Skip to content

General Data Protection Regulation (GDPR)

Radical legislative changes – offenders facing administrative fines in the order of millions of euros

Among other requirements, the General Data Protection Regulation (GDPR) imposes rigid compliance requirements on companies in the event of cyber attacks: Any data protection breach must now be notified to the data protection supervisory authority not later than within 72 hours. If this time limit is exceeded or no notification is effected, administrative fines of millions of euros may be imposed. Operators of critical infrastructures (i.e. entities that are vital for the functioning of the community) must additionally comply with the requirements of the IT Security Act and, in this regard, in particular take appropriate organisational and technical safeguards to avoid any interference with the functioning of their information technology systems and furnish proof of compliance with these standards to the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik; BSI) every two years.

 

News and insights

test tubes and dropper

News: 09 February 2024

Allen & Overy conseille le groupe Sartorius sur son augmentation de capital d'un montant de 1,4 milliard d'euros

Frankfurt am Main - Allen & Overy a conseillé le groupe Sartorius sur son augmentation de capital d'un montant total de 1,4 milliard d'euros. La transaction comprenait le placement de 613 497 actions…

Lire la suite
Artists impression of a major development

Publications: 15 November 2023

Les risques associés à la mise en oeuvre de CSRD doivent être anticipés

De nombreuses entreprises engagent le chantier de la mise en œuvre de la directive du 14 décembre 2022 Corporate Sustainability Reporting Directive (CSRD), leur imposant la publication annuelle d’un…

Lire la suite

Expertises connexes