{"id":10308,"date":"2019-12-18T10:09:19","date_gmt":"2019-12-18T15:09:19","guid":{"rendered":"https:\/\/blog.brainstation.io\/?p=10308"},"modified":"2020-05-07T12:41:18","modified_gmt":"2020-05-07T16:41:18","slug":"gdpr-explained-how-businesses-protect-personal-data-in-the-eu","status":"publish","type":"post","link":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu","title":{"rendered":"GDPR Explained: How Businesses Protect Personal Data in the EU"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">When the European Union\u2019s General Data Protection Regulation (GDPR) came into full force in May 2018, it was hot on the heels of the Facebook-Cambridge Analytica data scandal. The data breach heard around the world made consumers suddenly <\/span><i><span style=\"font-weight: 400;\">very<\/span><\/i><span style=\"font-weight: 400;\"> aware of how their personal data could be collected and manipulated without their consent. It\u2019s a pressing conversation that continues to evolve alongside rapid advances in technology to this day.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As the internet became increasingly data-driven over the years, the European Union (EU) recognized that the privacy standards they\u2019d had in place since 1995, the European Data Protection Directive, needed updating. In April 2016, the European Parliament adopted the GDPR and asked that all businesses be compliant by 2018. The GDPR embodies the EU\u2019s firm stance on data protection and privacy and applies uniformly to all EU member states (unlike the former directive).&nbsp;<\/span><\/p>\n<h2><b>Does GDPR Apply to You?&nbsp;<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Firstly, it\u2019s important to note that the GDPR has implications outside of the EU. If you\u2019re wondering if this applies to you, ask yourself these 2 simple questions:&nbsp;<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Do you offer goods or services in the EU?<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Are you collecting or processing the personal data of EU citizens or residents for commercial purposes?<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">If you answered yes to either or both of these questions, then you need to comply with GDPR. This actually means that the majority of companies with global reach need to have a data strategy in place to avoid penalties of up to tens of millions of euros.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you decide how and why personal data is being used, you\u2019re likely what the GDPR calls the \u201cData Controller.\u201d This can be a business owner or simply a member of the data team.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Alternatively, if you\u2019re someone who processes data on behalf of a third party, you\u2019re called a \u201cData Processor.\u201d The GDPR has special regulations for processors.&nbsp;&nbsp;<\/span><\/p>\n<h2><b>What\u2019s Considered Personal Data?&nbsp;<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">For a law that\u2019s all about protecting personal data, it\u2019s crucial to understand what kinds of data are included in the equation.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to the <\/span><a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-personal-data_en#answer\"><span style=\"font-weight: 400;\">European Commission<\/span><\/a><span style=\"font-weight: 400;\">, personal data is any piece of information that can identify a living individual. This includes, but isn\u2019t limited to, information such as names and surnames, personal email addresses, home addresses, biometric data and location data.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Information that\u2019s completely anonymous (and can\u2019t be reversed in any way) is not considered personal data. This includes email addresses that are generic (support@company.com) or a company registration number.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The GDPR is technology agnostic, which means personal data must be protected regardless of how it\u2019s being collected, organized, structured, used or deleted.&nbsp;<\/span><\/p>\n<h2><b>7 Principles for Data Protection<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">There isn\u2019t a one-size-fits-all approach to data protection and many parts of the law leave room for interpretation. The GDPR does lay out some guiding principles for processing personal data.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Process the data you collect lawfully, fairly, and transparently.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Collect data for a specific and explicit purpose and only process that data as it relates to that purpose. The only exception is if the data is being used for research, statistical, or scientific purposes for the good of the public.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Minimize the amount of personal data you collect. Don\u2019t collect more than is needed for the intended purpose.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Keep the data you collect up-to-date. If you\u2019re unable to do this, then you must make a reasonable effort to update or delete it quickly.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Personal data can be kept in a form that allows you to identify individuals only for as long as it takes to fulfill your intended purpose. Again, there are exceptions for research, statistical, or scientific purposes.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Have measures in place to process data in a way that safeguards it from unauthorized processing or altering, loss, or damage.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The data controller is ultimately held accountable and must be able to prove compliance.&nbsp;<\/span><\/li>\n<\/ol>\n<h2><b>When is it Okay to Process Personal Data?&nbsp;<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Certain conditions must be met for your data processing to be considered \u201clawful\u201d. Like other regulations of its kind, consent plays a leading role.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There are a few situations where you\u2019d be able to process personal data without consent, including:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">to fulfill a contract such as a background check for employment,<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">a court order, and&nbsp;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">to save a life.&nbsp;<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This list is not extensive, but you can read the full list in Chapter 2, Article 6 of the GDPR.&nbsp;<\/span><\/p>\n<h2><b>Getting Consent to Process Data<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">One of the first things you need to know about getting consent is that you need to prove that it happened. Consent can be given electronically, orally, or in writing as long as it\u2019s an affirmative action (like ticking a box to opt-in).&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re getting consent for more than one action, you need to make each action clear to the individual using clear and plain language. You need to make it as easy and nondisruptive as possible for an individual to revoke consent.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Because consent needs to be <\/span><i><span style=\"font-weight: 400;\">freely<\/span><\/i><span style=\"font-weight: 400;\"> given, you can\u2019t make the execution of a contract (for example, a sale) dependant on providing consent when that personal data isn\u2019t actually needed to fulfill that contract.&nbsp;<\/span><\/p>\n<h2><b>How the GDPR Can Impact Your Data Processes<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The individual, or what the GDPR calls the \u201cdata subject,\u201d has certain rights regarding their personal data. Understanding each of them will help ensure that you have reasonable processes in place to respect them.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Rights include:<\/span><span style=\"font-weight: 400;\">&nbsp;<\/span><\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><b>The right to access data.<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> If requested, you must be able to tell the data subject what personal data is being collected, the purpose of collecting it, who will be processing it, and how long you intend to store it. The data subject can also request a copy of their data free of charge which you must be able to provide in common electronic form.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><b>The right to correct and updated data<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">. You need to be able to quickly update inaccurate or incomplete data if requested by the data subject.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><b>The right to have data erased.<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> The GDPR calls this \u201cthe right to be forgotten\u201d. The data subject can ask that you erase their data, although there are some limitations to this, including a court order.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><b>The right to restrict processing<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">. If the data subject thinks your data is inaccurate, being processed unlawfully, or is no longer required for your intended purpose they can restrict you from processing it.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><b>The right to share their data<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">. The data subject can request their data, which you need to provide in a machine-readable format, so they can transmit that data to another controller.<\/span><\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><b><b>The right to object. <span style=\"font-weight: 400;\">Unless you can come up with a legitimate reason why you need to process someone\u2019s personal data, the data subject has the right to object to you processing it. This is especially applicable when it comes to data being used for marketing purposes.<\/span><\/b><\/b>&nbsp;<\/li>\n<li style=\"font-weight: 400;\"><b>The right not to be subject to an automated decision. <span style=\"font-weight: 400;\">The data subject can refuse to have a significant decision, like a job or credit application, made about their profile automatically without any human intervention.<\/span><\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">When data or information about data is requested, you need to have internal processes in place that enable you to action them within one month of receipt. It needs to be provided in a concise and easy to understand way and can be done in writing, electronically, or orally (if identity can be verified).&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the unfortunate event that you experience a data breach, you\u2019re obligated to inform data subjects within 72 hours.&nbsp;&nbsp;<\/span><\/p>\n<h2><b>What You Can do to Comply&nbsp;<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">When it comes to the GDPR, you must be able to demonstrate compliance before you\u2019re asked.<\/span><\/p>\n<p><a href=\"https:\/\/gdpr.eu\/what-is-gdpr\/\"><span style=\"font-weight: 400;\">GDPR.eu<\/span><\/a><span style=\"font-weight: 400;\"> suggests the following to get started:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Assign responsibility to someone on your team&nbsp;&nbsp;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Document all the details of your data processing practice including why data is processed and how<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure all your staff are properly trained<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Have responsible and compliant contracts with third-party data processors keeping in mind that you\u2019re ultimately accountable&nbsp;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Consider appointing a <\/span><a href=\"https:\/\/gdpr.eu\/data-protection-officer\/\"><span style=\"font-weight: 400;\">Data Protection Officer<\/span><\/a><span style=\"font-weight: 400;\"> (in some cases, you might actually be obligated to have one)&nbsp;<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Ignoring the GDPR comes at a hefty cost. Fines can be up to \u20ac20 million or 4% of your global revenue if higher, not to mention the loss of trust and credibility that comes with a data breach.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With the stakes this high, it\u2019s worth sweating the small stuff. Read the <\/span><a href=\"https:\/\/gdpr.eu\/tag\/gdpr\/\"><span style=\"font-weight: 400;\">entire document on GDPR.eu. <\/span><\/a><span style=\"font-weight: 400;\">&nbsp;&nbsp;<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. <\/p>\n","protected":false},"author":7,"featured_media":10310,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1066,169],"tags":[136,520,1146,1147],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v18.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GDPR Explained: How Businesses Protect Personal Data in the EU | BrainStation\u00ae Blog<\/title>\n<meta name=\"description\" content=\"The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. Here&#039;s what you need to know about the GDPR. \u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR Explained: How Businesses Protect Personal Data in the EU | BrainStation\u00ae Blog\" \/>\n<meta property=\"og:description\" content=\"The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. Here&#039;s what you need to know about the GDPR. \u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu\" \/>\n<meta property=\"og:site_name\" content=\"BrainStation\u00ae Blog\" \/>\n<meta property=\"article:published_time\" content=\"2019-12-18T15:09:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-05-07T16:41:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/d2re7sjnpekmig.cloudfront.net\/prod\/wp-content\/uploads\/2019\/12\/GettyImages-955665910.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2309\" \/>\n\t<meta property=\"og:image:height\" content=\"1299\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"BrainStation\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/brainstation.io\/blog\/#website\",\"url\":\"https:\/\/brainstation.io\/blog\/\",\"name\":\"BrainStation\u00ae Blog\",\"description\":\"The Digital Learning Company\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/brainstation.io\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#primaryimage\",\"url\":\"https:\/\/d2re7sjnpekmig.cloudfront.net\/prod\/wp-content\/uploads\/2019\/12\/GettyImages-955665910.jpg\",\"contentUrl\":\"https:\/\/d2re7sjnpekmig.cloudfront.net\/prod\/wp-content\/uploads\/2019\/12\/GettyImages-955665910.jpg\",\"width\":2309,\"height\":1299,\"caption\":\"General Data Protection Regulation -GDPR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#webpage\",\"url\":\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu\",\"name\":\"GDPR Explained: How Businesses Protect Personal Data in the EU | BrainStation\u00ae Blog\",\"isPartOf\":{\"@id\":\"https:\/\/brainstation.io\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#primaryimage\"},\"datePublished\":\"2019-12-18T15:09:19+00:00\",\"dateModified\":\"2020-05-07T16:41:18+00:00\",\"author\":{\"@id\":\"https:\/\/brainstation.io\/blog\/#\/schema\/person\/9f37983a6c4da6cf5dd422481ac8cf11\"},\"description\":\"The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. Here's what you need to know about the GDPR. \u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/brainstation.io\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR Explained: How Businesses Protect Personal Data in the EU\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/brainstation.io\/blog\/#\/schema\/person\/9f37983a6c4da6cf5dd422481ac8cf11\",\"name\":\"BrainStation\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/brainstation.io\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/80c14b8388838ae1453aec36606b232d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/80c14b8388838ae1453aec36606b232d?s=96&d=mm&r=g\",\"caption\":\"BrainStation\"},\"description\":\"BrainStation is a global leader in digital skills training, empowering businesses and brands to succeed in the digital age. Established in 2012, BrainStation has worked with over 250 instructors from the most innovative companies, developing cutting-edge, real-world digital education that has empowered more than 50,000 professionals and some of the largest corporations in the world.\",\"url\":\"https:\/\/brainstation.io\/blog\/author\/brainstation\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR Explained: How Businesses Protect Personal Data in the EU | BrainStation\u00ae Blog","description":"The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. Here's what you need to know about the GDPR. \u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu","og_locale":"en_US","og_type":"article","og_title":"GDPR Explained: How Businesses Protect Personal Data in the EU | BrainStation\u00ae Blog","og_description":"The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. Here's what you need to know about the GDPR. \u00a0","og_url":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu","og_site_name":"BrainStation\u00ae Blog","article_published_time":"2019-12-18T15:09:19+00:00","article_modified_time":"2020-05-07T16:41:18+00:00","og_image":[{"width":2309,"height":1299,"url":"https:\/\/d2re7sjnpekmig.cloudfront.net\/prod\/wp-content\/uploads\/2019\/12\/GettyImages-955665910.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"BrainStation","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/brainstation.io\/blog\/#website","url":"https:\/\/brainstation.io\/blog\/","name":"BrainStation\u00ae Blog","description":"The Digital Learning Company","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/brainstation.io\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#primaryimage","url":"https:\/\/d2re7sjnpekmig.cloudfront.net\/prod\/wp-content\/uploads\/2019\/12\/GettyImages-955665910.jpg","contentUrl":"https:\/\/d2re7sjnpekmig.cloudfront.net\/prod\/wp-content\/uploads\/2019\/12\/GettyImages-955665910.jpg","width":2309,"height":1299,"caption":"General Data Protection Regulation -GDPR"},{"@type":"WebPage","@id":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#webpage","url":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu","name":"GDPR Explained: How Businesses Protect Personal Data in the EU | BrainStation\u00ae Blog","isPartOf":{"@id":"https:\/\/brainstation.io\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#primaryimage"},"datePublished":"2019-12-18T15:09:19+00:00","dateModified":"2020-05-07T16:41:18+00:00","author":{"@id":"https:\/\/brainstation.io\/blog\/#\/schema\/person\/9f37983a6c4da6cf5dd422481ac8cf11"},"description":"The GDPR embodies the EU\u2019s stance on data protection and privacy and applies to all EU member states. Here's what you need to know about the GDPR. \u00a0","breadcrumb":{"@id":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/brainstation.io\/blog\/gdpr-explained-how-businesses-protect-personal-data-in-the-eu#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/brainstation.io\/blog"},{"@type":"ListItem","position":2,"name":"GDPR Explained: How Businesses Protect Personal Data in the EU"}]},{"@type":"Person","@id":"https:\/\/brainstation.io\/blog\/#\/schema\/person\/9f37983a6c4da6cf5dd422481ac8cf11","name":"BrainStation","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/brainstation.io\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/80c14b8388838ae1453aec36606b232d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/80c14b8388838ae1453aec36606b232d?s=96&d=mm&r=g","caption":"BrainStation"},"description":"BrainStation is a global leader in digital skills training, empowering businesses and brands to succeed in the digital age. Established in 2012, BrainStation has worked with over 250 instructors from the most innovative companies, developing cutting-edge, real-world digital education that has empowered more than 50,000 professionals and some of the largest corporations in the world.","url":"https:\/\/brainstation.io\/blog\/author\/brainstation"}]}},"_links":{"self":[{"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/posts\/10308"}],"collection":[{"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/comments?post=10308"}],"version-history":[{"count":3,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/posts\/10308\/revisions"}],"predecessor-version":[{"id":11425,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/posts\/10308\/revisions\/11425"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/media\/10310"}],"wp:attachment":[{"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/media?parent=10308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/categories?post=10308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/brainstation.io\/blog\/wp-json\/wp\/v2\/tags?post=10308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}