Obligations of Companies Under the Personal Data Protection Law
With its entry into force in 2016, the Personal Data Protection Law opened the door to a new era for companies. The rapid digitalisation of data processing activities has today made the protection of personal data not merely a legal requirement but an inseparable part of corporate reputation. Under the Law, companies are obliged, in their capacity as data controllers, to implement a series of technical and administrative measures.
Foremost among these obligations is the duty to inform. At the stage of obtaining personal data, data controllers must provide data subjects with clear and comprehensible information as to the purposes for which the data will be processed, to whom and for what purpose they may be transferred, the method and legal basis of collection, and the data subject's statutory rights. Privacy notices should be prepared specifically for the company's field of activity and its particular data processing operations, rather than using standard templates.
Furthermore, save for the exceptional circumstances set out in the Law, explicit consent must be obtained for personal data to be processed. A common error in practice, however, is to obtain explicit consent even where the Law expressly provides another ground for processing (for example, performance of a contract), thereby vitiating the legal process. Explicit consent is defined as "consent relating to a specific matter, based on information and expressed with free will"; making the provision of a service conditional upon explicit consent is plainly unlawful.
Finally, the obligation to register with VERBIS (the Data Controllers Registry Information System) is of considerable importance. Data controllers meeting criteria such as annual number of employees or total financial balance sheet are required to register. In inspections carried out by the Board, incomplete or erroneous notifications and breaches of the duty to inform can lead to substantial administrative fines. It is therefore vital that companies complete their data protection compliance processes through a holistic approach, subjecting them to both legal and technical review.
