EU data privacy law goes into effect amid confusion

Saturday, May 26, 2018

Print this page Email A Friend!

LONDON, United Kingdon (AP) — Lars Andersen's business handles some of the most sensitive data there is — the names and phone numbers of children.

The owner of London-based My Nametags, which makes personalised nametags to iron into children's clothing, says protecting that information is fundamental to his business, which operates in 130 countries.

But starting Friday, My Nametags and most other companies that collect or process the personal information of EU residents must take a number of extra precautions to comply with the new General Data Protection Regulation (GDPR), which the EU calls the most sweeping change in data protection rules in a generation.

While the legislation has been applauded for tackling the thorny question of personal data privacy, the roll-out is also causing confusion. Companies are trying to understand what level of protection different data need, whether this could force them to change the way they do business and innovate, and how to manage the EU's 28 national data regulators who enforce the law.

“Once you try to codify the spirit (of the law) then you get unintended consequences,” Andersen said. “There's been a challenge for us: What actually do I have to do? There are a million sort of answers.”

That uncertainty, together with stiff penalties for violating the law, has convinced internet-based businesses such as, an inbox management firm, and gaming company Ragnarok Online to block EU users from their sites. Pottery Barn, an arm of San Francisco-based housewares retailer Williams-Sonoma Inc, said it would no longer ship to EU addresses. The Los Angeles Times newspaper said it was temporarily putting its website off limits in most EU countries.

The implementation of GDPR has also made data protection an issue in contract negotiations, as firms argue about how to divvy up responsibility for any data breach.

“Deals are being held up by data protection,” said Phil Lee, a partner in privacy security and information at Fieldfisher, a law firm with offices in 18 EU cities. “If something goes wrong, what happens?”

EU countries themselves aren't quite ready for the new rules. Less than half of the 28 member states have adopted national laws to implement GDPR, though the laggards are expected to do so in the next few weeks, according to WilmerHale, an international law firm.

As with most EU-wide regulations, enforcement of the new data protection rules falls to national authorities. While the EU stresses that the law applies to everyone, one of the big outstanding questions is whether regulators will go after any entity that breaks the law, or simply focus on data giants like Google and Facebook .

Lawyers also say it isn't yet clear how regulators will interpret the sometimes general language written into the law. For example, the law says processing of personal data must be “fair” and data should be held “no longer than necessary”.

“It's time to put on your seatbelt and check your airbag,” said D Reed Freeman Jr, a privacy and cyber security expert at WilmerHale. “It's kind of like a lift-off with a rocket. It's about to launch.”

Andersen of My Nametags said the law has already caused problems for his business.

He has been advised that the company website in the Netherlands has to be different from the one in the UK because the two countries are likely to apply the law differently, and has a dispute with a supplier over which of them is responsible for protecting certain data.

UK Information Commissioner Elizabeth Denham has tried to ease concerns, saying the most important thing is for companies to try their best to comply with the law and work with authorities to correct any problems.

“We pride ourselves on being a fair and proportionate regulator, and this will continue under the GDPR,” Denham said in a blog post. “Those who self-report, who engage with us to resolve issues, and who can demonstrate effective accountability arrangements can expect this to be taken into account when we consider any regulatory action.”

The new law comes at a time when advances in technology make data more valuable, and therefore raise the stakes in protecting it.

Now you can read the Jamaica Observer ePaper anytime, anywhere. The Jamaica Observer ePaper is available to you at home or at work, and is the same edition as the printed copy available at




1. We welcome reader comments on the top stories of the day. Some comments may be republished on the website or in the newspaper � email addresses will not be published.

2. Please understand that comments are moderated and it is not always possible to publish all that have been submitted. We will, however, try to publish comments that are representative of all received.

3. We ask that comments are civil and free of libellous or hateful material. Also please stick to the topic under discussion.

4. Please do not write in block capitals since this makes your comment hard to read.

5. Please don't use the comments to advertise. However, our advertising department can be more than accommodating if emailed:

6. If readers wish to report offensive comments, suggest a correction or share a story then please email:

7. Lastly, read our Terms and Conditions and Privacy Policy

comments powered by Disqus



Today's Cartoon

Click image to view full size editorial cartoon