GDPR: a European framework to better protect personal data
The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, and governs the collection and use of personal data within the European Union. Its objective is clear: give citizens back control over their personal information and ensure respect for their fundamental rights.
The GDPR provides several rights for data subjects:
- Right to be informed about the collection and use of their data.
- Right of access to their personal data.
- Right to rectification of inaccurate data.
- Right to object to the processing of their data.
- Right to erasure (“right to be forgotten”).
- Right to data portability.
This regulation also introduces increased accountability for organizations and strengthens the powers of supervisory authorities, such as CNIL in France. Particular attention is paid to the protection of vulnerable populations, elderly people, minors, and people with disabilities.
Who is concerned by the GDPR?
The GDPR applies to any organization that processes personal data of European citizens, whether a company, association, or public institution. Its scope is broad and not limited to digital tools or websites.
Paper files, administrative records, employment contracts, client documents and contractual relationships with partners are also concerned. Each organization must implement appropriate measures to prevent risks of loss, alteration or unauthorized access to data.
An organization dedicated to privacy protection
To ensure GDPR compliance, we have appointed a Data Protection Officer (DPO) and a GDPR Officer. Working closely with management, they play a central role in driving and monitoring compliance.
The DPO, registered with CNIL, intervenes to:
- Support and advise the company and its teams on GDPR obligations.
- Monitor compliance with European regulations and national legal provisions.
- Respond to requests and questions from data subjects regarding their personal data.
- Maintain the relationship with the supervisory authority, particularly in case of incident or audit.
We are also supported by FCN Data, a French company specialized in data protection, to consolidate our practices and tools.
Exercise your rights
For any question concerning your personal data or to exercise your rights (access, rectification, erasure, objection, portability), contact our Data Protection Officer:
- Email: dpo@trybu.io
- By mail: Trÿbu, DPO · 87 rue du Fontenoy, 59100 Roubaix, France
- Supervisory authority: CNIL, www.cnil.fr