The challenge of complying with the GDPR should not be underestimated, nor should the consequences of failing to do so.
There is more to GDPR than sending an email asking everyone on your marketing list whether they are content to stay on your marketing list. It doesn’t just prevent you from adding that little pre-ticked opt-in box at the end of an email or form. It also affects matters such as whether or not you can google applicants for new positions and check their social medial accounts, how you market to your customers/clients and, how you respond to requests for the release of personal information (not forgetting whether or not you should have retained that information in the first place).
GDPR represents a huge overhaul of the existing data protection law which has stood since 1998 and introduces conceptual changes in the way in which data protection works, new and onerous obligations on businesses, changes in regulatory oversight and in liability/ penalties for non-compliance for those businesses affected.
External companies offering to ‘do’ GDPR for you are proliferating. However GDPR compliance demands a culture change within businesses in the UK so that we start to take data protection compliance seriously and create compliant cultures from within and maintain those cultures or face the consequences. Failure to comply with the GDPR could have serious implications for your business’s reputation, attract claims by aggrieved data subjects, and expose you to fines up to €20m or 4% of the total worldwide annual turnover of an undertaking (whichever is higher).
However, it doesn’t have to be the scary and expensive minefield which you have been hearing about. The key is preparation; having the correct systems and documentation in place is crucial. The new regime introduced by the GDPR, planning for it and compliance with it is well covered by information freely available on the ICO website. We have put together some Frequently Asked Questions for you.
Does the GDPR apply to my business?
What does the GDPR mean for my business?
- Principle 1: Lawfulness, fairness and transparency
- Principle 2: Purpose limitation
- Principle 3: Data minimisation
- Principle 4: Accuracy
- Principle 5: Storage limitation
- Principle 6: Integrity and confidentiality
- Principle 7: Accountability
What is personal data?
What does processing data mean?
What are the lawful grounds for processing personal data?
- for the performance of a contract (if the data subject is a party);
- to comply with a legal obligation;
- to protect the vital interests of the data subject or another natural person;
- to perform a task carried out in the public interest; and/or
- for the pursuit of the legitimate interests of your business or a third party
What should I do if I process personal data?
What rights do the people whose information I hold have?
| Data subject right/request | Comment |
| To be given access to personal data held about them | The GDPR expands the mandatory categories of information which must be suppliedYou must provide a copy of the personal data free of charge |
| To have inaccuracies corrected | This pre-existing right has not significantly changed under the GDPRHowever, you must now notify any third parties with whom you have shared data if the data subject requests any corrections |
| To have information erased (the right to be forgotten) | This is a new right to have personal data erased under specific circumstances.You must implement new systems and procedures to facilitate this, and to notify affected third parties about the exercise of this right. |
| To object to direct marketing | This is an absolute right—once an individual objects, you must stop processing their data for direct marketing purposes.The main difference from the pre-GDPR regime is the need to provide information about the right, which should be reflected in privacy notices |
| To prevent automated decision-making and profiling | The GDPR preserves the previous position, with only minor changes—the explicit consent of the data subject is a valid basis for evaluation on the basis of automated profiling |
| To be provided with their data in an electronic and commonly used format | This is a new right (known as data portability) |
The GDPR also imposes shorter deadlines for dealing with data subject requests, i.e. one month from receipt of the request.
What if I hold information on children?
Why am I getting all these emails?
Do I need to appoint a Data Protection Officer?
We are about to start a project that involves handling a lot of personal data. Is there anything we need to do?
We have messed up and processed personal data without a lawful ground for doing so. What now?
To find out more about how we can advise you on GDPR please fill in our contact form, or phone our Truro office on 01872 241414.
Enquire
Latest News
Nine common mistakes in debt recovery
Debt recovery is often a delicate balancing act for any business. You must ensure your business is protected from bad debts, however, you do not want to jeopardise a good business relationship by mishandling a disputed debt. ‘If you take the wrong action, miss...
Legal considerations when using AI in your business
Are you already using or considering using AI (artificial intelligence) in your business; whether in the form of product delivery to your customers or clients, or to help in the day-to-day administration of your business? AI is fast becoming an accessible and often...
Why your social media contest needs clear terms and conditions
Social media contests have become a popular way for businesses to engage with existing customers, drive up new user participation, increase brand visibility and to foster new sales through marketing data and analysis. However, running a successful campaign requires...



