Reading:
General Data Protection Regulation (GDPR)

Image

General Data Protection Regulation (GDPR)

July 28, 2022

The General Data Protection Regulation (GDPR) is the European Union’s data protection law, in force since 25 May 2018. It governs how personal data belonging to people in the EU is collected, stored and used, regardless of where the organisation doing the processing is based.

Why it matters for location data

Location data is usually personal data under the GDPR. A precise position history singles out an individual even without a name attached — it reveals where someone sleeps, works and spends time. Regulators have consistently treated it as identifying, which means every stage of collection and use needs a lawful basis.

Lawful bases and consent

Processing requires one of six lawful bases. For advertising and analytics uses of location data, that basis is normally consent, and the GDPR sets a high bar: it must be freely given, specific, informed and unambiguous, given by clear affirmative action, and as easy to withdraw as it was to give. Pre-ticked boxes and bundled permissions do not qualify.

Individual rights

People can request access to their data, ask for correction or erasure, object to processing, and request portability. Any organisation holding location data needs a working process for answering those requests, not just a policy describing one.

Penalties

Fines reach the greater of €20 million or 4% of worldwide annual turnover for the most serious breaches, which is what moved data protection from a compliance footnote to a board-level concern.

Related: how Tamoco approaches consent and data transparency.



0 Comments

    Leave a Reply

    Arrow-up