LoginSubscribe Now
International In-house Counsel Journal Logo
International In-house Counsel Journal Logo
  • Home
  • Business Sectors
  • Areas of Law
  • Editorial Board
  • Write a Paper
  • Subscribe
  • Books
  • Reports
  • Back Issues
  • Terms and Conditions
  • Cookie Policy
  • Privacy Policy
  • PLS LogoCopyright & permissions
© 2026 International In-house Counsel Journal Ltd. | ISSN 1754-0607 | Picture Credits: Freepix, Unsplash and by permission of the authors
Back to library search

GDPR Regulatory Compliance and the Role of Internal Audit: Theoretical & Practical Approach

December 2018Data ProtectionFMCG

Abstract

The General Data Protection Regulation (GDPR) is already in place from 25 May 2018, when it superseded EU member state implementations of the 1995 Data Protection Directive (DPD). Compliance with the GDPR is a legal requirement and can directly impact an Organization’s reputation and shareholder’s value. Sanctions for non-compliance include fines (maximum 4% global turnover), orders to stop using data or for measures to make its use compliant, regulator audits, and “class action” by privacy groups (e.g. consumer privacy groups or prompted by Works Councils). Other data protection sanctions include criminal sanctions for certain breaches and there is increasing support in the UK and other jurisdictions for extending personal liability to directors and managers. The GDPR introduces new obligations, strengthens existing requirements and enhances people’s rights in relation to their personal data. The legislation applies not only to EU affiliates that process personal data of anyone regardless of where they reside, but also applies to non-EU affiliates that process personal data relating to people within the EU. According to an old adage, there is no such thing as bad publicity. Data leakage cases throughout the years proved that it is not enough for companies to develop and implement comprehensive privacy practices, they need also the assurance that the practices are functioning as intended in an ever-changing risk environment and internal audit is the most important provider for this.

Subscribe to reador
PLS Logo Copyright & permissions

Author

Nikolaos Dounis

Cluster Internal Control & Compliance Manager, Imperial Tobacco Group, Greece

Related Papers

India's New Regime of Personal Data Protection - Comprehensive yet Comprehensible…
India unveiled a draft of its Personal Data Protection legislation for public comments in November 2022. The proposed law christened as the Digital Personal Data Protection Bill, 2022 will be...Read more
Portrait image of Dev Bajpai
Dev Bajpai
Wholetime Director & Chief Legal Officer, Hindustan Unilever Limited, India
A Critical Examination of Albania’s New Data Protection Regime and Its Implications for Employee Privacy
The adoption of Law No 124/2024 ‘On the Protection of Personal Data’ marks a major transformation in Albania’s data protection framework.1 By repealing Law No 9887/2008 and aligning domestic law...Read more
Portrait image of Enik Pogace
Enik Pogace
Head of Employee Relations Division, Bank of Albania, Albania
Borderless AI, Fragmented Regulations Navigating New Legal Frontier
AI is no longer a futuristic idea, the promise of tomorrow; it is woven into the fabric of contemporary business, revolutionizing how organizations operate, compete and succeed. AI has moved...Read more
Portrait image of Vijayalakshmi Natarajan
Vijayalakshmi Natarajan
VP, Associate General Counsel |Board Director, Harman (Samsung), India
The Evolving Legal Landscape of Intermediary Liability in India: A Deep Dive
India’s tryst with internet intermediary liability can be traced back almost two decades to when the Information Technology Act (IT Act), 2000 saw the light of day. With the rapid...Read more
Portrait image of Amit Sindhwani
Amit Sindhwani
Head of IPR, Usha International, India
Portrait image of Rajendra Kumar
Rajendra Kumar
Founding Partner RKR & Partners, RKR & Partners, India