Complex Mathematics

Why weakening GDPR now would be a bad move for data privacy



Earlier this year, the European Commission proposed a GDPR simplification package as part of the broader Omnibus IV initiative, designed to ease the compliance burden for so-called small mid-cap companies.

Under the current rules, companies with fewer than 250 employees may be exempt from maintaining detailed records of data processing activities—but only if their processing is occasional, involves no special categories of data and is unlikely to pose any risk to individuals’ rights. In practice, this exemption is rarely usable.

Matt Cooper

Director of Governance, Risk, and Compliance at Vanta.



Source link