학술논문

GDPR and Suppliers in SMEs
Document Type
Conference
Source
2022 17th Iberian Conference on Information Systems and Technologies (CISTI) Information Systems and Technologies (CISTI), 2022 17th Iberian Conference on. :1-6 Jun, 2022
Subject
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Computing and Processing
Robotics and Control Systems
Signal Processing and Analysis
Terminology
Force
Europe
Organizations
Regulation
Security
General Data Protection Regulation
GDPR
SME
Agreement
Supplier
Contract
Language
ISSN
2166-0727
Abstract
The General Data Protection Regulation (GDPR) EU 2016/679 came into force in May 2018, obliging organizations to change all processes that treat citizens Europeans' data.This Regulation is critical because it enshrines hefty fines for all organizations and individuals who do not comply. One of the main changes is the written agreements with all suppliers, which share personal data.More than 95% of the business world are Small-Medium Enterprises (SMEs), and SMEs represent 99,9% of business in Portugal. However, SMEs have scarce resources, thus making it challenging for these organizations to comply with GDPR and, in particular, to solve the written agreements.The authors have worked with SMEs to comply with RGPD and have developed a methodology to fulfill the supplier's agreements.We will show the results obtained and discuss the main challenges SMEs face in such a large regulatory.