Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Roinn

5 min read

Writen by Zlatko Delev

Posted on: August 20, 2021

US Companies and GDPR

Why US companies must comply with the GDPR

The GDPR applies to companies outside the EU because it is extra-territorial in scope. Specifically, the law is designed not so much to regulate businesses as it is to protect the data subjects’ rights. A “data subject” is any person in the EU, including citizens, residents, and even, perhaps, visitors.

What this means in practice is that if you collect any personal data of people in the EU, you are required to comply with the GDPR. The data could be in the form of email addresses in a marketing list or the IP addresses of those who visit your website.

You may be wondering how the European Union will enforce a law in territory it does not control. The fact is, foreign governments help other countries enforce their laws through mutual assistance treaties and other mechanisms all the time. GDPR Article 50 addresses this question directly. So far, the EU’s reach has not been tested, but no doubt data protection authorities are exploring their options on a case-by-case basis.

GDPR compliance checklist for US companies

  • Conduct an information audit for EU personal data

Confirm that your organization needs to comply with the GDPR. First, determine what personal data you process and whether any of it belongs to people in the EU. If you do process such data, determine whether “the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment.” Recital 23 can help you clarify whether your activities qualify as subject to the GDPR. If you are subject to the GDPR, continue to the next steps.

  • Inform your customers why you’re processing their data

Consent is only one of the legal bases that can justify your use of other people’s personal data. You can find the other “lawfulness of processing” justifications in GDPR Article 6. If you choose to process data on the basis of consent, however, there are extra duties involved. Finally, Article 12 requires you to provide clear and transparent information about your activities to your data subjects. This likely will mean updating your privacy policy.

  • Assess your data processing activities and improve protection

A data protection impact assessment will help you understand the risks to the security and privacy of the data you process and decide ways to mitigate those risks. Next, begin implementing data security practices, such as using end-to-end encryption and organizational safeguards, to limit your exposure to data breaches. When beginning new projects, you must follow the principle of “data protection by design and by default.”

  • Make sure you have a data processing agreement with your vendors

You, as the data controller, will be held partly accountable for your third-party clients if they violate their GDPR obligations. So it’s important to have a data processing agreement that establishes the rights and responsibilities of each party. This includes your email vendor, cloud storage provider, and any other subcontractor that handles personal data.

  • Appoint a data protection officer (if necessary)

Many organizations (especially larger ones) are required to designate a data protection officer . The GDPR specifies some of the qualifications, duties and characteristics of this management-level position.

  • Designate a representative in the European Union

Article 27 specifies which non-EU organizations are required to appoint a representative based in one of the EU member states. Recital 80 providers further details about this role.

  • Know what to do if there is a data breach

Articles 33 and 34 lay out your duties in the event personal data is exposed, whether through a hack or any other kind of data breach. The use of strong encryption can mitigate your exposure to fines and reduce your notification obligations if there’s a data breach.

  • Comply with cross-border transfer laws (if applicable)

As with previous EU regulations on the transfer of personal data to non-EU countries, GDPR Article 45 retains tough requirements for organizations wishing to do so. You may be required to self-certify under the Privacy Shield Framework.

By following these steps, along with the steps in our GDPR compliance checklist, you can help avoid drawing scrutiny from EU regulatory authorities.

Déan Teagmháil Linn

Tá súil agam go mbeidh sé seo úsáideach duit. Má theastaíonn Ionadaí AE uait, má tá aon cheist GDPR agat, nó má fuair tú iarratas SAR nó Rialálaí agus má theastaíonn cabhair uait, déan teagmháil linn ag am ar bith. Táimid i gcónaí sásta cabhrú ...
Foireann áitiúil GDPR.

Déan Teagmháil Linn

Recent blogs

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

How to Implement the New AI Law in Your Company

The implementation of the AI Act marks a significant stride towards responsible and fair use of art

Article 14 Guide: Meeting Regulatory Requirements for Personal Data Not Directly Obtained from Data Subjects

Imagine a software-as-a-service (SaaS) company looking to grow its clientele by purchasing leads fr

Faigh Do Chuntas Anois

Socraigh i gceann cúpla nóiméad. Cuir isteach sonraí do chuideachta agus roghnaigh na seirbhísí a theastaíonn uait.

Cruthaigh Cuntas

Téigh i dteagmháil

Níl tú cinnte cén rogha atá le roghnú? Glaoigh, ríomhphost, comhrá a dhéanamh linn
am ar bith.

Déan Teagmháil Linn
06 EOLAS GDPR

Fan Suas chun Dáta

Fág do chuid sonraí anseo agus seolfaimid nuashonruithe agus faisnéis chugat maidir le gach gné den GDPR agus d'Ionadaí an AE. Ní bheidh muid bombard tú le ríomhphoist agus beidh tú in ann a insint dúinn chun stop a chur ag am ar bith.

Tá Ainm Iomlán ag teastáil!

Tá Ríomhphost Gnó ag teastáil!

Tá cuideachta ag teastáil!

Glac leis na Téarmaí agus Coinníollacha agus an Polasaí Príobháideachais