Expert article
Autor: Erne Mraznica
JEL: F52, G14
doi: 10.5937/bankarstvo1704166M
SCINDEX
Summary: On May, 4th 2016 the General Data Protection Regulation (GDPR) was published in the Official Gazette of the EU, which will be in force from May, 25th 2018. The goal of the Regulation is the harmonization of the personal data protection at the EU level, the larger extent of control for the persons whose data are being processed (data subjects) and the improved management of modern risks in this area. Banks, by the nature of their business, are among the largest processors of personal data and during the process of complying with the GDPR will be in the position to conduct a full assessment of their existing regulatory and infrastructural personal data protection framework. At the same time, this will be an opportunity to correct the potential shortcomings in the existing processes and to significantly raise awareness about the organization of personal data protection standards, especially having in mind the strict sanctions in case of non-compliance.