Newsflash: GDPR – Legislation & Impact

Newsflash: GDPR – Legislation & Impact

On 25 May 2018, Regulation 2016/679, the General Data Protection Regulation (“GDPR”) came into full force and effect in all 28 EU Member States. All entities that process the data of European Union residents are required to be in full compliance from now onwards. National governments are currently evaluating or implementing their own complimentary legislation. United Kingdom National Legislation On 23 May 2018, The Data Protection Act 2018 received Royal Assent and became law, repealing and replacing the Data Protection Act of 1998. Its primary objective was to apply the GDPR standards to national law as the UK prepares for Brexit in March of 2019. It also empowers the Information Commissioner to effectively regulate and enforce data protection laws, including granting the Information Commissioner the authority to bring criminal proceedings in certain cases. Ireland National Legislation On 24 May 2018, Ireland signed into law the Data Protection Act 2018 (“DPA”), The DPA repeals almost all provisions of the Data Protection Act 1988 and provides for Ireland to enact derogations to GDPR, in the minimal cases where GDPR permits national law derogations. The DPA also expands the discretion of the Data Protection Commission and defines the administrative procedures for complaints, investigations, enforcement, and sanctions under the new data protection regime. Luxembourg National Legislation The Luxembourg data protection bill n°7184, to compliment GDPR, is currently pending in the legislative process. As of 15 May 2018, amendments were still being reviewed and adopted.   Funds Impact GDPR imposes obligations on the investment fund industry directly as funds, investment managers, management companies, and other fund industry actors frequently process personal data for a variety of reasons; this includes legal obligations, contractual and pre-contractual obligations, internal HR purposes, and marketing. For more information on what this means for investment funds in particular, please consult our guide attached. Should you have any questions, our GDPR team can be reached at frmc_gdpr@fundrock.com.