GDPR stands for General Data Protection Regulation, it replaces the existing Data Protection Act (DPA), and introduces a number of changes to the way businesses need to manage personal data. This blog is designed to give you a basic introduction and hopefully encourage you to start the process to allow you to be compliant.
Definition of Personal Data – Personal Data is data that identifies “a living individual” Essentially this means that if you hold any information on any individual then you need to be compliant. Those of you, whose business is wholly b2b, should take note, this includes information you hold on your staff and business email addresses that you hold that contain names.
While this is a European wide regulation, the British Government has already committed to introducing it in UK law. Brexit will make no difference. The fines have also changed and can equate to 2% or 4% of group global turnover depending on the severity of the breach.
In addition, some businesses must designate a Data Protection Officer (DPO). This can be outsourced to a 3rd party. Whilst some business owners will react negatively to the new regulations, my clients are encouraged to embrace the changes, trying to battle against them will prove and uphill and expensive choice. How would you like your personal data to be managed by the companies you have shared it with?
The GDPR comes in to force from May 25th 2018, however you should consider what is required now, create a plan to ensure you minimise your risk. A quick check on the ICO newsletter tells you about the companies that have been fined within the last month!
Useful links:
https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/
https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf (this document is updated as the finer points of GDPR are determined)
Leave A Comment