The General Data Protection Regulation (GDPR) is fundamentally changing the way businesses and organizations collect, process and manage personal data of all kinds. In this article, we will examine the real impact of the changes that GDPR will bring, both at the business and individual level, providing answers to some very important questions about the new European regulation.

As a society, we produce enormous amounts of digital data and information every day. The -effective- protection and safeguarding of personal information is now becoming a necessity, and the laws governing sensitive, personal data now seem inadequate.
The need for more effective privacy legislation will be signaled by the introduction of the European General Data Protection Regulation (GDPR), which will come into force on May 25, 2018.
Among the most notable changes that the new European regulation will bring is the strengthening of the rights and freedoms of individuals related to the protection of their personal data, giving them the ability to even initiate civil legal proceedings against organizations that violate the GDPR.
At the same time, many new obligations are imposed on businesses and organizations that collect, handle or analyze personal data, with significant fines imposed on those who violate the regulation.
More specifically, in cases of non-compliance with the requirements of the GDPR, administrative fines of up to 20,000,000 euros or up to 4% of the total global annual turnover of the previous financial year are foreseen.
So what are the measures that businesses and organizations should take to safeguard their customers' personal data? The task of complying with the GDPR is a process that requires methodicality and special attention, at all stages of its implementation. To achieve the maximum possible result, trust the companies/consultants on security issues, in order to ensure that your business is in full compliance with the new regulation.
Is GDPR essentially something new for businesses?
The General Data Protection Regulation (GDPR) is the new data protection law of the European Union. Until now, the only legal document we could turn to for personal data issues was the European Directive (Data Protection Directive 95/46/EC), which has been in force since 1995.
Although the GDPR maintains many of the principles established by the Data Protection Directive, it is considerably more ambitious. One of the main differences is that the GDPR gives individuals greater control over their personal data and organizations greater responsibility for the data they process. It is also worth noting that any violation of the regulation carries corresponding sanctions.
When does the implementation of the new European Data Protection Regulation become mandatory?
25-05-2018 is the date of mandatory implementation of 679 / 2016 GDPR and the obligation to comply with its requirements by all public and private sector companies headquartered in European Union countries.
What changes will GDPR?
The GDPR introduces significant changes to the lives of individuals and the way businesses operate as it gives extensive jurisdiction to the competent authorities to control the processing of our personal data, regardless of the country we are in. The passage and implementation of the GDPR aims to:
- Strengthening the rightsand freedoms of natural persons concerning the protection of their personal data.
- The need for uniform application of personal data protection rules in the European Union.
What is defined in GDPR? What new roles and processes are added?
- The concept of simple personal data and sensitive personal data and concepts such as "restriction of processing", "profiling", "pseudonymization" are added.
- The definition of "data controller" is established, who is responsible and must be able to demonstrate at all times that he or she is implementing the GDPR.
- The definition of a "data protection officer" (DPO) , who informs and advises the controller or processor and employees who process personal data on their obligations arising from the data protection regulation.
- The obligation of the processor of personal data is foreseen to:Create and maintain a record of data processing operations.
Implement appropriate measures to ensure the processing of personal data.
Inform the Data Protection Officer (DPO) in the event of a data breach. Notify the breaches to the supervisory authority within 72 hours.
What is the competent regulatory authority in Greece?
The regulatory authority in Greece is the Personal Data Protection Authority (PDPA), which operates as a constitutionally established independent Authority. The Authority's supervisory responsibilities include conducting administrative audits, as well as examining relevant complaints, appeals and questions regarding the application of the law and the protection of the rights of applicants when these are affected by data processing.
The A.P.D.P.C. has the right to conduct administrative audits of records, both public and private, ex officio or upon complaint. The audits are carried out by employees of the Department of Auditors, who are accompanied in some cases by members of the Authority. It is noted that the special investigative officers have the right to access any record without any kind of confidentiality being challenged.
After carrying out the required checks, the authority may impose administrative sanctions on the controllers or their representatives, if any, for breach of their obligations or for any other breach affecting the rights of users with regard to the protection of their personal data. Finally, the authority may report violations of the provisions of the law to the competent administrative and judicial authorities.
