Arkhi
/Blog/ News

How GDPR Will Change Your Business. Are You Prepared?

12 May 2022
How GDPR Will Change Your Business. Are You Prepared?

The General Data Protection Regulation (GDPR) privacy laws are coming into effect on the 25th of May 2018 and while it’s primarily an EU law, the requirements are going to change the way Australian organisations handle information. The new laws are not just a suggested direction; they’re a strict regulation and the consequences of not complying are huge.

What is it?

Every time we open our phones or jump on our laptop, we’re sharing personal information with businesses and organisations.

From sending work emails to Facebook messages; sharing Google docs, paying phone bills and shopping online – we share a lot of information without giving it half a thought. The GDPR laws are to set boundaries on what data is actually being collected and how it is being used.

From the 25th of May, businesses and organisations will need to be able to explain what data they’re collecting and why. It won’t just be a matter of businesses updating their privacy policy, companies are going to be held accountable for the information they are collecting and the reasoning behind it. And the penalties for not complying with the new regulations are huge – up to 20 million Euros or 4 percent of global revenue, whichever is higher.

What does this mean for Australian companies?

If you have any operation in the EU, you have to comply with the new rules. Even if you don’t currently, you run the risk of potential sanctions if European customers eventually sign up to your services.

Basically, the regulations put individuals in control of their data, who sees it and how it is used. Some key points from the jurisdiction include:

By not complying with the rules, companies run the risk of being shut out of a market of 500 million consumers.

How to be prepared

If your business gathers any type of personal data, understanding these regulations is essential – even if you only operate within Australia. Not complying with these rules puts you at risk the moment you have a European customer sign up to your services.

Personal data can be anything from name, age, IP address and profession to more sensitive information like ethnicity, political views, union memberships and biometric information – so if you’re collecting any of this information, you need to be able to explain why and be able to hand  the data over to anyone who asks.

The GDPR laws will be some of the largest changes to privacy regulations in the last decade and we can expect other countries to follow suit. Even if you have no current connection to the EU, it would be a smart move to understand these regulations and how they could potentially affect your business.

Ready to get real about growth?

[Let's Talk >]