What is GDPR?

The General Data Protection Regulations is EU legislation introduced on 25th May 2018 that regulates how companies collect and process EU citizens’ personal data.

GDPR Key Principles

GDPR covers two vital areas:

Personal Data

Information that can directly or indirectly identify someone, including:

  • Names, ID numbers and addresses
  • Locations and IP addresses
  • Cookies
  • Health, genetic and biometric data
  • Financial information
  • RIFD tags
  • Data on race, ethnicity, sexual orientation and political opinions

Data Processing

Manual or automatic actions that deal with personal data, including:

  • Collecting and recording data
  • Storing, altering and erasing data
  • Organising and structuring data
  • Using data

You need to understand three critical parties involved in data collection and protection:

  • Data Subject – the person whose personal information is processed
  • Data Controller – the person, company or organisation that chooses how and why the data subject’s information is collected and processed
  • Data Processor – a person, company or organisation acting on behalf of the data controller to collect and process data

Who Does GDPR Apply To?

If you or your company collects and stores the personal information of EU citizens, then you must comply with GDPR. Your company’s location is not relevant.

Brexit has not affected data protection in the UK; it has identical requirements for companies under UK GDPR.

Currently, it protects residents in:

  • Austria
  • Belgium
  • Bulgaria
  • Croatia
  • Cyprus
  • Czech Republic
  • Denmark
  • Estonia
  • Finland
  • France
  • Germany
  • Greece
  • Hungary
  • Ireland
  • Italy
  • Latvia
  • Lithuania
  • Luxembourg
  • Malta
  • Netherlands
  • Poland
  • Portugal
  • Romania
  • Slovakia
  • Slovenia
  • Spain
  • Sweden
  • UK

As with almost all legislation, some companies are exempt from particular GDPR requirements. Typically, companies and organisations with fewer than 250 employees do not need to comply with many of the record-keeping requirements unless their personal data processing:

  • Risks data subjects’ rights and freedoms
  • Is not occasional
  • Includes the special data categories specified in Article 9
  • Includes data surrounding criminal convictions or offences (see Article 10)

Benefits of GDPR Compliance

Effective GDPR compliance measures fulfil your legal requirements and have many other benefits:

Protect Your Customers and Employees

When you take on customers’ and employees’ personal data, you have a moral and legal obligation to protect it.

Encourage Customer Loyalty

Customers want to rely on you to keep their information safe. If they feel secure, they will likely stay with your company.

Conserve Your Reputation

Word of security issues spreads, destroying your company’s reputation and harming future activities and profits.

Prevent Lawsuits and Fines

If GDPR regulators believe you have breached your requirements, they can investigate your data processing. You risk costly fines from them if they find violations; the amount depends on:

  • The breach’s severity
  • The affected personal data
  • Your cooperation with authorities

How to Comply with GDPR

GDPR compliance often appears complex. However, you just need to follow this simple checklist.

1. Appoint a Data Protection Officer

You should have an individual in your company responsible for GDPR compliance. Appointing a DPO at the start of the compliance process allows them to build a system they can manage rather than being shoehorned into an existing structure.

Although GDPR only requires a DPO for particular circumstances, it can help all companies.

2. Identify Your GDPR Regulator

GDPR obligates EU states to provide at least one independent public body to regulate data processing. Your Data Protection Authority (DPA) is your primary GDPR contact. They should:

  • Supervise GDPR
  • Offer expert advice
  • Handle GDPR violations
  • Fine non-compliant data controllers and processors

3. Review Your Policies

Regular GDPR reviews are vital to ensure compliance, and whenever you adapt your policies, you should start with an audit.

You should identify what data you collect and store, whether your security is adequate and whether only authorised, necessary individuals can access it.

4. Conduct a Data Protection Impact Assessment

Once you understand your policies, you should then identify the risks your system faces. A Data Protection Impact Assessment (DPIA) pinpoints hazards, risks and mitigation policies.

GDPR has a DPIA template that is an ideal starting place. Then you can optimise it for your company’s needs.

5. Establish a Lawful Basis for Data Processing

Every company has different legal bases for processing customer data. The ICO has identified six, and your DPO should follow them.

  • Consent – explicitly requesting and receiving permission from a customer to use their data in specific ways
  • Contract – processing customer data to fulfil your contract with them
  • Legal Obligation – following necessary steps to process data and comply with GDPR
  • Vital Interest – process data to protect interests that affect a data subject’s life
  • Public Tasks – performing tasks in the public interest
  • Legitimate Interests – using customer data in ways that a customer would expect, perhaps to fulfil your or a third party’s needs, but that does not impact their privacy or could be achieved using varying means

6. Implement Security Measures

You then need to implement GDPR security measures, and cyber security is at the heart of these preventions.

Network security – establish a layered approach to network security with VPNs and firewalls

Data security – use antivirus software, encryptions, DLP systems, tokenisation and data backups

Access controls – control and protect access with multi-factor authentication, privileged access management and identity management

Insider risk management – know your company through employee monitoring, analysis of user and entity activity and third-party activity monitoring

7. Establish Data Subject Protection Rights

Your data subjects have multiple rights to:

  • Request and receive the data you have collected
  • Request that you delete their personal data
  • Object to data processing
  • Update their personal data
  • Correct inaccurate data
  • Request information about your actions with their data
  • Receive copies of their collected data
  • Limit how you use their data

8. Document Your Compliance

You should always record your security and compliance measures to monitor your processes and identify issues when something goes wrong. It can demonstrate your due diligence to your DPA and helps you optimise your efforts.

9. Implement Vital Training and Policies

Training is critical for reducing the risk of data breaches. Your employees should understand their GDPR requirements, the threats and consequences of breaches and how to respond to them.

Regular training is the best way to update your employees when your processes change. Showcase examples and scenarios to provide actionable advice.

10. Report Any Breaches

If the worst occurs, you must report it promptly. GDPR Article 33 specifies that the data controller should notify the Data Protection Authority within 72 hours of the breach. Therefore, communication between the Data Processor and the Data Controller is vital, although it can get complicated when using third-party Data Processors.

You should detail the nature of the breach, the data categories at risk, the number of records and data subjects affected, the consequences, the measures you took to mitigate risks, and the contact details of the DPO.

Instruct Our Solicitors Today

Our expert solicitors are available to help you fulfil your GDPR obligations. Contact us today to arrange a free consultation where we can learn about your situation and recommend the best resolution.