Despite the triggering of Article 50, UK government has stated that the new regulations will come into force as planned on 25 May 2018 – so waiting to act would not be wise.
There has been a raft of commentary to date focusing on the legal requirements for GDPR, so I’ll leave that to the legal experts. Instead, I would like to explore some initial practical aspects of the new regulations from my own perspective and how they can be implemented in an organisation.
It’s fair to say that, up until now, data protection has probably been treated purely as more of a risk-based exercise. We are all familiar with the stories about firms sending spam communications, showing that there are a large number of businesses out there who largely ignore the current rules. However there have also been a number of reputable businesses hitting the headlines who have failed to follow best practice and have been fined as a result. A hefty punishment you would be wise to avoid!
Raising awareness of GDPR within your organisation
While senior management teams within organisations need to understand the implications of GDPR and buy into the changes required, it is also critical that this message filters from the top down, to everyone within the organisation who may have actions to take. Senior management need to lead by example, showing the importance of treating personal information in accordance with privacy requirements. Training needs to be mandatory for new starts and, for existing staff, a series of group sessions on how the changes specifically impact your business are needed. Then, moving forward, refresher training once a year with an auditable record of attendance.
Securing your employee and customer data
The privacy of both employee and customer personal information needs to be at the core of the business processes in your organisation. It should not be an afterthought. Clearly this cannot change overnight, so what practical steps can you take?
Initially you need to document the business processes across the organisation, focusing on these questions:
- What different types of processing do you carry out?
- What data subjects are included for each of these activities?
- What personal data you hold and reasons for this?
- Where does it comes from?
- How does it get into the business?
- What format is it stored?
- Where is it stored?
- How, and who is the data shared with outside that area of the business and externally?
- What are the risks?
- How can they be mitigated?
Building up a picture of where you are as a business is vital to understanding both the potential and identifiable risks. Most businesses will have a HR function so that’s a good place to start. Some of the questions you may ask your HR team are:
- Do we have a valid reason for storing each different type of employee personal information?
- Are we sure it is up to date?
- Are there controls in place to ensure no one outside HR has access to the data?
- If that data is shared with a manager, how is this securely achieved?
- Is there an agreed retention period for employee performance records?
- How long are we keeping ex-employee data?
Once you understand the risks in relation to the new regulations, you will be able to work with different areas across your organisation to implement new policies, supporting procedures and training. This is a sizeable task, and as soon as you start digging, do not be surprised if legacy processes come to light and the time assigned for the work escalates.
How secure are your communications channels?
One of the key risks for many businesses is email. What unencrypted information is shared with customers, and what would be the consequences if the autocomplete function in Outlook, meant you sent it to the wrong person?
Once you have recorded the business processes, it’s an idea to start looking at the other key areas in the legislation, including:
- Privacy Impact assessments – Privacy by Design
- As part your training programme, management and staff need to be aware that privacy has to be central to any changes within your organisation. For example, if you are developing a new service or product line, a Privacy Impact Assessment is needed. This documents what the new line involves, the personal data required, the potential risks and the actions taken to mitigate these.
- Privacy Notices
- More rights have been introduced for data subjects (the individuals the data relates to) so be aware of these and ensure these are reflected in your privacy notices
- New Data Subject Rights
- This relates to the right of individual to access the personal information you hold about them. Have you implemented the policies and processes to manage these rights? For example, although Subject Access Rights (SARs) already exist, have you trained staff to identify these requests and pass to the correct person to action?
- Data Breach Notification
- If you have a data breach, do your staff know who to contact, and if they are not available who is their backup? Do you have an incident response plan? With 72 hours to notify the regulator, the fact the Data Protection Officer is on holiday is not a valid excuse for non-disclosure.
- Third Party Data Processors
- Data processors now fall under the new regulations, so you need to assess your contracts here.
In summary, understanding your business processes and the personal information you hold is a key step to reducing risk and achieving compliance. However with the huge rise in phishing scams, and malware such as ransomware, no business is immune to the risks of a data breach.
What is important is that you can lay the foundations and show the regulator documented proof that you have done all you can to secure personal information and have taken the new regulations seriously. Where you will fall foul is when a problem occurs and there is evidence you have been negligent in securing that information.
There should also be a focus on the overarching information security management framework of the organisation. There is huge overlap here with the key principles of GDPR with confidentiality, integrity and availability being at the core. By implementing a governance framework, you go a long way to achieving the foundations of GDPR compliance.
There are a number of security products which are specifically marketed as being compliant with the new regulations. While many of these can help you discover what personal data you hold, to cover the 72 hour breach notification, the overarching requirements and potential risks will not be overcome with technology.
Understanding the data processes and flows in your business and addressing risks accordingly is the way forward. Yes technology can help in certain areas, but it’s never the magic bullet.
Get ready for GDPR changes – stay informed and take action now.





