Personal data protection law: how to protect your private information

protection of personal data

In the digital age, protecting personal data has become a top priority for every individual. Each of us is constantly providing personal information when we interact with websites, use mobile apps or conduct online transactions. 

In this context, data protection legislation plays a key role in ensuring a safe environment for internet users, preventing abuse and protecting their privacy. 

In this article, we explore the current data protection legislation and how you can protect your private information under it.

What is personal data protection?

Personal data protection refers to legal regulations that guarantee individuals' rights over their private information. 

Personal data is any information that can directly or indirectly identify a person, such as name, address, phone number, email address or even financial information. Their protection is essential to prevent abuses such as identity theft, unauthorized access to bank accounts and other forms of cyber attacks.

In Romania, the protection of personal data is mainly regulated by Personal Data Protection Regulation (EU) 2016/679 (GDPR), adopted by the European Union, and the Law No 190/2018, which regulates its application in our country.

What does GDPR say about the protection of personal data?

GDPR (General Data Protection Regulation) is one of the strictest regulations in the field of personal data protection. The main aim of GDPR is to give individuals more control over how their personal data is collected, processed and stored.

GDPR principles

GDPR is based on several fundamental principles, including:

  • Transparency: Every person must be informed about the collection and processing of his or her personal data, including the purposes of such processing.
  • Lawfulness of processing: Personal data should only be collected and processed for lawful, explicit and legitimate purposes.
  • Data minimization: Only data strictly necessary for the purpose of the collection may be collected.
  • Accuracy: Personal data must be correct and up-to-date.
  • Limiting storage: Data should not be kept longer than necessary for the purposes for which it was collected.
  • Privacy and security: Data must be protected against unauthorized access and other forms of unlawful processing.

Individual rights under GDPR

Individuals have a number of important rights under the GDPR to protect their personal data:

  • Right to informationAnyone can find out what data is being collected about them and for what purposes.
  • Right of access: The individual may request a copy of the personal data collected.
  • Right of rectification: Anyone can request the correction of inaccurate personal data.
  • Right of deletion (right "to be forgotten"): The individual can request deletion of personal data under a number of conditions.
  • Right to restrict processing: A person may request that the processing of their data be restricted.
  • Right to object to processing: Individuals have the right to object to the processing of their data, especially in cases of direct marketing.
  • The right not to be subject to an automatic decision: Individuals should not be subject to decisions based solely on automated data processing.

How do you protect your personal data under the law?

The protection of personal data depends not only on compliance with legal regulations by organizations and authorities, but also on the behaviour of each individual. Here are some key steps you can take to protect your private information:

1. Use strong and unique passwords

One of the easiest and most effective data protection measures is to use strong passwords that include both letters, numbers and special characters. It is also advisable to use unique passwords for each account, avoiding reusing them across different platforms.

2. Enable two-factor authentication (2FA)

Two-factor authentication is an extra layer of security that requires a second code, sent to your mobile phone or generated by an app, in addition to your password. This prevents unauthorized access, even if someone learns your password.

3. Look out for suspicious emails and websites

Phishing is a common way to steal personal data. It is essential not to open emails or messages from unsafe websites and to check the sources carefully before clicking on links or downloading attachments.

4. Read the privacy policy of websites and apps

When using a website or app, it is important to read and understand the privacy policy. Here you will find out what personal data is collected, how it is used and whether it is shared with third parties.

5. Constantly update software and apps

Many cyber attacks rely on software vulnerabilities. Make sure you regularly update operating systems and applications to protect yourself from potential security breaches.

6. Be aware of social networks' privacy settings

Social networks are often used to collect personal data. Regularly check your privacy settings and limit what information is visible to the public. That way you can control who has access to your data and how much of your life is exposed online.

7. Delete old and unusable data

If you have accounts or apps that you no longer use, make sure you delete your personal data and accounts. Keeping them can pose a security risk as unused accounts are often targets for attackers.

Penalties for data protection breaches

If organizations fail to comply with GDPR regulations or national laws, they risk significant penalties. The National Supervisory Authority for Personal Data Processing (ANSPDCP) can impose administrative fines of up to 41TPTP3T of a company's global annual turnover or up to €20 million, depending on the seriousness of the breach.