Are your “experts” giving you the best advice: why every business needs a GDPR advisory service?

Have you thought about how a GDPR advisory service could impact your business? Aligning with compliance is something that every business should be striving for, but there are a few pitfalls you should be aware of. This article offers you an insight into what you need to consider about GDPR when paying for services including web design, CCTV and IT support.

Why GDPR more complex than you think

When your business chooses a vendor, it’s reasonable for you to expect them to provide you with advice that’s in your best interests. After all, many businesses sell their services on the basis of added value. Their experience in their industry comes at a price, right? But what you probably don’t anticipate is that this advice, or lack of it, could leave you exposed to the law.

So when it comes to web design, or CCTV or IT Support, sectors that most businesses will engage with, you would think that complying with the law goes without saying. However, this is not always the case, and poor transparency about GDPR leaves many businesses vulnerable to breaking regulations.

Web Design

Most businesses need web design to promote their products and services, which means they are often relying on other experts to get their GDPR right.

For any business that processes personal data, you need a bespoke privacy notice on your website. Not only does this comply with the law, but it also creates trust within your clients and demonstrates that you understand the importance of protecting their data.

Within your website, there are a variety of additional data protection concerns. These include whether you are asking for consent (which would not be legally valid if you don’t provide an adequate privacy notice), whether you have a valid cookie policy and the disclosure of the personal data of your clients/staff, such as displaying the names of your clients as a referral.

CCTV

Physical surveillance isn’t free of rules and regulations, either. The setup of a CCTV system should follow specific guidelines. A recent court case in the UK showed where this could go wrong. It resulted in a fine for domestic use of £17,000. While this was a case between neighbours, the lesson it can teach businesses is still significant.

How many companies installing CCTV advise that if it covers any public area, it should be registered, or even that there is a code to follow? Have they advised that an impact assessment may be needed, or that you have a responsibility to provide signage that provides fair processing? I’m not even getting into the monitoring of CCTV systems, which is usually done by 3rd parties.

Using a GDPR advisory service can help you overcome these obstacles and keep your business safe with CCTV while abiding by all the regulations.

IT support

Business owners hiring IT support naturally expect that their support partner already has a robust knowledge of GDPR, and will ensure that whatever they’re working on will be up to scratch.

In fact, IT support companies heralded the upcoming GDPR as an opportunity to sell additional compliance services, and for the most part, those services were welcomed. However, the vast majority of companies I have worked with have similar tales of woe. In many cases, I’ve found that the advice from IT support companies did not fulfil the IT requirements for GDPR.

What’s worse, if you want to align yourselves with compliance, any company you share data with needs to employ policies and processes to themselves to be in line with GDPR. If this isn’t the case, you can no longer claim that your business is aligned.

I must have come across over 100 companies in the IT support sector supporting SMEs, and only one has declared themselves compliant, while most have little interest. If you allow remote access on to your IT systems, you are by definition, sharing data.

Conclusion

No one said that GDPR was straight-forward or easy, but if you’re paying for a service or support to help grow your business, GDPR stipulates that you undertake due diligence around the data protection practices of partners, and is quite specific about how you should treat partners that can’t provide assurances, this is your risk.

If you want to understand how your vendors should be supporting you, and the advice they should be providing you with, get in touch with The Compliance Consultancy. We will be happy to answer any of your questions.