
Personal Data Breach Reporting Requirements Under the GDPR
What is Data Breach? A personal data breach is security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or

Direct marketing rules and exceptions under the GDPR
Direct marketing includes text messages (SMS) and emails that a customer receives from a product or service provider. But activities of direct marketing may include

Records of processing activities in GDPR Article 30
What do companies have to include in the records of processing activities? GDPR Article 30 requires companies to keep an internal record, which contains the

Data Protection Authorities (DPA)
Data Protection Authorities (DPA) Data Protection Authorities (DPA) are independent public authorities that supervise, through investigative and corrective powers, the application of the GDPR. They

Data Processing Agreement (DPA)
What is a DPA? A Data Processing Agreement (DPA) is a legally binding document to be entered into between the controller and the processor in writing or

GDPR compliance checklist for controllers
This is a simple GDPR compliance checklist for controllers that you can use to ensure you have considered most important aspects of the GDPR. Before

GDPR Basics: Are you a Controller or a Processor?
What are ‘controllers’ and ‘processors’? With this short and simple article, we will try to explain the basics of controllers and processors. Controllers are the

Templates for Records of Processing Activities
As we see every day, most companies and organisations still keep their Records of Processing Activities in spreadsheets. Through our experience, we have seen a

Web plug-in requires visitor’s consent
In the light of the recent ruling of the European Court of Justice, website owners have to bear in mind their data protection responsibilities when

First GDPR fine issued in Lithuania
A year after GDPR came into force, the Lithuanian Data Protection Authority (VDAI) has issued its first administrative fine. UAB ‘Mister Tango’, a company that provides financial

Finnish DPA ordered a company to change their data processing practises
An article was published recently in the Helsingin Salomat about the Finnish Data Protection Authority who had ordered a payment and financing solution company to correct

Data Protection Officer’s role and responsibilities
In light of the latest survey conducted by the CPO Magazine, we are looking into the role of the Data Protection Officer (DPO). In this

GDPR Compliance Checklist for 2020
Just recently, a report was published based on a survey of 252 global privacy professionals working for a wide range of organizations across 14 different

GDPR in B2B Marketing
There are two separate EU level regulations to follow when processing personal data for direct marketing in B2B and B2C activities. Privacy and Electronic Communication

Data Protection Impact Assessment Guide
The General Data Protection Regulation (GDPR) has introduced a new obligation, which requires companies and organizations to carry out data protection impact assessments if the personal

Cyber Attacks from the Perspective of GDPR: Ransomware
Nowadays almost every business sector integrates digital technologies. IT infrastructure and practice, if not updated regularly, ages and becomes weaker. Therefore, because of the amount and

Six Months With GDPR in Force. What Happened?
The GDPR, that came into force on the 25th of May, 2018, expanded the EU‘s data protection area coverage, introduced innovations that have an effect

Healthcare sector: How to Comply With GDPR?
Since GDPR entered into force, the personal data protection has become more challenging to the Healthcare sector. Meaning that data must be managed with more

Hospitality Sector: How to Comply With GDPR?
Hospitality sector (accommodation, restaurants & bars, travel & tourism and leisure) has one of the largest shares of personal data collected by sector. Therefore, necessary

IP Anonymisation on Google Analytics
Many companies use Google Analytics as their assistive tool in order to collect valuable information about customer behaviour on websites, mobile apps etc. By default, Analytics

GDPR Compliance Investigation in Finland and Sweden
After GDPR regulation coming into force on the 25th of May, the Finnish Data Protection Authority’s office was flooded with complaints about possible infringements. This

Loyalty Programs Under the Radar of GDPR
Lithuanian Data Protection Authority recently completed the investigation on proper personal data processing for direct marketing purposes. The target was the major food, household goods,

Legitimate Interest Guide Under the GDPR
GDPR lists six lawful bases for processing of personal data, and legitimate interest is one of them. There is no particular purpose defined, therefore, it

How does GDPR affect Direct Marketing and Profiling
How does GDPR affect Direct Marketing and Profiling Direct marketing and consumer behavioral habits (profiling) are the key tools a company uses to sell their

Sharing Our GDPR Expertise in Lithuania = Mission Success
Hi, I am Sarune – Country Manager (Lithuania) for GDPR Register. I know that GDPR compliance can be a headache sometimes, which is why I

Transmitting personal data to third countries
The GDPR has put strict rules in place, when it comes to data transfer to third countries or international organizations. Which countries are third countries? Third

The lawful basis for Data Processing under the GDPR
A lawful (or legal) basis for processing data must be satisfied before a business can process any personal data. Article 6 of the GDPR describes six

What are the GDPR fines for non-compliance?
Multi-tiered approach to GDPR fines and penalties General Data Protection Regulation has introduced a tiered approach to fines, meaning that the severity of the breach will

Would you like some cookies – Why websites ask this?
This is the question that many computer users are receiving daily. What does it mean and why is it being asked? It is a part

Data Rules for AdTech Under the GDPR
For those living in blissful ignorance: starting from May 25th 2018 a new General Data Protection Regulation (GDPR) will enter into force, which sets forth