Will your organisation be affected by the EU's General Data Protection Regulation?
The European Union's General Data Protection Regulation is due to begin in May 2018
In 2018, the Australian and global privacy and data landscape is shifting significantly, with the introduction of both:
- mandatory data breach notification (MDBN) under the Australian Privacy Act 1988 (Cth); and
- the new European Union privacy regime, the General Data Protection Regulation (GDPR).
Organisations should by now have taken steps to prepare for MDBN, which became law on 22 February. But many Australian organisations are not yet so familiar with the GDPR, which will come into effect on 25 May 2018.
The GDPR does not only apply to organisations based in the EU – instead, many Australian organisations will be caught by the GDPR. The GDPR will apply to organisations if they process the personal data of people in the EU and do any of the following:
- offer goods or services to people in the EU – for example, on a website or in marketing material that is in a European currency or language;
- monitor the behaviour of people in the EU – for example, by using cookies or other data processing or techniques which track individuals online; or
- have an office in the EU.
Where the GDPR applies, it is very demanding and the potential fines for non-compliance are eye-watering – up to €20 million or four percent of annual global turnover (whichever is higher).
This is an optimal time for organisations to:
- consider whether they fall within the ambit of the GDPR;
- map their data flows and understand the privacy implications; and
- review and, if necessary, amend their practices, policies and contracts to ensure that they are GDPR-compliant.
Maddocks offers a ‘privacy by design’ approach to proactively ensure whole organisations are privacy compliant. We believe that organisations who are robustly prepared can adjust to the new privacy and data landscape with confidence. For more information about the new privacy laws and practical ways to prepare for them, you can access our framework for preparing for the new mandatory data breach laws and our GDPR survival guide, both of which are co-authored with data security experts Commvault.
Need advice on your GDPR obligations?
Contact the Information Technology team.
Keep up to date with our legal insights and events
Sign upRecent articles
Reform to Australia’s merger clearance regime
By Ron Smooker, Shaun Temby, Jacqueline Picone, and Oliver Wahlstrom
A new mandatory, suspensory merger review system conducted by the ACCC comes into effect in Australia on 1 January 2026.
Important changes to the Workplace Injury Rehabilitation and Compensation Act 2013 concerning workers’ compensation in Victoria
By Catherine Dunlop, Jessica Mourney
From 31 March 2024, amendments to the Victorian workers’ compensation scheme took effect
A step closer to mandatory climate-related disclosure
By Ron Smooker, Rosamond Sayer, Samantha Murphy, and Joseph Fox
The Treasurer introduced the Treasury Laws Amendment (Financial Market Infrastructure and Other Measures) Bill 2024.
Gomeroi v Santos: New guidance on good faith negotiation, and the relevance of climate change
By Susanne Rakoczy, and Larissa Svetlov
We explore Gomeroi People v Santos NSW Pty Ltd and Santos NSW (Narrabri Gas) Pty Ltd [2024] FCAFC 26 (Gomeroi Appeal).
Consultant
Sydney