
New European regulations governing data protection come into force on 25 May next. This General Data Protection Regulation (GDPR) will apply".whenever a European resident is directly affected by data processing, including via the Internet"as the CNIL (Commission Nationale de l'Informatique et des Libertés). This new legislation also concerns data based outside the European Union when it contains information about European citizens.
This small revolution will not spare those involved in business travel - quite the contrary. For several years now, the race for traveller information has been gathering pace, with the personalisation service. The aim of the game for suppliers is to provide their targets with a tailor-made offer or, better still, to anticipate their expectations.
Airlines, railways, airports, hotels, Michelin-starred restaurants, booking platforms, travel agencies: each and every one of these players - and there are more and more of them - is "investigating" the habits of the typical traveller, with increasingly detailed information being collected. It could be as simple as the passenger's favourite seat on a flight from Paris to Paris, or as complex as a flight from Paris to London.Frankfurt than its biometric characteristics - which are gradually coming into widespread use. All in a climate of cybercrime increasingly threatening.
Bringing order to the hunt for data
It was therefore necessary to put some order into this hunt for data, and that is precisely the aim of this new regulation, which aims to strengthen data protection while harmonising the rules within the EU. The RGPD clarifies and strengthens the rights of individuals while defining the duties of companies. The data controller will have to obtain the clear and explicit consent from the individual (opt-in) and be able to prove it. Visit right of access and rectification also forms part of these obligations, as does the right to withdraw consent or the right to be forgotten.
Guardrails
In particular, the new regulation introduces the concept of "data portability. According to the CNIL, this new right "allows individuals to retrieve the data they have supplied in an easily reusable form, and, where appropriate, to transfer it to a third party. The aim here is to give people back control over their data, and to compensate in part for the asymmetry between the data controller and the data subject.." To put it plainly, individuals are taking back control of their information, and their explicit consent is now required when data is collected.
The RGPD introduces two genuinely important new principles. With the "privacy by design"With the first principle, respect for privacy must be taken into account right from the design stage of a database, application or service. With the second principle "privacy by default"In addition to being integrated natively into solutions, devices guaranteeing the integrity of personal data (encryption, pseudonymisation, etc.) are also activated by default.

The European regulation also requires companies to put in place safeguards governing the management of personal data, to map its circulation and to anticipate crisis management in the event of a problem. "The aim is not only to limit the number of risk of vulnerabilitybut also to define in advance how we would operate in the event of an intrusion"sums up Valéry Lynierco-founder of MagicStaya hosting platform that has been working on making its solution compliant. In the event of a data breach, the data controller must notify the CNIL within 72 hours of becoming aware of it. Individuals affected by the hacking must also be notified "as soon as possible".
Among the major points of the RGPD are the following appointment of a referent within the company. This "data protection officer" (DPO, Data protection officer) will play a pivotal role in terms of advice, control, processes and exchanges with the relevant authorities. While it is not compulsory for all companies to appoint such a "conductor", the CNIL "strongly recommends" that they do so.
Rather than seeing regulation as a constraint, some see it as a tool for differentiation, or even a lever for growth. "We want to set an example, and we are going far beyond what is required, because this is a major issue for companies, and it will be even more so in the future."says Valéry Linÿer of MagicStay. This is a colossal investment for a start-up like ours, but it has enabled us to sign up several major groups".
In the event that companies do not identify on their own the benefits to be derived from this new regulation, the sanctions The RGPD clarifies the possible fines, which could be as high as up to €20 million or 4 % of annual worldwide salesThe larger of the two amounts will be taken into account. However, the threat has not yet prompted French companies to take concrete action. According to the barometer published in the first quarter by the Association française des correspondants à la protection des données à caractère personnel (AFCDP), less than one company in five (19 %) believes that it will be compliant with the RGPD on 25 May.


















