Yleinen tietosuoja-asetus (GDPR) luo yhdenmukaiset säännöt, joita sovelletaan kaikkeen henkilötietojen käsittelyyn, jota suorittavat Euroopan talousalueella (ETA) sijaitsevat organisaatiot tai joka kohdistuu yksityishenkilöihin EU:ssa. Tietosuoja-asetusta sovelletaan niin julkisen kuin yksityisen sektorin organisaatioihin niiden koosta riippumatta. Yleisen tietosuoja-asetuksen ensisijaisena tavoitteena on varmistaa, että henkilötiedoilla on sama korkeatasoinen suoja kaikissa EU- ja ETA-maissa. Tämä vahvistaa sekä yksilöiden että tietoja käsittelevien organisaatioiden oikeusvarmuutta ja tarjoaa korkeatasoisen suojan ihmisille.
Asetus tuli voimaan 24.5.2016, ja sitä on sovellettu 25.5.2018 alkaen.
How can I apply for the European Data Protection Seal?
Controllers should formally submit their EU-wide certification criteria to:
the competent data protection authority (DPA) in the EEA country where the scheme owners have their headquarters;
the competent data protection authority (DPA) in the EEA country where a certification body operating the certification mechanism have their headquarters, considering the member state in which the most certificates are likely to be issued.
How can my processing operations or my organisation become GDPR certified?
Under the GDPR, certification is conducted by national certification bodies or by the competent national data protection authorities (Art. 42(5) GDPR).
For further information, we recommend contacting the relevant national DPA for your organisation. You can find a overview of all EEA DPAs here.
Miten pysyn Euroopan tietosuojaneuvoston työn tasalla?
Tietosuojaneuvosto julkaisee säännöllisesti tiedotteita, uutisia, blogeja ja muuta sisältöä verkkosivustollaan ja sosiaalisen median kanavissaan (Twitter: @EU_EDPB; LinkedIn: Euroopan tietosuojaneuvosto) pitääkseen tietosuojayhteisön ja suuren yleisön ajan tasalla työstään.
Tietosuojaneuvoston verkkosivustolla on myös kaksi RSS-syötettä, joista voit tilata päivityksiä tietosuojaneuvoston uutisista ja uusimmista julkaisuista.
The deadline for submitting comments to a public consultation has expired, can I still submit comments?
Unfortunately, the EDPB cannot consider late contributions as part of the public consultation.
My organisation would like to become a certification body, how can we become accredited?
Certification bodies are accredited by the national data protection authorities (DPA) or by the national accreditation body (named in accordance with Regulation 17065/2012). For further information regarding certification bodies, we recommend contacting the national DPA in your country. You can find an overview of all EEA DPAs here.
We are constantly working on the translation of our documents into the official EU languages. All static content, as well as press releases and documents officially adopted by the Board, such as Guidelines, will be made available in these languages.
This process takes time and various steps need to be completed in order to provide translations of the best quality.
Please note that documents undergoing public consultation are usually not translated. It is only after the public consultation has been concluded and a final version of the document has been adopted by the Board that these documents will be translated.
Do you think your data has been lost or stolen?
The GDPR puts in place clear procedures in case of a data breach. If a data breach poses a risk, companies and organisations holding your data have to inform the relevant data protection authority within 72 hours or without undue further delay. If the leak poses a high risk to you, then you must also be informed personally.
I think my data protection rights have been violated, what can I do?
If you believe your data protection rights have been violated you can contact the organisation holding your data, contact your national data protection authority (DPA), or go to a national court.
DPAs can conduct investigations and impose sanctions where necessary. You can find the contact details for all EEA DPAs here.
What are my rights under the GDPR?
All individuals residing in the European Economic Area (EEA) have the right to the protection of their personal data.
More specifically, under the GDPR, you have several rights
Right to be informed
Right of access
Right to rectification
Right to restriction of processing
Right to data portability
Right to object
Right not be subject to a decision based solely on automated processing.