Here we look at some other new areas being introduced next May.

If you use Cloud Services to store data you will need to ensure that the company storing the data is compliant, it is your responsibility to do so. The larger cloud hosting companies are very aware of GDPR and are making preparations to provide you with assdurances to avoid this necessity, but hosting data out of the EU does not mean you don’t need to GDPR compliant, it actually makes it more complicated.

The definition of what constitutes “personal data” has also changed to include new digital forms of ID, and is covered in a future blog.

From May 2018, if you suffer a breach, the regulations state that you must notify the ICO within 72 hours. Furthermore the way of handle a breach will change, and we would certainly recommend you to employ an expert to avoid the potential of fines. This is a key area to be prepared for.

The fines have also changed and can equate to 2% or 4% of group global turnover depending on the severity of the breach. This however doesn’t limit your exposure, depending on the type of breach, the ICO can instruct an Assessor to conduct an assessment, and these professionals can charge upwards of £5,000 per day. Of further consideration is your brand damage, and the clean-up operation. The fines have been designed to get you to buy in to the GDPR principles, it’s much easier and less costly to minimise your exposure than deal with a breach you’ve taken less than reasonable steps to avoid.

Useful links:

https://ico.org.uk/

https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/

https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf (this document is updated as the finer points of GDPR are determined)