GDPR – Will your business remain compliant in 2021?
The General Data Protection Regulations “GDPR” has been around for a few years now and you must have been living under a rock if you haven’t heard of them. Most businesses have got to grips with the steps they need to take to remain compliant. However, what happens now that the UK has left the EU? We will explain in this article how this may affect your business and what steps you should be taking to remain compliant.
GDPR Requirements
Let’s start with a little bit of history for those that don’t know much about the GDPR. May 2018 saw the biggest shake up in data protection law for two decades. Businesses were scrabbling around trying to implement requirements to ensure they were compliant. Here we explain in brief how to be compliant:
Obtaining Consent – your terms of consent must be clear.
Timely Breach Notification – you must report a breach within 72 hours to your customers, the ICO and any data controllers you may have. Failure to do so will result in fines.
Right to Data Access – a user can request to see the data you hold on them at any time. You must provide them with this information free of charge. You must also include the various ways you are using their data.
Right to data Deletion – once you have achieved the original purpose or use your customers have the right to request that you completely delete their data from your records.
Privacy by Design – your systems must be designed with the proper security protocols in place from the outset. Failure to do so will result in a fine.
Data Protection Officers – you may need to hire a Data Protection Officer. This depends on the size of your business and the categories of data you are processing.
How will Brexit affect GDPR?
The UK is currently in a transition period until December. Negotiations are taking place to map out the UK’s relationship with the EU. During the transition period nothing will change in terms of the GDPR and you should continue to follow existing guidance.
The UK has confirmed that the GDPR will be brought into UK law as the ‘UK GDPR’. However, there may be further developments about transferring data from the EU to the UK. The UK will have the freedom to keep regulations under review.
What happens at the end of the transition period?
The EU will have to make an adequacy decision about the UK as it will be a ‘third country’. What this essentially means is whether the UK’s privacy laws align with the principles of the GDPR.
The UK needs to demonstrate that it is a safe place for data processing so that restrictions are not imposed. If the UK passes this rigorous testing then it will not be bound by the appropriate safeguarding requirements which are set out in Articles 46 – 49 of the GDPR and personal data will flow unrestricted.
However, as it stands at the moment it’s unlikely that the EU will grant automatic adequacy to the UK.
UK to EU transfers
If your business is sending data from the UK to EU member states then this will remain unaffected.
EU to UK transfers
UK businesses that receive personal data transfers of EU citizens or EU member states will have to comply with Articles 46 – 49 of the GDPR.
The most relevant legal basis for such transfers will be within a company’s standard contractual clauses SCCs. These EC-approved data protection clauses need to be embedded into contracts or added as an appendix. These clauses cover the contractual obligations between the parties to protect the rights of individuals whose data is being transferred.
The ICO has a detailed article on this, and you can also find lots of useful information on their website surrounding the GDPR https://ico.org.uk/media/for-organisations/documents/2617966/information-rights-and-eot-faqs.pdf
Privacy Shield Program
Another point worth noting is the recent news surrounding GDPR and those companies that have been relying on the Privacy Shield program as a mechanism to transfer data to the USA.
On the 16th July the European Courts declared this mechanism as invalid. What this essentially means is that companies that have been relying on Privacy Shield to comply with the GDPR will now have to find alternative ways to ensure they are protecting their users’ personal data.
We are talking about companies such as Facebook, Google and interestingly Mailchimp. In reality what these companies will now need to do is either have servers in the EU to store the data of their EU users. Or, ensure they are strictly adhering to the use of other mechanisms recognised by the GDPR to appropriately safeguard personal data.
As a business you must be seen to be proactive in protecting the storage and processing of all personal data. If you are a user of Mailchimp for your business you should check what steps they are going to take to ensure they remain compliant with the GDPR.
Whilst a lot is still unclear there are steps that your business should be taking right now. You should start reviewing your policies and processes now to ensure you remain compliant from January 2021. If you need any guidance please contact us and we would be happy to talk this through with you.