ALVANTIA

Soluciones que aportan valor

ALVANTIA
  • SCF Platform
  • Factoring Platform
  • Customised solutions
    • Consulting
    • Highly qualified in-house teams
  • Contact
  • Join us
  • Articles
  • English
    • Español
  • LinkedIn

GDPR: What is it and how does it affect us?

  • 10/08/2018
  • alvantia (es)alvantia(en)TechnologyTecnología
GDPR: What is it and how does it affect us?

According to the Charter of Fundamental Rights of the European Union, the protection of natural persons with regard to the processing of personal data is a fundamental right. However, rapid technological change and globalisation have posed new challenges in this area. The scale of the collection and exchange of personal data has increased significantly, and technology now enables both private companies and public authorities to use personal data on an unprecedented scale in carrying on their activities. At the same time, awareness of personal information is growing, and there is clearly a growing concern for security, privacy and the protection of personal data.

There is an increasing need to ensure a consistent level of protection of personal data throughout the European Union to prevent divergences that hinder the free movement of personal data within the internal market, since the proper functioning of the market requires the free movement of personal data not to be restricted or prohibited. Legislation is therefore needed to provide legal certainty and transparency for economic operators, to offer the same level of rights to natural persons in all Member States, to require the same level of responsibilities and obligations from data controllers and processors, and to ensure consistent supervision of the processing of personal data (with equivalent sanctions in all Member States and effective cooperation between the supervisory authorities of the various countries).

The new European data protection legislation responds to this: “Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data”, better known as the General Data Protection Regulation (GDPR), which repeals the old regulation (Directive 95/46/EC) and entered into force on 25 May.

Impact on people

The new legislation requires greater protection and extends the rights of citizens in terms of the processing of their personal data, granting the following rights to any person residing in the EU or who has transferred data to a company operating in any EU country:

  • Right of Access: the owner of the data may obtain information about whether the personal data being processed concern them or not and, in that case, they will have the right to obtain information about their personal data that is being processed.
  • Right of Correction: to correct errors and modify inaccurate or incomplete data.
  • Right of Opposition: data subjects may object to the processing of their data.
  • Right of Deletion: data may be deleted and cease to be processed, unless there is a legal obligation to retain it and/or if there are no other legitimate reasons to process it.
  • Right of Limitation: under the conditions legally established, processing of data may be ceased, thereby preventing their further use by the controller, which may then only be kept for carrying out or defending claims.
  • Right of Portability: the data subject can receive their personal data and transfer them directly to another controller in a structured, commonly-used, machine-readable format.

Impact on businesses

The greater protection of personal data required by the GDPR has meant that companies have to comply with rules such as the duty to inform data subjects of the circumstances relating to the processing of their data, to establish greater security measures, to carry out risk analyses, etc. These obligations include most notably compliance with certain principles, which require the data to be:

  • Processed in a lawful, fair and transparent manner in relation to the data subject (lawful, loyal and transparent)
  • Collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation).
  • Accurate and, if necessary, up to date: all reasonable steps must be taken to ensure that personal data which are inaccurate in relation to the purposes for which they are processed is deleted or rectified without delay (accuracy).
  • Preserved in such a way as to allow the identification of data subjects for no longer than is necessary for the purposes of processing the personal data (limitation of the retention period).
  • Processed in such a way as to ensure adequate personal data security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through the implementation of appropriate technical or organisational measures (integrity and confidentiality). In addition, the data controller shall be responsible for compliance with these principles and must be able to demonstrate this (proactive responsibility).

However, this more demanding regulation should not be viewed by companies as an obstacle to carrying on their activities, but rather as an opportunity to offer more adequate services to their clients and to create a company image that is adaptable to changes and committed to compliance with legislation. In an increasingly regulated and competitive environment, where penalties for non-compliance are increasingly severe, only the most agile companies, capable of modernising and adapting quickly to change, will be able to achieve excellence in the sector.

Tagged

Data protectionGDPR

Share

Related Posts

Factoring and Confirming sector in Spain reaches 266,652 million euros in 2024

03/03/2025

Alvantia joins Finwave Iberia & Latam and becomes part of Grupo Fibonacci

20/02/2025

Alvantia sponsors the First Inter-Assembly Conference of the Spanish Factoring Association

25/11/2024

Alvantia participates in the webinar “Factoring and Confirming in Spain and its comparison with LATAM”

16/09/2024

Latest posts

  • Factoring and Confirming sector in Spain reaches 266,652 million euros in 2024
  • Alvantia joins Finwave Iberia & Latam and becomes part of Grupo Fibonacci
  • Factoring and sustainable finance
  • Alvantia sponsors the First Inter-Assembly Conference of the Spanish Factoring Association
  • Alvantia participates in the webinar “Factoring and Confirming in Spain and its comparison with LATAM”

Archive

© 2025 ALVANTIA

  • LinkedIn
  • Home
  • Legal conditions
  • SCF Platform
  • Factoring Platform
  • Customised solutions
    • Consulting
    • Highly qualified in-house teams
  • Contact
  • Join us
  • Articles
  • English
    • Español
Gestionar el consentimiento de las cookies
Para ofrecer las mejores experiencias, utilizamos tecnologías como las cookies (propias y de terceros) para almacenar y/o acceder a la información del dispositivo. El consentimiento de estas tecnologías nos permitirá procesar datos como el comportamiento de navegación o las identificaciones únicas en este sitio. No consentir o retirar el consentimiento, puede afectar negativamente a ciertas características y funciones.
Funcional Always active
El almacenamiento o acceso técnico es estrictamente necesario para el propósito legítimo de permitir el uso de un servicio específico explícitamente solicitado por el abonado o usuario, o con el único propósito de llevar a cabo la transmisión de una comunicación a través de una red de comunicaciones electrónicas.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Estadísticas
The technical storage or access that is used exclusively for statistical purposes. El almacenamiento o acceso técnico que se utiliza exclusivamente con fines estadísticos anónimos. Sin un requerimiento, el cumplimiento voluntario por parte de tu proveedor de servicios de Internet, o los registros adicionales de un tercero, la información almacenada o recuperada sólo para este propósito no se puede utilizar para identificarte.
Marketing
El almacenamiento o acceso técnico es necesario para crear perfiles de usuario para enviar publicidad, o para rastrear al usuario en una web o en varias web con fines de marketing similares.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Ver preferencias
{title} {title} {title}