What is GDPR? Initially this was legislation implemented by the EU in 2018 and was put in place purely to protect the data and personal information of individuals.
Following Brexit the UK has adopted this legislation as their own and it has its own unique title of “UK-GDPR”. It sits along the already established Data Protection Act 2018 and together they govern the UK’s data protection regime.
In this article we will look at reasons why fulfilling your GDPR obligations as an organisation is so important. We will also explain how you can get yourself compliant if you have not already done so.
It stands to reason that as we have seen major shifts in many aspects of the law. Your business’ legal obligations need to be reviewed regularly. Your organisation may need to revise current processes and policies to comply with these changes.
WHAT YOU NEED TO KNOW
There are various principles that need to be apparent within a Privacy or Data Protection Policy. It is therefore best to seek legal advice to make sure that you are abiding by the data protection legislation for you to be compliant as an organisation.
So, what are the main things that should be considered when it comes to your data protection policy?
The main ones include transparency, purpose limitation and integrity and confidentiality. It should be fairly self-explanatory why these would be the most important. For example; transparency means that you as a business will be forthcoming with everything. Especially regarding what data will be extracted, for what reason as well as the duration that it will be utilised for.
The process of collecting data can be for a number of reasons. When collecting data an organisation is obliged to divulge what the information will be used for. The data should not be kept or used for longer than is necessary.
SECURITY OF DATA IS KEY
When you have someone’s personal data in your hands you need to take the necessary steps to ensure that it is as secure as possible and cannot find its way into the wrong hands. As we live in a technology driven world, it is likely that the data you are extracting and using will be kept in some kind of digital library – the threat is very real when it comes to anything being online and therefore you need to have the strictest possible measures in place.
Here are some ways to keep things under “lock and key”.
- Keeping your anti-virus up to date
- Keep your operating system updated
- Use passwords on all computers and devices
- Never use a public wifi network if you have personal data on the device
LEGAL TALK
We have now looked at some of the main considerations to ensure your organisation is abiding by the rules and regulations of the data protection legislation. But how do you go about implementing it all?
First off you need to have policies and tools in place to make things easier. You will find that we have spoken about this topic no end and we cannot stress enough the importance of keeping up to date with all the trends that are ever changing.
The next step is to actually track how the data is moving around your organisation and where it goes to and ultimately ends up. This way you can be on top of potential legal issues that may arise and rectify the situation timeously. Coupled with this is the need to train your employees so that they are on the same page and will abide by the organisational measures put in place.
Where you extract the data from also dictates the types of policies needed. For instance, if you are getting people to share their information with you via your website, you will need to have a Privacy and Cookies Policy in place. We at K&K Consulting can help you with these documents.
Data protection policies are not a “one-size fits all” and that is why we always recommend seeking legal advice.
We have had to assist many businesses with getting their documents in legal order and we can help you too. You can sign up to one of our Power Hours or listen to our
podcast. Both will provide you with valuable insight into the data protection legislation and anything else related to it.
FINAL WORDS
Make sure you review and revise your policies and procedures on a regular basis. This will reduce the risk of a data breach from arising down the line.
If you are unsure if your business is compliant then
get in touch. We are experts in this field and can help you navigate through this in a way you will understand.