Data protection reform - (not) an issue?
Prof. Spangenberg presented new data protection regulations at the 9th IMS Breakfast.
Ensuring a uniformly high level of data protection throughout the EU and consistent responsibilities for protecting personal data from misuse —these are, in broad terms, the objectives of the new EU General Data Protection Regulation (EU GDPR), which takes effect on May 25, 2018, and is the topic of the 9th IMS Breakfast .
What makes it unique is that it applies not only to companies based in Europe, but also to companies that use data from EU citizens.
In Germany alone, 200 laws must be amended to implement the regulation. Prof. Spangenberg presented these regulations and the resulting requirements for companies in a forceful and clear manner. This is because the regulation imposes a wide range of obligations on companies. They must:
- familiarize themselves with the changed legal requirements,
- create an inventory of processes and responsibilities involving the processing of personal data,
- identify the level of protection required and assess risks,
- plan, implement, and monitor technical and organizational safeguards—design secure processes and establish an appropriate organizational structure,
- and establish procedures for handling “data breaches.”
However, according to Prof. Spangenberg, one in three companies has so far ignored the requirements that will soon take effect; on the other hand, companies face a fine of 20 million euros or up to 4% of their annual revenue for non-compliance. Regional companies are keeping a close eye on this issue, as demonstrated by the lively participation of 20 company representatives at the IMS breakfast. Stefan Riedel, Account Manager at TÜV Rheinland Akademie GmbH—co-organizers of the IMS breakfast—highlighted additional training opportunities in this area.
In addition to Prof. Spangenberg’s remarks, Dr. Jörg Bentlage, Data Protection Officer (DPO) and Managing Director of Anthesis Group Germany, spoke about the responsibilities of a corporate DPO. This is because, according to the EU GDPR, government agencies and a wide range of companies are required to appoint a Data Protection Officer (DPO). His presentation was streamed virtually and recorded with the support of the Center for e-Learning, making it available for future educational use. Many thanks to Enrico Schuster and Andreas Sommer!
A prerequisite for implementing data protection is systematic information security management. In addition to quality, environmental, energy, and occupational safety management systems, Prof. Spangenberg also teaches this topic in our “Integrated Management Systems” and “Integrated Management” degree programmes, equipping our students with an important skill for the job market.
First floor