{"id":1564,"date":"2017-12-15T18:09:01","date_gmt":"2017-12-15T18:09:01","guid":{"rendered":"https:\/\/crigroup.com\/?post_type=blog&#038;p=1564"},"modified":"2022-11-14T15:29:06","modified_gmt":"2022-11-14T15:29:06","slug":"gdpr-21-century-compliance-approach","status":"publish","type":"post","link":"https:\/\/crigroup.com\/ar\/gdpr-21-century-compliance-approach\/","title":{"rendered":"GDPR: A 21st Century approach to Compliance"},"content":{"rendered":"<p>Ever since its conception, GDPR has caused a strong stir in the legal and compliance world. The new law builds on the previous data protection legislation but at the same time provides more resilient protections for consumers, and more privacy considerations for organisations involved in the processing of personal data. The new EU General Data Protection Regulation (GDPR) in Europe, adopted in 2016, will be applicable starting on May 25, 2018. GDPR comes with significant changes compared to the Data Protection Directive 95\/46\/EC involving operational changes in organisations.<\/p>\n<p>To say that GDPR is an extension of the previous law will also not be true. It is an add on but a game changer as well in the field of legal and compliance. It has been dubbed as the most important change in data privacy laws in 20 years, leaving the compliance world in a bit of an abyss due to it ever evolving nuance and uncertain nature of applicability. Each country needs to have their own Data protection (outside EU) as stringent and controlled as the EU\u2019s GDPR.<\/p>\n<p><strong>Personal data<\/strong><\/p>\n<p>So, what exactly does GDPR apply to? GDPR applies to personal data and personal sensitive data. If you are offering goods or services to EU citizens inside or outside the EU GDPR will apply. However, the GDPR\u2019s definition is more detailed and makes it clear that information such as an online identifier, can include for e.g. an IP address which can amount to \u2018personal data\u2019. The more expansive definition provides for a wide range of personal identifiers to constitute personal data, reflecting changes in technology and the way organisations collect information about people.<\/p>\n<p>For most of the organisations, keeping HR records, employment checks, customer lists, or contact details etc, the change to the definition should make little practical difference. So one can assume that in case an individual or organisation hold information that falls within the scope of the Data Protection Act, it will also fall within the scope of the GDPR. The GDPR applies to both automated personal data and to manual filing systems where personal data are accessible according to specific criteria. This is wider than the DPA\u2019s definition and could include chronologically ordered sets of manual records containing personal data.<\/p>\n<p><strong>Sensitive personal data<\/strong><\/p>\n<p>It is important to note that the GDPR refers to sensitive personal data as \u201cspecial categories of personal data\u201d as stated in Article 9. These categories are broadly the same as those in the DPA, but there are some minor changes. For example, the special categories specifically include genetic data, and biometric data where processed to uniquely identify an individual. Personal data relating to criminal convictions and offences are not included, but similar extra safeguards apply to its processing. All kinds of background screening and due diligence fall under it.<\/p>\n<p><strong>Controller and Processor<\/strong><\/p>\n<p>Another main guide to get ready for GDPR includes first determining whether your organisation processes personal data as a \u201cdata controller\u201d or \u201cdata processor\u201d The GDPR applies to \u2018controllers\u2019 and \u2018processors\u2019(Article 19-23). A controller determines the purposes and means of processing personal data. A processor is responsible for processing personal data on behalf of a controller. Incase of a processor, the GDPR places specific legal obligations on you as a processor for example, the requirement to maintain records of personal data and processing activities. There is the result of bearing the onus legal liability if processor is found responsible for a breach.<\/p>\n<p>However, controllers are not relieved of their obligations where a processor is involved as the GDPR places further obligations on controllers to ensure its contracts with processors comply with the GDPR. The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU.<\/p>\n<p><strong>Consent<\/strong><\/p>\n<p>In furtherance of understanding GDPR it is important to know the requirement of Consent under the GDPR (Article 32) must be a freely given, specific, informed and unambiguous indication of the individual\u2019s wishes. There must be some form of clear affirmative action \u2013 or in other words, a positive opt-in consent cannot be inferred from silence, pre-ticked boxes or inactivity. Consent must be verifiable, and individuals generally have more rights where you as a person or organisation rely on consent to process their data.<\/p>\n<p>For processing to be lawful under the GDPR, you need to identify a lawful basis before you can process personal data. These are often referred to as the \u201cconditions for processing\u201d under the DPA.It is important that you determine your lawful basis for processing personal data and document this.<\/p>\n<p><strong>Data protection officer<\/strong><\/p>\n<p>This becomes more of an issue under the GDPR because your lawful basis for processing influences individuals\u2019 rights. For example, if you rely on someone\u2019s consent to process their data, they will generally have stronger rights, for example to have their data deleted. Data protection officer (DPO) is the person responsible for GDPR compliance. As per article 35 the DPO will be required by an organisation to be hired depending on the size and processing of large volume of special category of data by an organisation. This person will operate independently of the organisation. The principles of accountability and transparency have previously been implicit requirements of data protection law, however the GDPR\u2019s emphasis elevates their significance.<\/p>\n<p>Ultimately, the aim of these measures should be to minimise the risk of breaches and uphold the protection of personal data. The background investigation companies such as CRI Group offering various screening services and conducting fraud examinations, pre- as well as <a href=\"https:\/\/crigroup.com\/ar\/employee-background-checks\/\" target=\"_blank\" rel=\"noopener\">post-employment screening<\/a> through \u201cEmploySmart\u201d, \u201c3PRM\u201d <a href=\"https:\/\/crigroup.com\/ar\/due-diligence\/\" target=\"_blank\" rel=\"noopener\">due diligence investigation<\/a> services and third-party checks will need to incorporate GDPR in their system for adequate accountability, transparency and governance in the organisation.<\/p>\n<p><strong>Who is CRI Group?<\/strong><\/p>\n<p>Based in London, CRI Group works with companies across the Americas, Europe, Africa, Middle East and Asia-Pacific as a one-stop international <a href=\"https:\/\/crigroup.com\/ar\/third-party-risk-management\/\">Risk Management<\/a>, <a href=\"https:\/\/crigroup.com\/ar\/employee-background-checks\/\">Employee Background Screening<\/a>, <a href=\"https:\/\/crigroup.com\/ar\/business-intelligence\/\"><div id=\"h1-9\">\u0630\u0643\u0627\u0621 \u0627\u0644\u0623\u0639\u0645\u0627\u0644<\/div><\/a>,\u00a0<a href=\"https:\/\/crigroup.com\/ar\/due-diligence\/\"><div id=\"h1-2\">\u0627\u0644\u0639\u0646\u0627\u064a\u0629 \u0627\u0644\u0648\u0627\u062c\u0628\u0629 <span class=\"rtl-1\">360\u00b0<\/span><\/div><\/a>, <a href=\"https:\/\/crigroup.com\/ar\/compliance-solutions\/\"><div id=\"h1-1\">\u062d\u0644\u0648\u0644 \u0627\u0644\u0627\u0645\u062a\u062b\u0627\u0644<\/div><\/a>\u00a0and other professional <a href=\"https:\/\/crigroup.com\/ar\/investigative-solutions\/\">Investigative Research<\/a> solutions provider. We have the largest proprietary network of background-screening analysts and investigators across the Middle East and Asia.\u00a0Our global presence ensures that no matter how international your operations are we have the network needed to provide you with all you need, wherever you happen to be. CRI Group also holds <strong>BS 102000:2013<\/strong>\u00a0and <strong>BS 7858:2012 Certifications<\/strong>, is an HRO certified provider and partner with Oracle.<\/p>\n<p>In 2016, CRI Group launched <a href=\"https:\/\/abacgroup.com\/\">Anti-Bribery Anti-Corruption (ABAC\u00ae) Center of Excellence<\/a> &#8211; an independent certification body established for <a href=\"https:\/\/abacgroup.com\/iso-37001-certification\/\">ISO 37001:2016 Anti-Bribery Management Systems<\/a>, <a href=\"https:\/\/abacgroup.com\/iso-37301-certification\/\">ISO 37301 Compliance Management Systems<\/a> and <a href=\"https:\/\/abacgroup.com\/iso-31000-risk-management\/\">ISO 31000:2018 Risk Management<\/a>, providing <a href=\"https:\/\/abacgroup.com\/iso-37001-training\/\">training<\/a> and <a href=\"https:\/\/abacgroup.com\/iso-37001-certification\/\">certification<\/a>. ABAC\u00ae operates through its global network of certified ethics and compliance professionals, qualified auditors and other certified professionals. As a result, CRI Group&#8217;s global team of certified fraud examiners work\u00a0as a discreet white-labelled supplier to some of the world\u2019s largest organisations.\u00a0<a href=\"https:\/\/abacgroup.com\/contact\/\">Contact\u00a0ABAC\u00ae for more<\/a> on ISO Certification and training.<\/p>","protected":false},"excerpt":{"rendered":"<p>Ever since its conception, GDPR has caused a strong stir in the legal and compliance world. The new law builds on the previous data protection legislation but at the same time provides more resilient protections for consumers, and more privacy considerations for organisations involved in the processing of personal data. The new EU General Data [&hellip;]<\/p>","protected":false},"author":1,"featured_media":21386,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16,146],"tags":[],"class_list":["post-1564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-solution","category-resources"],"gutentor_comment":0,"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"GDPR builds on the previous protection legislation, provides resilient protections for consumers &amp; more privacy considerations for businesses.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/crigroup.com\/ar\/gdpr-21-century-compliance-approach\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR: A 21st Century approach to Compliance | CRI Group\u2122\" \/>\n<meta property=\"og:description\" content=\"GDPR builds on the previous protection legislation, provides resilient protections for consumers &amp; more privacy considerations for businesses.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/crigroup.com\/ar\/gdpr-21-century-compliance-approach\/\" \/>\n<meta property=\"og:site_name\" content=\"National-Grade Workforce Integrity &amp; Safe Hiring Framework\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/crigroup\/\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-15T18:09:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-11-14T15:29:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/crigroup.com\/wp-content\/uploads\/2017\/12\/GDPR-A-21st-Century-approach-to-Compliance.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@crigroup\" \/>\n<meta name=\"twitter:site\" content=\"@crigroup\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/crigroup.com\/#organization\",\"name\":\"CRI Group\\u2122\",\"url\":\"https:\/\/crigroup.com\/\",\"sameAs\":[\"https:\/\/www.facebook.com\/crigroup\/\",\"https:\/\/www.linkedin.com\/company\/corporateresearchandinvestigations\/\",\"https:\/\/www.youtube.com\/channel\/UCn-EXXdew6XIApQm0kyGPMw\/\",\"https:\/\/twitter.com\/crigroup\"],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/crigroup.com\/#logo\",\"inLanguage\":\"ar\",\"url\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2022\/04\/CRI-Group-Copy.jpg\",\"contentUrl\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2022\/04\/CRI-Group-Copy.jpg\",\"width\":1920,\"height\":796,\"caption\":\"CRI Group\\u2122\"},\"image\":{\"@id\":\"https:\/\/crigroup.com\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/crigroup.com\/#website\",\"url\":\"https:\/\/crigroup.com\/\",\"name\":\"National-Grade Workforce Integrity &amp; Safe Hiring Framework\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/crigroup.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/crigroup.com\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"ar\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#primaryimage\",\"inLanguage\":\"ar\",\"url\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2017\/12\/GDPR-A-21st-Century-approach-to-Compliance.jpg\",\"contentUrl\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2017\/12\/GDPR-A-21st-Century-approach-to-Compliance.jpg\",\"width\":1920,\"height\":1280,\"caption\":\"GDPR A 21st Century approach to Compliance\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#webpage\",\"url\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/\",\"name\":\"GDPR: A 21st Century approach to Compliance | CRI Group\\u2122\",\"isPartOf\":{\"@id\":\"https:\/\/crigroup.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#primaryimage\"},\"datePublished\":\"2017-12-15T18:09:01+00:00\",\"dateModified\":\"2022-11-14T15:29:06+00:00\",\"description\":\"GDPR builds on the previous protection legislation, provides resilient protections for consumers & more privacy considerations for businesses.\",\"breadcrumb\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#breadcrumb\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/crigroup.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"All Solutions\",\"item\":\"https:\/\/crigroup.com\/all-solutions\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Compliance Solution\",\"item\":\"https:\/\/crigroup.com\/all-solutions\/compliance-solution\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"GDPR: A 21st Century approach to Compliance\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#webpage\"},\"author\":{\"@id\":\"https:\/\/crigroup.com\/#\/schema\/person\/1fa7c310a7670e7d554b30e5d4c94d78\"},\"headline\":\"GDPR: A 21st Century approach to Compliance\",\"datePublished\":\"2017-12-15T18:09:01+00:00\",\"dateModified\":\"2022-11-14T15:29:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#webpage\"},\"wordCount\":1155,\"publisher\":{\"@id\":\"https:\/\/crigroup.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-21-century-compliance-approach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2017\/12\/GDPR-A-21st-Century-approach-to-Compliance.jpg\",\"articleSection\":[\"Compliance Solution\",\"Resources\"],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/crigroup.com\/#\/schema\/person\/1fa7c310a7670e7d554b30e5d4c94d78\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/crigroup.com\/#personlogo\",\"inLanguage\":\"ar\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3c599f0f92bce780dd3dc1c2b4dcc284?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3c599f0f92bce780dd3dc1c2b4dcc284?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/crigroup.com\/\",\"Admin\"],\"url\":\"https:\/\/crigroup.com\/ar\/author\/admin-2\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts\/1564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/comments?post=1564"}],"version-history":[{"count":5,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts\/1564\/revisions"}],"predecessor-version":[{"id":21387,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts\/1564\/revisions\/21387"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/media\/21386"}],"wp:attachment":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/media?parent=1564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/categories?post=1564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/tags?post=1564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}