The General Data Protection Regulation (GDPR) was introduced in 2018 in an effort to give European citizens more control over their personal data. The regulation applies to any company that processes the data of individuals in the EU, regardless of whether the company is based inside or outside the EU.

Although the GDPR has generally been well received, there are still many myths and misconceptions about what it entails. In this blog post, we debunk some of the most common GDPR myths and help you understand the regulation even better.

Myth #1: The GDPR Only Applies to Companies Based in the EU

This is a widespread myth that is often discussed in the business world. Many mistakenly believe that the General Data Protection Regulation (GDPR) only applies to companies based in the European Union (EU). But that's not true. As mentioned above, the GDPR applies to any company that processes the data of individuals in the EU, regardless of whether the company is based inside or outside the EU. So if your company has customers in Europe, you must be GDPR-compliant.

This also applies to companies that don't have an establishment in the EU but offer their products or services to EU citizens. It's important for companies worldwide to be aware of this and to make sure they meet the GDPR requirements to avoid penalties and fines.

Myth #2: Only Large Companies Are Affected by Fines

That's not quite right. Under the General Data Protection Regulation (GDPR), all organizations that collect, process, and store personal data can face fines for non-compliance, regardless of their size or type. This also applies to small and medium-sized enterprises, charities, government agencies, and other entities that process personal data.

The GDPR provides for a tiered system of fines based on the severity of the violation, and an organization's size and financial resources are taken into account when determining the amount of the fine. However, the GDPR makes it clear that fines are not the only penalty for non-compliance. Supervisory authorities have a range of enforcement tools at their disposal, such as ordering organizations to stop data processing or delete personal data, and imposing a temporary or permanent ban on data processing activities.

Myth #3: The GDPR Means I Can No Longer Send Marketing Emails Without the Explicit Consent of Everyone on My Mailing List

Fact: You can still send marketing emails under the GDPR, but you need a lawful basis to do so. One of the legal bases for processing personal data is "legitimate interest". This means that in Germany, you may send marketing emails to people who are already customers, provided they had the opportunity to opt out of receiving such emails and other specific criteria set out in German competition law are met. If you don't have a legitimate interest basis, you must obtain explicit consent from individuals before sending them marketing emails. For example, if someone has unsubscribed from your mailing list, you need their explicit consent before adding them back to your list. And even if someone has consented to receiving marketing emails, they can withdraw their consent at any time by using the "unsubscribe" link in your emails or by contacting you directly.

Myth #4: GDPR Compliance Is Expensive and Time-Consuming

A common myth about the GDPR is that compliance is expensive and time-consuming. While it's true that implementing the necessary measures requires some effort, the costs and time involved are usually manageable and can even lead to long-term savings.

Like any major compliance initiative, GDPR compliance requires a certain upfront investment of time and money. However, once you have established data protection policies and procedures and trained your employees accordingly — which is easiest done by engaging an external data protection officer with the right expertise — GDPR compliance shouldn't cost you much time or money anymore.

A great way to save time and money is to use ready-made data protection tools like heyData. With heyData, you can quickly and easily implement the necessary data protection measures and ensure your GDPR compliance. The data protection software can, for example, help you automatically generate your privacy policy, carry out Data Protection Impact Assessments (DPIAs), log your data processing, and much more. This saves you not only time and money but also stress, and it minimizes the risk of fines and legal consequences. So in reality, the myth of expensive and time-consuming GDPR compliance doesn't necessarily hold true.

Myth #5: All of a Company's Processing Activities Require the DPO's Approval

Under the GDPR, companies must ensure that they protect the personal data they process and guarantee compliance with data protection laws. The most common question companies have is whether they need the approval of the data protection officer (DPO) to carry out all of their processing activities.

The answer is no. If a company is not required to appoint a DPO, it is not necessary to obtain the DPO's approval for all processing activities. However, the DPO is responsible for ensuring that the company acts in compliance with the GDPR. Companies must also ensure that they have an appropriate legal basis for processing personal data, such as the data subject's consent or the performance of a contract. There are also certain processing activities that can take place without consent, such as compliance with legal obligations or the protection of legitimate interests.

Overall, companies do not need to obtain the DPO's approval for all processing activities. Instead, they must ensure that they act in compliance with the GDPR and have an appropriate legal basis for their processing.

Conclusion

Even five years after the GDPR came into force, there is still some confusion surrounding the regulation. We hope this blog post has helped clear up some of the myths around it. If you're still unsure how the GDPR applies to your company or what steps you need to take to comply, reach out to heyData's data protection experts — we're happy to help!