
You may have heard rumblings about GDPR—General Data Protection Regulation—and wondered what exactly it is and whether it affects your business. Read on for a breakdown that shares what you really need to know.
GDPR went into effect on May 25, 2018. If you're a European Union citizen or company or are a non-EU company that offers goods and/or services or monitors the behavior of EU data subjects, this applies to you. Since you may not always know if a customer is an EU citizen, the better assumption is that it applies.
What's the goal? To introduce a single data protection law that increases privacy for individuals by enforcing stronger security rules for companies that handle personal data.
But what does it mean? The GDPR sets rules relating to the protection of people's fundamental rights and freedoms regarding the processing of personal data. Under the European Charter of Fundamental Rights Article 8(1), the protection of natural persons with regard to the processing of personal data is a fundamental right. Prior to the GDPR, this right was protected by the Data Protective Directive. The GDPR expands on the DPD and requires additional elements of protection.
Personal data includes anything that relates to someone's identity, specifically including name, email address, bank details, social media updates, medical history and computer IP address.
Under the GDPR, when is it OK for travel companies to collect personal data? It depends on three conditions:
A travel company is allowed to retain personal data as long as there is a legitimate business interest. Therefore, consider revising your document retention policy.
CONSENT
When it comes to obtaining consent from your customers, be sure to have an intelligible and easily accessible form available. The GDPR requires customers to "opt in" to consent rather than having to "opt out." This form should be distinguishable from other matters and include clear and plain language as well as the right to withdraw consent at any time. This is an example consent form for an individual company:

Photo courtesy of Jeff Ment.
For minors, the same rules apply and consent for children under 16 must be given by a parent or legal guardian.
Also worth noting: Under the GDPR, individuals have the right to be forgotten. If an individual requests that their data be scrubbed, you must comply unless there's a legal purpose for retaining the data.
If you have a contract with third parties, only disclose necessary data. The third party will be responsible for the data they handle and should destroy it when the legitimate purpose is complete. Should they want to use the data for marketing purposes, they would need to obtain their own consent. Note that it's unwise to take responsibility for third-party consent yourself.
The consent form should also link to the privacy policy that contains detailed information about how the customer's data is used, stored, et cetera, along with the following:
Within the privacy policy, be sure to tell customers who you are, how their personal data will be collected, what type of information is collected, how it will be used and who has access to their information. Additionally, provide an option to opt out and detail how they can access their information.
STORAGE OF PERSONAL DATA
To be in compliance with stored personal data, you must keep a record of all current and existing data, how and when a customer provided consent, how their data is being protected—you'll want encryption and firewalls, how the data is being used, and monitoring protocols to avoid a breach.
What you can do right now:
If there's a serious breach? You must report it within 72 hours.
Be sure to describe the nature of the personal data breach including where, if possible; the categories and approximate number of data subjects concerned; and the categories and approximate number of personal data records concerned. Describe the likely consequences of the personal data breach and the measures taken or proposed by the controller to address the personal data breach including, where appropriate, measures to mitigate its possible adverse effects. Only notify individuals if the breach is considered "high-risk."
Penalties for noncompliance are steep: a fine up to $22.8 million (€20 million) or 4 percent of annual turnover, whichever is higher.
Information courtesy of Jeff Ment. To learn more, visit Ment Law.