What is GDPR?
The General Data Protection Regulations is EU legislation introduced on 25th May 2018 that regulates how companies collect and process EU citizens’ personal data.
GDPR Key Principles
GDPR covers two vital areas:
Personal Data
Information that can directly or indirectly identify someone, including:
- Names, ID numbers and addresses
- Locations and IP addresses
- Cookies
- Health, genetic and biometric data
- Financial information
- RIFD tags
- Data on race, ethnicity, sexual orientation and political opinions
Data Processing
Manual or automatic actions that deal with personal data, including:
- Collecting and recording data
- Storing, altering and erasing data
- Organising and structuring data
- Using data
You need to understand three critical parties involved in data collection and protection:
- Data Subject – the person whose personal information is processed
- Data Controller – the person, company or organisation that chooses how and why the data subject’s information is collected and processed
- Data Processor – a person, company or organisation acting on behalf of the data controller to collect and process data
Who Does GDPR Apply To?
If you or your company collects and stores the personal information of EU citizens, then you must comply with GDPR. Your company’s location is not relevant.
Brexit has not affected data protection in the UK; it has identical requirements for companies under UK GDPR.
Currently, it protects residents in:
- Austria
- Belgium
- Bulgaria
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Estonia
- Finland
- France
- Germany
- Greece
- Hungary
- Ireland
- Italy
- Latvia
- Lithuania
- Luxembourg
- Malta
- Netherlands
- Poland
- Portugal
- Romania
- Slovakia
- Slovenia
- Spain
- Sweden
- UK
As with almost all legislation, some companies are exempt from particular GDPR requirements. Typically, companies and organisations with fewer than 250 employees do not need to comply with many of the record-keeping requirements unless their personal data processing:
- Risks data subjects’ rights and freedoms
- Is not occasional
- Includes the special data categories specified in Article 9
- Includes data surrounding criminal convictions or offences (see Article 10)
Benefits of GDPR Compliance
Effective GDPR compliance measures fulfil your legal requirements and have many other benefits:
Protect Your Customers and Employees
When you take on customers’ and employees’ personal data, you have a moral and legal obligation to protect it.
Encourage Customer Loyalty
Customers want to rely on you to keep their information safe. If they feel secure, they will likely stay with your company.
Conserve Your Reputation
Word of security issues spreads, destroying your company’s reputation and harming future activities and profits.
Prevent Lawsuits and Fines
If GDPR regulators believe you have breached your requirements, they can investigate your data processing. You risk costly fines from them if they find violations; the amount depends on:
- The breach’s severity
- The affected personal data
- Your cooperation with authorities
How to Comply with GDPR
GDPR compliance often appears complex. However, you just need to follow this simple checklist.
1. Appoint a Data Protection Officer
You should have an individual in your company responsible for GDPR compliance. Appointing a DPO at the start of the compliance process allows them to build a system they can manage rather than being shoehorned into an existing structure.
Although GDPR only requires a DPO for particular circumstances, it can help all companies.
2. Identify Your GDPR Regulator
GDPR obligates EU states to provide at least one independent public body to regulate data processing. Your Data Protection Authority (DPA) is your primary GDPR contact. They should:
- Supervise GDPR
- Offer expert advice
- Handle GDPR violations
- Fine non-compliant data controllers and processors
3. Review Your Policies
Regular GDPR reviews are vital to ensure compliance, and whenever you adapt your policies, you should start with an audit.
You should identify what data you collect and store, whether your security is adequate and whether only authorised, necessary individuals can access it.
4. Conduct a Data Protection Impact Assessment
Once you understand your policies, you should then identify the risks your system faces. A Data Protection Impact Assessment (DPIA) pinpoints hazards, risks and mitigation policies.
GDPR has a DPIA template that is an ideal starting place. Then you can optimise it for your company’s needs.
5. Establish a Lawful Basis for Data Processing
Every company has different legal bases for processing customer data. The ICO has identified six, and your DPO should follow them.
- Consent – explicitly requesting and receiving permission from a customer to use their data in specific ways
- Contract – processing customer data to fulfil your contract with them
- Legal Obligation – following necessary steps to process data and comply with GDPR
- Vital Interest – process data to protect interests that affect a data subject’s life
- Public Tasks – performing tasks in the public interest
- Legitimate Interests – using customer data in ways that a customer would expect, perhaps to fulfil your or a third party’s needs, but that does not impact their privacy or could be achieved using varying means
6. Implement Security Measures
You then need to implement GDPR security measures, and cyber security is at the heart of these preventions.
Network security – establish a layered approach to network security with VPNs and firewalls
Data security – use antivirus software, encryptions, DLP systems, tokenisation and data backups
Access controls – control and protect access with multi-factor authentication, privileged access management and identity management
Insider risk management – know your company through employee monitoring, analysis of user and entity activity and third-party activity monitoring
7. Establish Data Subject Protection Rights
Your data subjects have multiple rights to:
- Request and receive the data you have collected
- Request that you delete their personal data
- Object to data processing
- Update their personal data
- Correct inaccurate data
- Request information about your actions with their data
- Receive copies of their collected data
- Limit how you use their data
8. Document Your Compliance
You should always record your security and compliance measures to monitor your processes and identify issues when something goes wrong. It can demonstrate your due diligence to your DPA and helps you optimise your efforts.
9. Implement Vital Training and Policies
Training is critical for reducing the risk of data breaches. Your employees should understand their GDPR requirements, the threats and consequences of breaches and how to respond to them.
Regular training is the best way to update your employees when your processes change. Showcase examples and scenarios to provide actionable advice.
10. Report Any Breaches
If the worst occurs, you must report it promptly. GDPR Article 33 specifies that the data controller should notify the Data Protection Authority within 72 hours of the breach. Therefore, communication between the Data Processor and the Data Controller is vital, although it can get complicated when using third-party Data Processors.
You should detail the nature of the breach, the data categories at risk, the number of records and data subjects affected, the consequences, the measures you took to mitigate risks, and the contact details of the DPO.
Instruct Our Solicitors Today
Our expert solicitors are available to help you fulfil your GDPR obligations. Contact us today to arrange a free consultation where we can learn about your situation and recommend the best resolution.
