News sometimes coincides with regulatory changes! The Cambridge Analytics/Facebook scandal involving the misuse of personal data serves as a stark reminder. The GDPR could well be a major reform, not only for data location but also for user protection (that's you and me). For now, however, it remains a complex undertaking for all businesses, especially law firms.
GDPR in brief
The General Data Protection Regulation (GDPR) is a European regulation passed in 2016. It comes into force in member states on May 25, 2018.
The GDPR concerns all private or public organizations which collect and process so-called personal or even sensitive data of EU residents.
Personal data includes your personal or professional contact details, lifestyle habits, economic and financial data, connection data and geolocation. So-called sensitive data relates to your ethnic origins, religious beliefs, political opinions, trade union membership, genetics, biometrics, health, criminal convictions and national identification number.
In a context of dematerialization and decentralization of data, the GDPR aims to guarantee the security and confidentiality of your data and that of your customers.
What impacts for your office?
As a lawyer, you are required to collect and process both personal and sensitive data. Therefore, you are obligated to comply with the GDPR. This involves appointing a Data Protection Officer, collecting a minimum amount of personal data, guaranteeing your clients' rights regarding their data, auditing your internal systems in terms of security and confidentiality, and ensuring that any subcontractors you use comply with the GDPR (see " Preparing in 6 Steps" - CNIL ).
Your obligations also depend on your role in data processing. Indeed, there is an important distinction in the GDPR between the person who collects the data (i.e. Data Controller) and the person who processes it (i.e. Data Processor). So, if you store the data you collect yourself (on your computer, USB stick, external hard drive, local server, etc.), you are considered both a Data Controller and a Data Processor. In this case, you must guarantee the security and confidentiality of your data yourself. This means, for example, setting up redundancy, backups, encryption of your data, etc.
This can be complex but above all far from your area of expertise. Furthermore, in the event of non-compliance with the GDPR, you risk a fine of up to 20 million euros or 4% of your global turnover (see Article 83 of the GDPR).
Jarvis, your dedicated Data Processor
Fortunately at Jarvis Legal, the security and confidentiality of your data has always been at the heart of our concerns, well before the arrival of the GDPR. We have always ensured that your data is hosted in France in an ultra-secure manner.
With Jarvis, you no longer have to worry about these security and confidentiality obligations of your data. It is in fact we who assume this role of Data Processor for you. Jarvis provides you with all the guarantees in terms of security and confidentiality in strict compliance with the GDPR. You can concentrate on managing your files and interacting with your clients with peace of mind. Jarvis takes care of the rest.
Locally installed software: be careful!
Many lawyers still use software installed locally (on their hard drive or local server). Warning: this software automatically makes you the Data Processor. They delegate the daily management of the security and confidentiality of your data to you! Yet another strong argument in favor of Jarvis over locally installed management software. To paraphrase John Bowden Connally, Nixon's Treasury Secretary, regarding the dollar: “GDPR? our software, your problem! »
In fact, the solutions are best placed to enable you to be compliant, without investment on your part. However, you must avoid non-European solutions, which therefore do not comply with the legislation. We can cite solutions based on Sharepoint or Microsoft, or Russian or American solutions (some of which are available on the French market). Your customers' data as well as yours are not secure under the conditions required by the legislator!
In conclusion, choose solution publishers who are French or from the European Union and imperatively Saas or Cloud. So you don't have any difficulty being in compliance yourself!
