The typical ticked boxes in subscription forms are no more enough: in four months from now every company will have to ensure that the consents on processing of sensitive data.
Certification bodies and Italy's DPA can then issue certifications. However, these need to follow some "certification criteria" (as demanded in art. 42(5) GDPR) which must be as well identified by the Garante.
Il Garante ha preso le distanze da entità o aziende che hanno offerto finora certificazioni alle imprese, per due motivi (come si può anche vedere nello schema soprastante).
One of the many new concepts introduced by the GDPR - the EU General Data Protection Regulation - is the Data Protection Impact Assessment (DPIA), regulated at art. 35. The DPIA can be defined as a process designed to.
As you may already know, the new GDPR (General Data Protection Regulation) will be effective from May 2018, introducing a new framework for everyone who processes EU citizens' personal data.
2015 came to an end and we at Chino.io are curious to see what 2016 will bring for digital healthcare in the EU. Last year a lot of things happened in this area and we would like to highlight the most important ones.