The GDPR is still on everyone's lips and, although the topic is hardly new, it continues to cause confusion and uncertainty. Our article brings clarity.
What is the GDPR?
The General Data Protection Regulation (GDPR, in German Datenschutz-Grundverordnung or DSGVO) is an EU law that governs the processing of personal data. It came into force on 25 May 2018 and applies to every company that processes personal data of EU citizens, regardless of where that company is located.
Why the GDPR?
The aim of the GDPR is to strengthen privacy and the protection of personal data and to ensure that such data is processed securely and lawfully. Companies now have to obtain the consent of the data subject before processing their data, for example, and inform them of their rights to access, rectification and erasure of data.
Consequences of the GDPR
It is important to familiarise yourself with the GDPR and to make sure that your own company acts in accordance with it. GDPR-compliant data protection management is an important factor here.

Companies that breach the GDPR can face heavy fines of up to 20 million euros or 4% of annual worldwide turnover, whichever amount is higher.
Who is responsible for a website's GDPR compliance?
Responsibility for complying with the General Data Protection Regulation (GDPR) on a website can lie with various parties, depending on the circumstances.
- The website operator: As a rule, the operator of a website, meaning the company that runs it, is responsible for GDPR compliance on the website. This applies both to the collection, processing and use of personal data by the website itself and to third-party services used on the website.
- The data protection officer: Under certain circumstances a company must appoint a data protection officer (DPO). The DPO is responsible for implementing and monitoring the GDPR within the company and can also be responsible for GDPR compliance on the website.
- The web developer: In some cases the web developer also bears responsibility for implementing the technical and organisational measures that ensure the website is operated in accordance with the GDPR; this includes setting up technical safeguards and implementing data protection requirements.
It is important to note that responsibility for GDPR compliance is not always clearly assigned and that several parties may be able to be responsible for complying with the GDPR.
It is therefore important to define responsibilities within the company precisely and to make sure that everyone involved takes the necessary steps to ensure GDPR compliance.
Which data may be collected without consent under the GDPR?
Under the General Data Protection Regulation (GDPR), personal data may be collected without consent if one of the following conditions applies:

-
Contractual necessity: Where processing the data is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract.
-
Legal obligation: Where processing is necessary for compliance with a legal obligation to which the controller is subject.
-
Protection of vital interests: Where processing is necessary in order to protect the vital interests of the data subject or of another natural person.
-
Public interest: Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
-
Legitimate interests: Where processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
It is important to note that these conditions can differ from case to case and that the processing of personal data should always take place on a legal basis.
ELECOS Team
Writes at ELECOS about websites, data protection and productive working.
