDPR requirements demands substantial financial and human resources, as well as training of employees; hence, companies need guidance to support them in this transition. The purposes of this study were to compare the current Data Protection Directive 95/46/EC with the GDPR by systematically analysing their differences and to identify the GDPR's practical implications, specifically for companies that provide services based on personal data. This study aimed to identify and discuss the changes introduced by the GDPR that would have the most practical relevance to these companies and possibly affect their data management and usage practices. Therefore, a review and a thematic analysis and synthesis of the article-level changes were carried out. Through the analysis, the key practical implications of the changes were identified and classified. As a synthesis of the results, a framework was developed, presenting 12 aspects of these implications and the corresponding guidance on how to prepare for the new requirements. These aspects cover business strategies and practices, as well as organisational and technical measures.
Year
DOI
Venue
2018
10.1016/j.clsr.2017.05.015
Computer Law & Security Review
Keywords
DocType
Volume
General Data Protection Regulation,GDPR,Data Protection Directive,Personal data
Journal
34
Issue
ISSN
Citations 
1
0267-3649
11
PageRank 
References 
Authors
0.64
4
3
Name
Order
Citations
PageRank
Christina Tikkinen-Piri1110.64
Anna Rohunen2354.78
Jouni Markkula325025.91