Call our team on 01709 321 665
On the 25th May, the law surrounding data protection is changing. Are you prepared?
Author:
Helen Marshall
Published:
11 April 2018
We are sure most of you are aware that come 25th May 2018, the way data is handled and collected is changing. The General Data Protection Regulations (GDPR) is an EU-wide directive, which will affect all businesses (no matter the size). If your company is found to not be compliant, you potentially face huge fines, so it is best to make sure you are prepared.
What Information does GDPR apply to?
Personal Data
Personal data means any information relating to an identifiable person, who can be identified (directly or indirectly) by reference to a particular identifier.
Sound a bit complicated? It did to us too at first, but the definition from the ICO provides a variety of personal identifiers to constitute personal data, including: name, ID number, location data or online identifier.
GDPR also relates to automated personal data and manual filing systems. This could include any manual records you have containing personal data.
Personal data that has been pseudonymised (e.g. key-coded) can fall within the scope of GDPR, depending on how difficult it is to attribute the pseudonym to a particular individual.
Sensitive Personal Data
GDPR refers to Sensitive Personal Data as “special categories of personal data” which includes genetic and biometric data, where processed to uniquely identify an individual.
Ok, so what else?
The GDPR sets a high standard for consent. Consent means offering individuals real choice and control. GDPR will require a positive opt-in for individuals. What does that mean? It means that you will no longer be able to use pre-ticked boxes or any other default method of consent. Consent will need to be explicit and requires a very clear and specific statement of consent.
Remember: be clear & concise.
It is also worth noting that consent must now be kept separate from other terms and conditions.
The GDPR will not just affect you as a business, but also as an individual. So, it makes sense for you to know the rights of individuals:
We know that is a lot to take in and it still might not be clear as day (we had to go over the rights quite a few times, so we fully understood them), but we are hoping this might have helped you a bit. If you do need more detail on any of these (we have shortened them down quite a substantial amount), the ICO website has everything you need to know.
You will need to impose measures that minimise the risk of breaches and uphold the protection of personal data. GDPR requires personal data to be processed in a way that ensures its security, including: protection against unauthorised and unlawful processing, and against accidental loss, destruction or damage.
There is a lot of information to get your head around when it comes to GDPR, but it will be worth it. All the information and guidance you need available on the ICO website (link below). Rest assured, our experienced Compliance Department has been working hard to implement new procedures to ensure that we are compliant before the 25th May deadline, which means your data and your client data is in the safest and most compliant of hands.
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/
Tags: Data protection, regulation, GDPR
Customer looking for options to exit a bridge shortly after coming out of an IVA with a recent CCJ
Customer looking to raise finances for debt consolidation and home improvements
Our Senior Sales and Development Manager, Sonny Gosai, anticipates a surge in demand for bridging lo...