Why has the GDPR been brought in?
The world today is almost unrecognisable from those quaint days of waiting until 6pm to get the news and physically going to shops to purchase anything we needed. Our lives were private in a way that could not be comprehended today.
In a rather recent, scary article, entitled; ‘I asked Tinder for my data. It sent me 800 pages of my deepest, darkest secrets’ A French journalist reported that in March 2017 she asked the dating app company to grant her access to her personal data, something every EU citizen has a legal right to do. She wrote in her article for The Guardian:
“Some 800 pages came back containing information such as my Facebook “likes”, my photos from Instagram (even after I deleted the associated account), my education, the age-rank of men I was interested in, how many times I connected, when and where every online conversation with every single one of my matches happened … the list goes on.”
The article then provides the opinion of a data scientist:
“I am horrified but absolutely not surprised by this amount of data,” said Olivier Keyes, a data scientist at the University of Washington. “Every app you use regularly on your phone owns the same [kinds of information]. Facebook has thousands of pages about you!”
Another data expert stated:
“We are leaning towards a more and more opaque society, towards an even more intangible world where data collected about you will decide even larger facets of your life. Eventually, your whole existence will be affected.”
Because commercial organisations can collect and store customer data, new regulations have long been required to protect everyone from private information about themselves from being abused and misused.
And the threat is very real. Recently, one of the ‘big four’ accounting firms, Deloitte, was the target of a hacker which resulted in client emails and plans being compromised . And in 2016, Three Mobile was the victim of a brutal cyber-attack which resulted in around 210,200 customers having their personal data breached. It also ended in a PR disaster for the company as customers discovered their names, phone numbers, addresses, dates of births, payment method and some email addresses might have been accessed by the criminals. The GDPR is designed to protect consumers from such breaches.
Article 5 of the GDPR sets out a further six privacy principles, stating that data must be:
• Processed fairly, lawfully and transparently;
• Collected for specified legitimate purposes only;
• Adequate, relevant and limited to what is necessary in relation to its purpose;
• Accurate and kept up to date;
• Stored for no longer than is necessary; and
• Processed in a way that ensures appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage.
What does my business have to do to be GDPR compliant by May 2018?
All UK businesses are required to review and amend their data protection governance policies and procedures. Brexit makes no difference to the application of the GDPR to UK businesses; the government has made it clear the regulations will become part of English law regardless of the UK’s EU membership.
To meet the GDPR compliance requirements on time, organisations need to implement the following:
- Review all current data management processes – this should include an audit to identify any weaknesses in your existing data management policies and procedures.
- Appoint a person dedicated to managing GDPR compliance – this person should have a knowledge of data administration, the backing of senior management and be provided with the resources to prove GDPR principles are being complied with.
- Communicate GDPR guidelines throughout the organisation – internal teams need to be made aware of their responsibilities under the GDPR. For example, marketing departments need to understand that evidence that a person has consented to allow the organisation to process data must be expressly and freely given by the data owner. In other words, people may need to actively ‘opt-in’ to receiving communications from your company after May 2018.
- Consolidate company data to make protecting it easier – many organisations now have data stored on mobile devices and other IT assets which never reach the centralised system. Any data that can be labelled Personally Identifiable Information (PII) should be well-managed and if possible, reduced. Companies should also encrypt centrally held data. If you are exploring the idea of storing and controlling data in the Cloud, look for an encryption solution that only enables an internal representative to unlock the appropriate files.
- Create a robust GDPR communication strategy – multiple communications strands will need to be created as GDPR compliance will be an ongoing requirement from 2018. Not only will the key compliance officer need to keep senior management and the in-house legal team (if applicable) informed of any changes or threats to data protection, employees will need to be reminded of their duties and responsibilities.
To ensure your organisation has the policies and procedures in place to comply with the GDPR, obtaining legal advice is crucial. The penalties for non-compliance may be harsh, not only in monetary terms but reputational damage if customer or client data is breached.
Nalders Solicitors is one of the oldest and largest law firms in Cornwall. Our business solicitors have the commercial acumen and expertise to guide you through GDPR compliance. To make an appointment, please phone our Truro office on 01872 241414.
