Spanish DPA Issues GDPR Guidelines

Alston & Bird
Contact

On January 26, 2017, the Spanish data protection authority (“AEPD”) published three guidance papers on the implementation of the general data protection regulation (“GDPR”). Although the guidance is primarily directed at small and medium-sized companies, it gives a snapshot on how the AEPD reads the GDPR and is thus relevant for all companies having operations in Spain.

  • GDPR Guide for Controllers: the guide summarizes the requirements of the GDPR while providing practical recommendations on how to implement them. The guide also contains a questionnaire to help controllers make a self-assessment of their privacy practices in light of the GDPR.
  • Guide on the Privacy Notices: the guide summarizes the requirements of the GDPR and provides for practical recommendations as to how notices should be delivered to individuals, including through which specific means and channels. Importantly, the AEPD recommends a layered approach to information notices whereby basic information is provided in a table format which is immediately visible to individuals, and detailed information is provided in a second layer. The AEPD invites companies to review their notices and procedures as of now, and in any case before the GDPR fully applies in May 2018.
  • Guidelines for Contracts between Controllers and Processors: the guidelines describes the requirements of the GDPR with respect to vendor management and provides for a list of provisions which should be part of a data processing agreement.  An annex to the guidelines contains model clauses which companies may use in the situations where the processor  processes the controller’s personal data exclusively in its own premises and systems.

The AEPD’s press release is available here.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Alston & Bird | Attorney Advertising

Written by:

Alston & Bird
Contact
more
less

Alston & Bird on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide