Baltimore Sun

Puzzling EU data privacy law takes effect

Countries, firms struggle with how to implement it

- By Danica Kirka

LONDON — Lars Andersen’s business handles some of the most sensitive data there is — the names and phone numbers of children.

The owner of London-based My Nametags, which makes personaliz­ed nametags to iron into children’s clothing, says protecting that informatio­n is fundamenta­l to his business, which operates in 130 countries.

But starting Friday, My Nametags and most other companies that collect or process the personal informatio­n of EU residents now must take a number of extra precaution­s to comply with the new General Data Protection Regulation, which the EUcalls the most sweeping change in data protection rules in a generation.

While the legislatio­n has been applauded for tackling the thorny question of personal data privacy, the rollout is causing confusion.

Companies are trying to understand what level of protection different data need, whether this could force them to change the way they do business and innovate, and how to manage the EU’s 28 national data regulators, who enforce the law.

“Once you try to codify the spirit (of the law) — then you get unintended consequenc­es,” Andersen said. “There’s been a challenge for us: What actually do I have to do? There are a million sort of answers.”

That uncertaint­y, together with stiff penalties for violating the law, has convinced internet-based businesses such as Unroll.me, an inbox management firm, and gaming company Ragnarok Online to block EU users My Nametags chief Lars Andersen says determinin­g what his company must do to comply is confusing at best. from their sites.

Pottery Barn, an arm of San Franciscob­ased housewares retailer Williams-Sonoma Inc., said it would no longer ship to EU addresses. The Los Angeles Times said it was temporaril­y putting its website off limits in most EU countries. The Baltimore Sun, like the Times a Tronc newspaper, is also affected.

The implementa­tion of GDPR has also made data protection an issue in contract negotiatio­ns as firms argue about how to divvy up responsibi­lity for any data breach.

“Deals are being held up by data protection,” said Phil Lee, a partner in privacy security and informatio­n at Fieldfishe­r, a law firm with offices in 18 EUcities. “If something goes wrong, what happens?”

EU countries as a whole aren’t ready for the new rules. Less than half of the 28 member states have adopted national laws to implement GDPR, though the laggards are expected to do so in the next few weeks, according to WilmerHale, an internatio­nal law firm.

As with most EU-wide regulation­s, enforcemen­t of the new rules falls to national authoritie­s.

While the EU stresses that the law applies to everyone, one of the big outstandin­g questions is whether regulators will go after any entity that breaks the law or focus on data giants like Google and Facebook.

Lawyers also say it isn’t yet clear how regulators will interpret the sometimes general language written into the law.

For example, the law says processing of personal data must be “fair” and data should be held “no longer than necessary.”

Andersen of MyNametags said the law has already caused problems for his business.

He has been advised that the company website in the Netherland­s has to be different from the one in the U.K. because the two countries are likely to apply the law differentl­y, and has a dispute with a supplier over which of them is responsibl­e for protecting certain data.

U.K. Informatio­n Commission­er Elizabeth Denham has tried to ease concerns, saying the most important thing is for companies to try their best to comply with the law and work with authoritie­s to correct any problems.

“We pride ourselves on being a fair and proportion­ate regulator and this will continue under the GDPR,” Denham said in a blog post.

 ?? MATT DUNHAM/AP ??
MATT DUNHAM/AP

Newspapers in English

Newspapers from United States