Skip to main content

On November 1, 2017, VodafoneZiggo and Voxius organized a well-attended event on the topic “The European General Data Protection Regulation: Are You Compliant?” The event was part of the semi-annual series of Compliance Round Tables that Voxius organizes for in-house counsel and compliance professionals.

The event was held at VodafoneZiggo’s headquarters, which offers a stunning view of the Amsterdam skyline. Our host, Tim Langelaar, Senior Privacy, Risk & Compliance Manager, welcomed the “sold-out” audience of 50 participants. He expertly demonstrated how VodafoneZiggo has implemented data protection legislation in a practical manner.

The keynote speaker was Jeroen Terstegge, one of the Netherlands’ leading privacy lawyers. Terstegge has 25 years of experience in the field of privacy and, as Philips’ Privacy Officer, was one of the architects of the Binding Corporate Rules (BCRs).

First, the scope of the General Data Protection Regulation (GDPR), which took effect on May 25, 2018, was discussed. Next, the principles governing the processing of personal data were examined. For example, personal data must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. And personal data must be collected for specified, explicit, and legitimate purposes. The “accountability” obligation imposed by the GDPR was also discussed. The session explained what measures data controllers can take to ensure that the processing of personal data is carried out in accordance with the Regulation and how best to demonstrate compliance.

Terstegge also discussed the power of internet companies such as Facebook and Google, noting that these companies are gaining increasing influence, which has implications for privacy. He also addressed the safeguards that must be put in place in order to transfer personal data abroad. Finally, participants were provided with an overview of “Things (not) to do” to help them become privacy-compliant in a timely manner.

As usual, the meeting was chaired by Roland Notermans, who has 20 years of experience with compliance and business conduct programs. Under his professional guidance, participants were encouraged to ask questions and share any insights they might have. After the main session, the participants stayed behind for quite some time to continue discussing the topics in small groups while enjoying some snacks and drinks.

At the request of the participants, we are considering a more comprehensive and practical follow-up session on the GDPR, in which compliance officers will work together to identify practical applications in the workplace.

We look back on a very successful and, above all, engaging meeting, and we will let you know soon about the topic and date of the next meeting.