EU’s General Data Protection Regulation (GDPR)

EU’s General Data Protection Regulation (GDPR) THE EU’s General Data Protection Regulation comes into force on 25 May 2018. All companies, including international firms, doing business with individuals located in EU member nation territory must comply. The principles are similar to those already in the Data Protection Act, with an added new accountability requirement. The new law will require all businesses to show how they comply with the principles, for example, by documenting decisions taken. What impact will this new regulation have on your company? Data Protection of the Individual Cloud, Internet of Things (IoT) and mobile computing have all added to the challenge of sharing, managing and securing information. The GDPR tries to help add further layers of control and accountability to protect the misuse of personal data. Some of the new obligations of GDPR include:

  • Right to obtain and access data, allowing individuals to request access to data held about them and how that data is held and used.
  • Right to deletion, giving individuals the right to have personal data removed.
  • Consent to collection of personal information, ensuring organisations gather information with explicit consent of the individual and are able to prove that they have done so.
  • Right to rectification of and objection to information being used for profiling that may result in discrimination.
So, What Should You Be Doing Now? Many large and international companies have already made great inroads into preparing themselves for GDPR. However, many SME’s are unaware or not prepared and could face substantial penalties for non-compliance, especially those that handle a large volume of personal information. What needs to be done varies from company to company but starting to think about it and make provisions is the first step. The next step would be to obtain a Data Protection Audit to assess compliance under the existing and the upcoming GDPR regulations. Data Protection Audit A Data Protection Audit will help you to assess:
  • What types of personal data you are holding.
  • How you are holding that information and how it has been obtained – relying on silence or pre-ticked boxes will not be acceptable.
  • Why you are holding the information, and what your retention/destruction policies are.
  • Where the folders holding the electronic files are located.
These are just some of the issues that will be addressed during an audit, along with updating data protection and privacy policies. A year may seem a long way off, but as the penalties start when the GDPR comes into force on 25 May 2018 and are likely to be high for non-compliance, the sooner you put new practices in to place the better. If you are in doubt about your obligations S4B recommend getting in touch with a Data Protection expert to carry out an audit to ensure you are fully compliant. The Information Commissioner’s Office  https://ico.org.uk/for-organisations/improve-your-practices/audits/ has full details of what you need to do and how to find someone to carry out an audit for you.   The S4B Team We are a firm of Chartered Accountants in Maidenhead who pride ourselves on keeping our clients up to date and fully compliant. Contact us at info@ s4b.uk.com or alternatively call us on 01628 623444 to see how we can help you.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.