Get ready for the new data protection rules

12th September 2017

The government is to introduce new data protection rules under the General Data Protection Regulation (GDPR) which takes effect from 25 May 2018.

Under the GDPR businesses will have increased obligations to safeguard the personal information of individuals which is stored by the business. These rules apply to the information of customers, suppliers or employees. Generally for those who are currently caught by the Data Protection Act it is likely that you will have to comply with the GDPR.

GDPR will apply to data ‘controllers’ and ‘processors.’ Processing is about the more technical end of operations, like storing, retrieving and erasing data, whilst controlling data involves its manipulation in terms of interpretation, or decision making based on the data. The data processor processes personal data on behalf of a data controller. Obligations for processors are a new requirement under the GDPR.

The GDPR applies to personal data which is wider than under the Data Protection Act (DPA).

One key change to the current DPA rules is that those affected will have to show how they have complied with the rules. Proof of staff training and reviewing HR policies are examples of compliance.

Under GDPR, higher standards are set for consent. Consent means offering people genuine choice and control over how their data is used.

Overall, the aims of GDPR are to create a minimal data security risk environment, and to protect personal data to rigorous standards. For most organisations, this will entail time and energy getting up to speed with compliance procedures. Reviewing consent mechanisms already in place is likely to be a key priority. In practice, this means things like ensuring active opt-in, rather than offering pre-ticked opt-in boxes, which become invalid under the new rules.

Organisations will also have to think about existing DPA consents. The ICO’s advice is that:

‘You should review how you seek, record and manage consent and whether you need to make any changes. Refresh existing consents now if they don’t meet the GDPR standard.’

Where the current consents do not meet the new GDPR then action will be needed.

The fines for non compliance are severe at up to 20 million euros or 4% of total worldwide annual turnover (if higher).

The Information Commissioner’s Office (ICO) has published some very useful information and a 12 step planning guide to help organisations get ready ahead of the May 2018 deadline.

 

 

For further information and advice get in contact with our team at Decisive:IT who can offer practical advice and take you through the steps you need to take to ensure you are compliant with the upcoming GDPR changes.

 

Other helpful links: ICO getting ready GDPR 12 steps.pdf

Disclaimer - All information in this post was correct at time of writing.
Other Blogs
Paul Jefferson
18th April 2024 Beware of VAT refund fraud

Beware of VAT refund fraud!   We have become aware of several recent cases where taxpayers’ bank account details have been amended on the HMRC portal, without their knowledge, so that VAT repayments have been fraudulently diverted to a third party.   It seems that HMRC have been acting on the basis of a fraudulent…

Andrew Band
17th April 2024 Whitings 2024 Annual Farming Seminar

Our Whitings 2024 Annual Farming Seminar is just around the corner.   Farming always has to cope with changing environment, weather, commodity prices, political changes, etc. This year these challenges feel heightened and this is why we are pleased to welcome back speakers from the Andersons Centre to inform us of these changes and what…

Amanda Newman
17th April 2024 Buy To Let through a Limited Company

There continues to be an ongoing debate when buying a residential property to let out about whether to buy this personally or set up a limited company to own it. Unlike our sole trader v limited company comparisons for a trading business there is not a clear division based on profits. There are a lot…

Nick Edgley
11th April 2024 Do you need to re-register for Child Benefits?

If you’ve heard about the changes post 5 April 2024 and are wondering whether you need to re-register for Child Benefits, this is the blog post for you.   If you have been affected by the increase in the High Income Child Benefit Charge cap to £60,000, then you may need to restart your Child…

Peter Brown
10th April 2024 Pension Contributions for directors

Are you thinking about planning ahead for retirement and want to find out more about Pension Contributions for directors?   When it comes to planning for your retirement, Company pension contributions can offer significant benefits in terms of reducing your company’s Corporation Tax bill. Here’s how you can use both personal and company contributions to…

Angelica Ferentinos
9th April 2024 Child Benefit changes – What you need to know

The new Child Benefit changes came into effect on 6 April 2024, with families receiving up to £1,331 per year (for the first or only child), and up to £881 per additional child, increasing by £83.20 and £54.60 respectively on the year before. This is paid directly into your bank account every 4 weeks. There…