Latest Updates:How Solicitors Can Manage Closed Files More EfficientlyWhat Happens When Office Storage Space Runs Out?Paper vs Digital Records: Does Your Business Still Need Physical Document Storage?What Is BS EN 15713 and Why Does It Matter?

GDPR 2018

GDPR
Policy

Ensure your business complies with the General Data Protection Regulation introduced on May 25th 2018.

header-about

What Steps Do I Have To Take?

From May 25 2018, EU guidelines came into effect making changes to the way in which organisations are able to collect, use and transfer personal data. Below are a few key steps to consider to help ensure your compliance with GDPR.

Select A Topic

Ensure that decision makers and key people in your organisation are aware that the law has changed to the GDPR. They need to be understand the implementation deadlines and appreciate the impact this is likely to have.

You will need to document what personal data you hold, where the information came from, and with whom it is shared. An information audit may be organised to get everything up to date.

You should check your procedures to ensure they cover all of an individual’s rights, including steps you take to delete personal data, and also how you provide data electronically and/or in a commonly used format.

Review your current privacy notices to make sure they are up to date and put a plan in place for making any changes needed.

Identify the lawful basis for your processing activity in the GDPR. Document this and be sure to update your privacy notice explaining it.

Plan how you will handle requests within the new timescales and update your procedures providing any additional information.

You should make sure you have the correct procedures in place to detect, report and subsequently investigate any personal data breaches that may occur.

Consider whether you need to put systems in place to verify the ages of individuals and to therefore ensure parental or guardian consent is obtained prior to any data processing activity.

Familiarise yourself now with the ICO’s code of practice on Privacy Impact Assessments as well as the latest guidance from the Article 29 Working Party. Work out how and when to implement these within your organisation.

Are you required to formally designate a Data Protection Officer? You should assign someone with the responsibility for data protection compliance and assess where this role will sit within your organisation.

If your organisation operates in more than one EU member state or the UK – for example, if you carry out cross-border processing -, you should determine your lead data protection supervisory authority. Article 29 Working Party guidelines will help you do this.

The Impact of Brexit

With the United Kingdom’s departure from the EU, GDPR no longer applies ‘directly’. But that doesn’t mean UK organisations no longer need to comply with it as the Data Protection Act 2018 enshrines GDPR’s requirements in law. In addition to the existing legislation, the UK government has issued a statutory instrument titled ‘The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019’. Put simply, this amends the original law and merges it with the requirements of GDPR. The outcome is a new data protection framework known as the ‘UK GDPR’.

Menu