“The Compliance Consultancy delivered exactly what I had been looking for, high-level expertise and consultancy but focussed on delivery for the smaller business. I’m now confident that we’re compliant with the GDPR requirements”

Spencer Nute - Managing Director, Invew Energy

90% of Businesses not ready for GDPR

Legal firm Blake Morgan published a recent survey, which has revealed 9 out of 10 UK businesses still have not made crucial updates to their privacy policies which is one of the key requirements to changes in the forthcoming new data protection laws.

As time runs out to comply with the General Data Protection Regulation (GDPR), the survey found many organisations may be at risk of non-compliance, risking regulatory action and reputational and brand damage for not getting their house in order.

With the massive growth of the digital economy, GDPR represents the biggest shift in data protection for many years and all organisations which retain or process personal information will need to comply. The new law focuses on greater transparency as to how personal data is collected, retained and processed, makes organisations more accountable and gives enhanced rights to those whose personal data is being collected and processed.

It is backed up with a significantly higher fines regime for the most serious breaches of up to £17m (€20m) or 4% of worldwide turnover (whichever is greater) and a requirement to notify personal data breaches within 72 hours where they are likely to result in a risk to people’s rights and freedoms.

They commented that “GDPR Compliance is good corporate housekeeping.  Not only will it avoid running the risk of financially and reputationally damaging fines or sanctions – ultimately it will assure the public’s trust in your organisation at a time when data privacy and security are more important than ever before.  As the UK’s data protection regulator ICO has recently highlighted GDPR is essentially about trust.”

Key Research findings included:

  1. Only around one in ten businesses (13%) had updated privacy policies, one of the significant requirements of GDPR.
  2. Around four out of ten businesses (39%) had not taken any steps at all to prepare for the new law – leaving just months to act and exposure to ICO action.
  3. Around one in five businesses (21%) did not currently have a senior person in place responsible for data protection.
  4. More than three quarters of businesses (76%) had not put in place systems to ensure data security breaches are notified in line with GDPR.
  5. More than three quarters of businesses (77%) had not reviewed their data processing contracts which will be under greater scrutiny under GDPR.

“The Compliance Consultancy delivered exactly what I had been looking for, high-level expertise and consultancy but focussed on delivery for the smaller business. I’m now confident that we’re compliant with the GDPR requirements”

Spencer Nute - Managing Director, Invew Energy

If you have concerns about complying with GDPR our data protection experts are available to answer your questions on 0161 951 5660 or click here to arrange a 30-minute review of your options with one of our GDPR consultants at a time to suit you.

We’ve also produced a complementary Guide to GDPR for SME’s which lists in plain English what you and your business needs to do to become compliant, click here to download.