Towards the end of 2017 I looked into some of the misunderstandings surrounding GDPR, at the GDPR Scotland Summit. The new regulations mark the biggest overhaul in data protection law for 20 years. With less than six months to go until GDPR comes into force, here are some of the myths that I uncovered.
GDPR is a revolution in data protection law
The principles that underpin GDPR are largely the same as those that apply under current data protection law. While there are a number of material changes, for organisations that comply with the Data Protection Act, it should be a case of evolution not revolution.
For many, the biggest challenge will be creating and maintaining an accurate map of how they use personal data and demonstrating compliance with GDPR. That requires a big push on the two key themes under GDPR – accountability and transparency. In particular, that means a focus on record keeping, data management and internal policies, procedures and training. Carry out a gap analysis to assess where you stand against GDPR and then work out what you need to do to prepare.
The high fines will cause firms to go bust
While the 4% of global turnover/€20 million maximum fines have attracted lots of headlines and hyperbole, any fine that is issued under GDPR must be proportionate. The UK Information Commissioner’s Office (ICO) has made clear, in its own myth-busting blogposts, that any suggestions the ICO will make early examples of organisations for minor infringements, or that maximum fines will become the norm, is scaremongering.
It is worth noting that the ICO is yet to issue a maximum fine under the current rules, with the highest fine to date under the Data Protection Act being the £400,000 fine issued to Talk Talk for the security failings that led to the October 2015 attack on its systems.
Fines are just one part of the ICO’s toolkit for enforcing GDPR – alongside issuing warnings, reprimands and corrective orders. It also has the power to conduct audits and to order the suspension of processing.
GDPR only applies to personal data processed after 25 May 2018
GDPR applies to all processing from 25 May 2018. There is no grandfathering of existing processing activities or grace period for compliance. While there are no formal transition periods in GDPR, the text was finalised in April 2016, giving organisations two years to prepare, though that has been made more difficult by delays in regulatory guidance.
Brexit means that we don’t need to worry about GDPR
As an EU Regulation with direct effect in member states, GDPR will automatically come into force in the UK on 25 May 2018. Under the EU Withdrawal Bill, GDPR will then automatically become part of UK domestic law upon Brexit.
In any event, the UK Government has made clear that it is seeking “friction-free” data transfers between the UK and the rest of the EU. To enable that, the UK Government is seeking a finding of adequacy from the EU Commission, which will require the UK to adopt EU-equivalent data protection laws.
GDPR does not apply if personal data has been encrypted
Encryption is mentioned in GDPR as being one of the tools that organisations can use to help protect personal data, and it may help reduce the risks to individuals if there is a data breach. However, the processing of that data is still subject to GDPR.
I can buy a product/service that will make me GDPR compliant
While technology undoubtedly has its part to play in helping an organisation comply with its obligations under GDPR, it is not a solution. Organisations should look at why and how they are processing personal data. Be wary of anyone offering a product or service that is GDPR certified or that promises to make you GDPR compliant.
I can’t process personal data without consent
Under GDPR, the rules on consent are being tightened up. However, consent is just one of a number of legal bases upon which personal data can be processed. Consent can be problematic – it can be withdrawn and it gives individuals some additional rights.
If you currently rely upon consent then look at whether there is another, more appropriate basis upon which to carry out that processing – for example, it is necessary to perform a contract or it is necessary for the purposes of legitimate interests that you are pursuing. If you are unsure what your legal basis processing is, then get expert advice.
There is an exemption for small businesses
Again, this is not correct. There is an exemption to the obligation to maintain a record of data processing activities for organisations that employ fewer than 250 people. However that exemption is qualified. In particular, it will not apply where the organisation processes special categories of personal data, such as medical information or trade union membership. As most organisations will hold special category personal data relating to their staff, the exemption is likely to be very limited.
The right to be forgotten will stop my business from being able to provide services to customers
The right to be forgotten (or right of erasure) is not an absolute right. An individual can only require his or her personal data to be erased where the processing takes place on the basis of consent, it is no longer necessary for the organisation to hold that data or the organisation has no overriding legitimate grounds for processing. It’s important that organisations have in place a policy to ensure that such requests are handled properly.
Every personal data breach will need to be reported to the ICO
There is no obligation to report a personal data breach to the ICO if it is unlikely to result in risk to the rights and freedoms of individuals. For example, an employee losing an encrypted laptop is unlikely to result in a risk. What is important is that the organisation has a clear understanding of where and how it processes personal data and an internal breach reporting procedure in place to detect and assess breaches and identify whether they need to be reported.
Remember, even if a breach is not reportable the organisation must retain a record of it on its breach reporting register.
If I use the cloud then GDPR compliance is my service provider’s problem
One of the changes under GDPR is that data processors, such as cloud service providers, will acquire direct obligations under data protection law. Those obligations include information security, record keeping and notifying data controllers of personal data breaches. However, the organisation using a cloud service still retains overall responsibility for the decision to use that provider and for ensuring that the processing complies with GDPR.
That means organisations still need to carry out appropriate diligence on the cloud service provider – including understanding how the service provider keeps the data secure, where it is hosted, and what subcontractors are used. The organisation should also ensure that a contract is in place that complies with the new mandatory clause requirements under GDPR. There is no grandfathering provision for existing contracts.
The ICO is unlikely to take any enforcement action
This one may have a grain of truth in it. The ICO announced earlier this year that it planned to recruit another 200 staff to help it prepare for and police GDPR. However, despite a substantial increase in caseload the ICO has instead lost 30% of its technical staff. It is therefore inevitable that when GDPR comes into force the ICO will need to concentrate its resources when it comes to investigations and enforcement action. That may mean that the initial focus is on dealing with complaints against larger, higher profile, organisations or more severe breaches.
However, that is not a reason to ignore GDPR. In the past, a number of organisations have suffered substantial reputational damage as a result of a breach of data protection law. Even if the ICO does not issue a monetary penalty, the reputational damage arising out of lesser enforcement action and investigations should be enough of an incentive to encourage organisations to take data protection compliance seriously.





