As of May 25, 2018, wherever you are in the world, if you do business in the European Union or handle EU residents’ personal data, the European General Data Protection Regulation (GDPR) is set to change the way you manage data.
With penalties for non-compliance representing 4% of worldwide revenue (or €20 million, whichever is higher), companies cannot afford to ignore the GDPR.
Personal data under GDPR is literally any information that could identify any aspect of an individual's personal, public or professional life. Examples include; a person's name, address, phone number, email address, IP address, and cultural, economic and biometric information.
GDPR protects not only identifiable individuals, but also individuals who could be "singled out" among others, even if they can’t be directly identified.
Certain articles of the regulation have dominated the headlines – including individuals’ right to be forgotten (having their personal data deleted altogether) or right to access their personal data, for example.
This adds new responsibility for HR leaders to ensure compliance and avoid penalties. GDPR will require more of HR's time, more technology and possibly even more personnel.
Under GDPR, you will have to update your staff and applicants with privacy notices that specify what is the purpose of the processing and what is the legal basis for such processing, and whether you will be transferring their data out of the EU.
HR will have to implement a lawful mechanism to transfer personal data out of the EU. In order to transfer personal data outside of the EU, companies will have to implement one of the following mechanisms; Binding Corporate Rules, Standard Contractual Clauses, individual consent or send data to a company located in an 'adequate' country. ADP has adopted Binding Corporate Rules in 2018.
Data controllers, meaning persons or companies making the decision to launch data processing and overseeing the means by which personal data is processed, must notify the Data Protection Authorities within 72 hours of being made aware of a personal data breach unless there is no risk to the rights and freedoms of individuals. Failure to report within this timeframe may result in fines.
HR will be expected to document and demonstrate compliance with GDPR, such as being able to provide a registry of applications, processes, and categories of data being processed by your organization.
Given the complexity of compliance, it is not surprising that over three quarters of HR leaders are using GDPR and other data privacy legislation as a driver for seeking an outsourced HCM solution.
Why outsource? Your company may not have the technical expertise or resources to carry out the necessary changes ahead of GDPR, and outsourcing your HR data processing to a cloud-based HCM provider like ADP can go a long way toward reducing the burden of accountability. ADP has been preparing for GDPR for a long time, and can help our clients be positioned to meet the requirements of this demanding new age in European privacy protection.
As of March 2018, ADP ranks among an elite group of companies worldwide to have gained regulators’ approval to implement BCRs as both a data processor (covering the processing of clients’ data) and data controller (covering the data of our employees and other business associates).
We’re passionate about protecting the privacy of our clients’ and employees’ personal information at every stage – as we define, develop and refine our products and set the policies that govern how we gather and manage data every single day. Implementing Binding Corporate Rules illustrates our commitment to protect personal data in accordance with the standards required in the EU, regardless of where the European data is processed, accessed or hosted.
Carlos Rodriguez, President and CEO