General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)


Shop for magnets online with Magnosphere

Our online magnets shop is 100% secure, providing complete peace of mind when shopping with us. We do not store any of your credit card details and we do not use or share any of your personal information (except to provide you with updates of your order). f you want strong and powerful rare earth magnets, improved corrosion resistance NdFeB (Neodymium magnets), high temperature magnets or even bonded magnets, we offer it. If you require custom sized magnets, we can produce it for you. If you need SmCo and NdFeB with very tight tolerances, we can assist. And if you are not sure what you need, our technical support will guide you.


General Data Protection Regulation (GDPR) requirements, deadlines and facts

GDPR is a regulation that requires businesses to protect the personal data and privacy of EU citizens for transactions that occur within EU member states. And non-compliance could cost companies dearly. Here’s what every company that does business in Europe needs to know about GDPR.

Companies that collect data on citizens in European Union (EU) countries will need to comply with strict new rules around protecting customer data by May 25. The General Data Protection Regulation (GDPR) is expected to set a new standard for consumer rights regarding their data, but companies will be challenged as they put systems and processes in place to comply.

Compliance will cause some concerns and new expectations of security teams. For example, the GDPR takes a wide view of what constitutes personal identification information. Companies will need the same level of protection for things like an individual’s IP address or cookie data as they do for name, address and Social Security number.

The GDPR leaves much to interpretation. It says that companies must provide a “reasonable” level of protection for personal data, for example, but does not define what constitutes “reasonable.” This gives the GDPR governing body a lot of leeway when it comes to assessing fines for data breaches and non-compliance.

Time is running out to meet the deadline, so CSO has compiled what any business needs to know about the GDPR, along with advice for meeting its requirements. Many of the requirements do not relate directly to information security, but the processes and system changes needed to comply could affect existing security systems and protocols.


What is the GDPR?

The European Parliament adopted in April 2016, replacing an outdated data protection directive from 1995. It carries provisions that require businesses to protect the personal data and privacy of EU citizens for transactions that occur within EU member states. The GDPR also regulates the exportation of personal data outside the EU.

The provisions are consistent across all 28 EU member states, which means that companies have just one standard to meet within the EU. However, that standard is quite high and will require most companies to make a large investment to meet and to administer.


What types of privacy data does the GDPR protect?

  • Basic identity information such as name, address and ID numbers
  • Web data such as location, IP address, cookie data and RFID tags
  • Health and genetic data
  • Biometric data
  • Racial or ethnic data
  • Political opinions
  • Sexual orientation

Which companies does the GDPR affect?

Any company that stores or processes personal information about EU citizens within EU states must comply with the GDPR, even if they do not have a business presence within the EU. Specific criteria for companies required to comply are:

  • A presence in an EU country.
  • No presence in the EU, but it processes personal data of European residents.
  • More than 250 employees.
  • Fewer than 250 employees but its data-processing impacts the rights and freedoms of data subjects, is not occasional, or includes certain types of sensitive personal data. That effectively means almost all companies, showed that 92 percent of U.S. companies consider GDPR a top data protection priority.

When does my company need to be in compliance?

Companies must be able to show compliance by May 25, 2018.


Who within my company will be responsible for compliance?

The GDPR defines several roles that are responsible for ensuring compliance: data controller, data processor and the data protection officer (DPO). The data controller defines how personal data is processed and the purposes for which it is processed. The controller is also responsible for making sure that outside contractors comply.

Data processors may be the internal groups that maintain and process personal data records or any outsourcing firm that performs all or part of those activities. The GDPR holds processors liable for breaches or non-compliance. It’s possible, then, that both your company and processing partner such as a cloud provider will be liable for penalties even if the fault is entirely on the processing partner.

The GDPR requires the controller and the processor to designate a DPO to oversee data security strategy and GDPR compliance. Companies are required to have a DPO if they process or store large amounts of EU citizen data, process or store special personal data, regularly monitor data subjects, or are a public authority. Some public entities such as law enforcement may be exempt from the DPO requirement.


How does the GDPR affect third-party and customer contracts?

The GDPR places equal liability on data controllers (the organization that owns the data) and data processors (outside organizations that help manage that data). A third-party processor not in compliance means your organization is not in compliance. The new regulation also has strict rules for reporting breaches that everyone in the chain must be able to comply with. Organizations must also inform customers of their rights under GDPR.

What this means is that all existing contracts with processors (e.g., cloud providers, SaaS vendors, or payroll service providers) and customers need to spell out responsibilities. The revised contracts also need to define consistent processes for how data is managed and protected, and how breaches are reported.

“The largest exercise is on the procurement side of the house—your third-party vendors, your sourcing relationships that are processing data on your behalf,” says Mathew Lewis, global head of banking and regulatory practice at legal service provider Axiom. “There’s a whole grouping of vendors that have access to this personal data and GDPR lays out very clearly that you need to ensure that all of those third parties are adhering to GDPR and processing the data accordingly.”

Client contracts also need to reflect the regulatory changes, says Lewis. “Client contracts take a number of different forms, whether they are online click-throughs or formal agreements where you make commitments to how you view, access, and process data.”

Before those contracts can be revised, business leaders, IT, and security teams need to understand how the data is stored and processed and agree on a compliant process for reporting. “A pretty sizable exercise is required by the technology groups, the CISO, and data governance team to understand what data fits within the firm, where it’s being stored or processed, and where it’s being exported outside the company. Once you understand those data flows and the impact on the business, you can start to identify the vendors you need to be most focused on both from an information security perspective, how you manage those relationships going forward, and how you memorialize that in the contract itself,” says Lewis.

The GDPR might also change the mindset of business and security teams toward data. Most companies see their data and the processes they use to mine it as an asset, but that perception will change, says Lewis. “Given GDPR’s explicit consent and firms needing to be much more granular in their understanding of data and data flows, there’s a whole set of liabilities that now exist with the accumulation of data,” says Lewis. “That’s quite a different frame of mind both for legal and compliance, but maybe more important for the way the business thinks about the accumulation and usage of that data and for information security groups and how they think about managing that data.”

“Data is leaving the firm in all kinds of ways,” says Lewis. “While the CISO and the technology groups need to be able to track all of that, you also need to put protection in place.” Those protections need to be spelled out in the contract so the outside firms understand what they can and cannot do with the data.

Lewis notes that by going through the process of defining obligations and responsibilities, it prepares a company to handle GDPR compliance operationally. “If one of your vendors says, ‘You were hacked last night,’ did they know who to call and how to respond as part of meeting the regulatory requirements,” he says.

The 72-hour reporting window that the GDPR requires makes it especially important that vendors know how to properly report a breach. “If a vendor was hacked and you’re one of thousands of clients, do they notify your procurement department or an account person or someone in accounts receivables? It could come in all kinds of ways,” says Lewis.

You want a clearly defined path in the contract for the information to get to the person in your organization responsible for reporting the breach. “A regulator is not going to say you shouldn’t have had a breach. They are going to say you should have had the policies, procedures, and response structure in place to solve for that quickly,” says Lewis.

Larger companies might have thousands of contracts to update. Complicating that challenge is that it needs to be done late in the compliance process. Before you can define responsibilities and responsibilities, you must know exactly what data you have, where and how it is processed, and the data flows. “That’s left a lot of institutions racing toward the deadline trying to complete the technical and operational issues and having to play catch-up on putting the right contract in place to enforce that. A lot of firms have not done any renegotiation of contract terms.”

That begs the question: What happens if the contracts aren’t all in place by the May deadline? Lewis sees several risks to not completing the contracts:

  • Operational: If you haven’t agreed on what your processes will be with a vendor, it’s not clear how you will be operating under GDPR.
  • Vendor management: Under GDPR, you need to know how your vendors operate including their security framework and how they manage data. Without that knowledge, you don’t know the risk they present.
  • Regulatory fines: Lewis notes that the EU is known for its willingness to levy steep fines for regulatory non-compliance. If a breach occurs, not having contracts in place might well work against the company. “Not having a contract is an indication you don’t know what your vendors are doing, and that is a larger management issue about what infrastructure you’re using and how you’re treating the data,” says Lewis. “It gives the regulator an idea of how organized you are and how well you understand your data flows.”

We ship our Magnets worldwid via Sea or Air Shipment

Magnet Magnetic attraction and repulsion force of magnets, Magnetism, Rare Earth Magnets, Neo magnets, Neodymium Iron Boron magnets, Neodymium Magnets, NdBFe magnets, NdFeB magnets, NIB magnets, Super magnets, Super Magnetic Discs Block Countersunk Sphere


Buy Neodymium Magnets at Magnosphere and get a better deal!

Magnosphere produces magnets at great prices, produced and delivered on time for all areas of industry, automotive, aerospace, electronics as well as in the design sector, trade fair construction, offices and for the home.

We are an ISO certified shop and carry the Trusted Shops seal. We have successfully completed more than 400,000 orders and offer our ever-growing customer base 24/7 customer service.

All items are available for immediate delivery in large numbers with daily dispatch. Our selection is your win! Thousands of satisfied customers! Buy from a company with the highest quality standards and customer service with flexible and diverse payment options and conditions.

We can also custom manufacture these to fit your exact specifications using our in-house global manufacturing facilities and team of experienced engineers. Need high quantities of magnets at the lowest and fairest price possible? Just let us know what you are looking for and contact our Customer Care Team by sending us a request for quote! We'll work with you to determine the most economical way of providing you with what you need.

Trust in our experience and convince yourself of our service and our products and we look forward to welcoming you to our magnet shop at Magnosphere. You are welcome to contact us by eMail: info(at)magnosphere.co.uk. Available 24/7 x 365 and we are also there for you on public holidays! Or just give us a call.


ROHS-Directive

ROHS-Directive Magnosphere conforms to the RoHs directive and the Reach and PFOS regulations. Directive 2002/96 / EC of the European Parliament and of the Council, of January 27, 2003, on waste electrical and electronic equipment (WEEE).


Magnete aus Neodym (NdFeB) - Die Supermagnete, starke Magnete, Neodym-Magnete, Starke Neodym Magnete, Magnetfolie, Magnetband, Magnetstreifen, Magnetklebeband, Magnetschilder, Magnetetiketten, Magnetleiste, Werkzeughalter, Messerhalter, Messerblock magnetisch, Schlüsselbrett, Eisenfolie, Ferrofolie, Metallfolie, Eisenband, Ferroband, Metallband, Stahlband, Selbstklebende Neodym Magnete, Magnete für Magnettafel, Starke Magnete, Neodym-Magnete, Ferrite, Ferrit-Magnete, SmCo Samarium Magnets, Alnico Magnete, Dauermagnete, Permanentmagnete, Supermagnete, Kühlschrankmagnete, Büromagnete, Organisationsmagnete, Schulmagnete, Magnete Tier, Hufeisenmagnet, Magnethaken, Magnetöse, Topfmagnet mit öse, Scheibenmagnet, Ringmagnet, Stabmagnet, Magnetsysteme, Taschenlampe


We are very proud to offer excellent customer service. We know that without our clients, we would not be here. If you have any questions about your order or something else, please call or email us!: info(at)magnosphere.co.uk
24 / 7 x 365 Including holiday periods! Our customer service team is available to help you!