Tue, May 29, 2018 - Page 9 News List

No tolerance for those who breach GDPR, EU warns

The new law applies across the union, with members having to give their data watchdogs, who now have unprecedented fining powers, complete independence

By Stephanie Bodoni  /  Bloomberg

From tech giant Facebook to libraries and schools, organizations are now subject to the world’s most far-reaching data privacy regulation in a crackdown aimed at protecting people from losing control over their personal information.

It has occupied thousands of lawyers, taken years of planning and triggered billions of e-mails.

Mess up now and you can expect very little tolerance, said European Data Protection Board chair Andrea Jelinek, the Austrian in charge of policing the EU’s General Data Protection Regulation (GDPR), which took effect on Friday.

“If there are reasons to warn we will warn; if there are reasons to reprimand we will do that; and if we have reasons to fine, we are going to fine,” Jelinek, 57, told reporters ahead of the big day.

Asked about criticism that some regulators are more lenient than others, she said that “it was like that in the past, but it should not continue in the future.”

Privacy has moved from a niche topic to one of the biggest headaches for top bosses such as Facebook founder Mark Zuckerberg, who last week was grilled by EU lawmakers about how the data of about 87 million users and their friends may have been shared with a consulting firm with links to then-US presidential candidate Donald Trump’s US presidential campaign.

The pressure has been increasing on firms using or processing EU personal data in the run-up to the deadline. Privacy regulators across Europe for the first time get equal rights and responsibilities, and the same powers to mete out fines of as much as 4 percent of worldwide annual sales for serious violations.

Not everyone is willing to wait for Jelinek and regulators to flex their new powers.

Austrian lawyer Max Schrems, who has taken on Facebook many times and won a landmark EU court ruling in 2015, filed four complaints on Friday under the new rules, accusing Google, Facebook and also WhatsApp and Instagram of forcing users to agree to new privacy policies.

“Facebook has even blocked accounts of users who have not given consent,” Schrems said in an e-mailed statement. “In the end, users only had the choice to delete the account or hit the ‘agree’ button — that’s not a free choice, it more reminds of a North Korean election process.”

The 30-year-old’s group called “noyb” — for none of your business — filed what are likely the first GDPR complaints with national regulators in Belgium, France, Austria and Germany.

“We have prepared for the past 18 months to ensure we meet the requirements of the GDPR,” Facebook’s chief privacy officer Erin Egan said in an e-mailed statement. “We have made our policies clearer, our privacy settings easier to find and introduced better tools for people to access, download, and delete their information.”

Facebook’s “work to improve people’s privacy doesn’t stop on May 25,” Egan said.

EU nations will have to apply the same rules across the bloc, and give their data regulators complete independence.

“We don’t like to see any deviations which will go beyond the rules and spirit” of the rules, EU Justice Commissioner Vera Jourova said earlier in the month.

Facebook would dodge the tough new sanctions under the updated EU rules if any violations in the Cambridge Analytica case are proven because the rules do not apply retroactively.

Still, if companies “don’t stop on Friday, we can get them,” said Jelinek who leads Austria’s data privacy agency as well as board of regulators drawn from across the EU’s 28 nations.

Comments will be moderated. Keep comments relevant to the article. Remarks containing abusive and obscene language, personal attacks of any kind or promotion will be removed and the user banned. Final decision will be at the discretion of the Taipei Times.

TOP top