GDPR stands for General Data Protection Regulation, and its main role is to protect personal data. We have written many blogs regarding GDPR compliance because it’s vital for small businesses in the UK to follow. 

One of the reasons many businesses fail to comply with GDPR could be its a relatively new piece of legislation. GDPR was introduced in 2018, but all businesses had to switch to UK GDPR laws after Brexit. The transition wasn’t too complicated but some businesses wrongly assumed that they didn’t need to comply with the regulations when the UK left the EU. 

In this blog, we talk about the importance of GDPR compliance and the steps you need to take to comply with GDPR rules.

Example of breach of personal data

A recent ICO fine was issued to Interserve Group Limited for £4.4 million. People often wonder why they have to register and pay the Information Commissioner’s Office a registration fee each year. The money helps them prosecute companies when serious data breaches occur. 

Interserve had breached its information security obligations and failed to see the risks posed by the following:

  • The use of outdated protocols
  • Processing personal data on unsupported operating systems
  • Failure to provide information security training
  • Failure to implement policies governing information security
  • Failure to run an investigation of the initial cyber-attack and
  • Failure to implement endpoint security on time

As a result, Interserve suffered a cyber-attack that compromised the personal data of over 113,00 current and former employees. 

Interserve had all the information security policies in place, but failed to implement them or at least have them overseen by senior management. This cost the company considerable reputational and financial damage. 

The importance of GDPR compliance

We can’t stress enough how important it is to get your policies and processes in place, even as a small company. Whether your company processes personal data on a larger scale or you have lots of personal data flowing through your business, then having the correct policies in place is crucial.

However, what’s also very important is to actually implement and train staff on those policies, as the Interserve case proves. In this case, they had all the correct policies in place but failed to implement them effectively throughout the organisation.

Even as a Sole Trader or small business, you should, at the very least, do the following:

  1. Check whether you have to register with the ICO (99% of businesses do) https://ico.org.uk/for-organisations/data-protection-fee/self-assessment/
  2. If you have a website that collects personal data, you need a Privacy Notice. If your website uses cookies, you will also need a Cookie Notice
  3. Audit personal data. List all the different types of data your business processes.
  4. Determine whether your collection of data is lawful with this ICO lawful basis checker.
  5. Adhere to people’s individual rights when processing data.
  6. If you are processing personal data for clients or a client has asked you to process personal data for them, you must either have the relevant clauses in a contract or a separate data processing agreement. We have one for sale in our shop: https://kkbservices.com/product/data-processing-agreement/

There may also be other obligations placed upon you depending on your business, the types of personal data you handle and what you do with the data. It’s really important you get professional advice to ensure you are compliant. 

It is also advisable to keep your policies and processes under review and conduct regular training programs with your team, no matter how small. 

If you are unsure whether you are complying with the obligations placed upon you contact us. The processes and policies you implement don’t have to be complext if you are small or medium sized organisation. However, ensuring you follow them is crucial.