The EU General Data Protection Regulation (“GDPR”) comes into force across the European Union on 25th May 2018 and brings with it the most significant changes to data protection law in two decades. Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet the requirements of the digital age.
We are committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have a robust and effective data protection program in place. However, we recognize our obligations in updating and expanding this program to meet the demands of the GDPR. In order to strengthen our commitment to protect the data privacy of our customers, vendors and stakeholders, we are using KPMG’s Cyber Security services along our GDPR Readiness Journey.
HOW WE ARE PREPARING FOR THE GDPR
We already have a consistent level of data protection and security across our organization, however it is our aim to be fully compliant with the GDPR by as soon as possible. We have documented what personal data we hold, where that data came from and who it is shared with. KPMG conducted an information audit across the SET hotels to map data flows. We have set comprehensive but proportionate governance measures, management support and direction for data protection compliance in a framework of policies and procedures. We are implementing strictest data protection policies and procedures to meet the requirements and standards of the GDPR and any relevant data protection laws, including:
- Data Protection
- Data Retention & Erasure
- Data Breach
- Data Transfers & Third-Party Disclosures
- Subject Access Requests
We are revising our consent mechanisms for obtaining personal data, ensuring that individuals understand what they are providing, why and how we use it and giving clear, defined ways to consent to us processing their information.
DATA PROTECTION OFFICER
We have designated responsibility for data protection compliance to a suitable individual within the organization. Mr. Lionel Robin has been appointed as Data Protection Officer (DPO). If you have any questions about our preparation for the GDPR, please contact firstname.lastname@example.org.