Εφαρμογή κινητών συσκευών για τη συλλογή προσωπικών δεδομένων σε συμμόρφωση με τον Γενικό Κανονισμό για την Προστασία των Δεδομένων (ΓΚΠΔ)
Mobile application for collecting personal data in compliance with General Data Protection Regulation (GDPR)
View/ Open
Keywords
GDPR ; Προσωπικά δεδομέναAbstract
With the General Data Protection Regulation (GDPR) (EU) 2016/679 adopted by the European Parliament in 2016 with effect from May 2018, the regulatory compliance requirements for businesses that process personal data increased significantly. According to the accountability principle, businesses, not only are required to comply but also must be able to prove their compliance in any given moment.
With the GDPR, the increasing complexity of regulatory compliance creates an administrative burden on the operation of businesses and the use of information technology is a tool to mitigate it. In recent years the rapid evolution of mobile devices and the significant familiarity of users with them creates business opportunities for the development of mobile applications in the market of regulatory compliance.
This master's thesis concerns the documentation of requirements and the design of a mobile application and the relevant business plan for its development. The application will enable businesses to collect personal data while providing information to data subjects, obtaining consent from them for specific processing purposes (if applicable) as well as enabling data subjects to object (if applicable) to the processing based on legitimate interest of the business. The data subject will be able to receive in an email a copy of the form he / she filled in and to confirm his / her identity by submitting a unique code that he / she will receive by email / viber or WhatsApp message. The application also assists the deletion / rectification of personal data and consent withdrawal at the request of the data subject and the compliance to data retention period. Revenue generation will be based on the use / purchase of the application (88%) and the provision of consulting services (12%).
The application will be addressed to businesses (legal entities and freelancers) based in the European Union which process personal data and collect them in person.
The investment requires a capital of ~180.000 € to cover the expenses of the two years which will be covered by 50% - 80% by subsidy and the rest by increase in share capital. The development of the application is expected to last 6 months and within the first year 15 months of operation, the company is expected to become profitable. The total profit before taxes in the first six years is expected to be ~2.000.000 €.