In recent years, we've all heard the term "personal data." To a greater or lesser extent, we've aligned our business processes with the legal requirements in this area.
The number of inspections by Roskomnadzor that have identified violations in this area this year is steadily approaching 100%. According to the Roskomnadzor statistics for the Central Federal District for the first half of 2019, there were 131 violations in 17 inspections.
Our daily reality includes "cold" calls from various organizations with which we might have never had any dealings. Calls from mobile phones on behalf of large businesses (banks, insurance companies, etc.). SMS messages that cannot be opted out of. Their numbers seem to be only increasing.
Balancing business interests with compliance with regulatory requirements is a true challenge for businesses of any size. The list and sufficiency of the measures applied is proposed to be assessed independently by law. One positive aspect is that risks can be reduced by avoiding the most common violations. Moreover, this does not require additional costs or implementing technically complex measures.
And so, the top violation on the list is the breach of conditions for processing personal data. Examples include an incomplete list of processing purposes, categories of subjects, as well as third parties who have access to the data.
The truth we must accept is this: it is impossible to create a one-size-fits-all consent for all situations—neither for employees, nor for clients, nor for users of a software product. Although it is very desirable.
Every time you launch a new marketing campaign or change a sales system, take 5 minutes to ensure that the consent includes:
1) the name and address of the company – the operator,
2) purposes of processing,
3) list of data,
4) list of actions with the data and methods of processing,
5) cross-border transfer and/or transfer to third parties (specifying particular countries and third parties),
6) duration of the consent and
7) method of withdrawal.
Few templates from the internet can boast compliance with all criteria, so they can be borrowed, but with caution and addendums.
Did auditors gain access to documents containing personal data? — Consent is required specifying the purpose (conducting the audit), name, and address of the auditing company. Has the company delivering goods for the online store changed? — Consent obtained during client registration on the website is no longer sufficient. A reference to a partner list will not provide 100% peace of mind, but it is better than nothing.
The processing of end-user data of software deserves special mention. When we want to know our user as well as possible and send them relevant offers. When data is collected and stored, even though a license key is sufficient for product registration. We can use such data with the subject's consent, but we cannot tie the ability to provide the core service/sell the product to mandatory marketing communications. This is not only about personal data, but also about advertising legislation.
Other conditions are no less challenging to fulfill. The list of purposes should not be excessive. The principle one purpose – one consent applies. That is, obtaining consent for the processing of a job applicant's resume data and its inclusion in the personnel reserve with one signature will not be possible. As a compromise, viable examples are those where each purpose is highlighted in a separate paragraph in one document, and the subject is given the opportunity to write 'agree' / 'disagree' in each case.
And finally, what are personal data? How to understand from the vague definition given in the law ('any information relating to an identified or identifiable natural person'), whether a specific case falls under its action? Roskomnadzor promised to approve the personal data matrix by the end of 2018. The deadline was postponed to the end of 2019. We are waiting.
What else are we waiting for:
- Draft Law No. 04/13/09-19/00095069. Simplification of the consent form. Legalization of electronic consent form (checkbox, SMS, etc.). Currently, practice is dual; the court can either apply by analogy the rules for paper consent or recognize electronic consent as inappropriate.
- Draft Law No. 729516-7. Increase in fines. For repeated violations of the localization requirement (initial data collection in databases on the territory of the Russian Federation) – 18 million rubles. Change in the procedure for imposing fines. Will we multiply the fine amount by the number of subjects whose consent is deemed improper?
And the personal data subjects are waiting for the incessant calls and messages, which are impossible to stop, to cease. I am not interested in credit; contextual advertising hinders my content viewing, and I remember that my car insurance is being downloaded.
Source: habr.com
