A simple guide to GDPR

davids355

Super Moderator
Moderator
Executive VIP
Jr. VIP
Joined
Apr 25, 2011
Messages
19,849
Reaction score
28,297
This is a quick guide to GDPR from my point of view (Looking at GDPR on behalf of small businesses). I am by no means an expert, but I have been studying GDPR for the past couple of weeks and I have been doing quite a bit of work in this area.

What is GDPR?
Basically GDPR is an updated version of the data protection act. It comes with a lot of new restrictions in terms of how data should be collected, stored and processed.

The GDPR brings with it a number of changes and improvements to the data protection act including:

Enhanced documentation requirements
Enhanced Fair processing notice
Stricter rules on consent to data processing
Mandatory requirement to notify the ICO of a data breach
Enhanced rights for data subjects or owners
New rules requiring the appointment of Data Protection Officers
Tougher penalties

Who does GDPR apply to?
It applies to anyone who processes data belonging to EU residents - so that is irrespective of whether or not you are operating in the EU yourself.

What does this mean in reality?
It relates to identifiable data - for example any data where you could identify a specific individual. This could be as little as a full name and as much as the collection of bank details, social security numbers and so on.

When you are collecting this data you have to do so responsibly, in particular you should be collecting the data with consent, you should only be collecting as much data as necessary to undertake whatever work you are doing for the subject and you should also only retain the data for as long as required.

In addition you need to take care when storing the data - ensuring that it is held securely - and lastly you should be transparent with the ways in which you store and use the data. The subject has a right to ask about this process and also has a right to request removal of the data from your system - which you must make easy for them to do.

What about if you outsource your data storage to a third party?
If a third party is handling your client data on your behalf that does not abscond you from any responsibility. In fact as the data controller you are responsible for it still and as such it is also your responsibility to ensure that any third parties who handle data on your behalf are doing so in compliance with GDPR.

This also means that if you handle data for third parties yourself then you might find yourself losing work if you are not GDPR compliant, because lots of companies within the EU are going to start requiring this.

Some questions answered
Do I have to re-opt in all of my marketing contacts?
No you dont have to do this. as long as you do have an audit trail and you can confirm that you have consent to send marketing to those contacts.

Do I have to encrypt data at rest?
The level of security required will generally be proportionate to the risks posed to the rights and freedoms of data subjects. Moreover, cost considerations, the nature, scope, context, and purposes of data processing, and the current state of the art will also be factored into determining what is appropriate.
I take this to mean that no, data does not necessarily need to be encrypted at rest, but it depends on the nature of the data, how big a risk there is of it falling into the wrong hands and also how proportionate the costs of encryption would be.

How long do I have to retain client data?
The Act does not set out any specific minimum or maximum periods for retaining personal data. Instead, it says that:

Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

This is the fifth data protection principle. In practice, it means that you will need to:

review the length of time you keep personal data;
consider the purpose or purposes you hold the information for in deciding whether (and for how long) to retain it;
securely delete information that is no longer needed for this purpose or these purposes; and
update, archive or securely delete information if it goes out of date.

Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

This is the fifth data protection principle. In practice, it means that you will need to:

review the length of time you keep personal data;
consider the purpose or purposes you hold the information for in deciding whether (and for how long) to retain it;
securely delete information that is no longer needed for this purpose or these purposes; and
update, archive or securely delete information if it goes out of date.

References
https://ico.org.uk/for-organisations/guide-to-data-protection/principle-5-retention/
https://www.signupto.com/news/digital-marketing/gdpr-double-opt-in-and-re-consent/
https://www.itgovernance.eu/blog/en/does-the-gdpr-apply-to-me

GDPR Audit and Policies
https://www.blackhatworld.com/seo/gdpr-site-survey-guidance-and-policies.1023467/
 
Thanks for putting this together - definitely helps simplify a few things. One thing I'm confused about, however, is:

"...so that is irrespective of whether or not you are operating in the EU yourself" - who is going to enforce that for someone operating in, say, the US? Why would anyone have to kowtow to laws that weren't enacted by their own government? I understand for global companies, but makes no sense for small businesses outside the EU, imo.
 
Last edited:
Thanks for putting this together - definitely helps simplify a few things. One thing I'm confused about, however, is:

"...so that is irrespective of whether or not you are operating in the EU yourself" - who is going to enforce that for someone operating in, say, the US? Why would anyone have to kowtow to laws that weren't enactd by their own government? I understand for global companies, but makes no sense for small businesses outside the EU, imo.

There are quite a lot of things about GDPR that the people who enacted it have not thought about. This is one of them. The short answer is that no-one can enforce their laws on the citizens of another jurisdiction. Of course, if the business has an office in the EU, it can, but if, say, a US developer based only in the US sells a browser add-on to a European citizen, the EU can do nothing.

The ICO's own website is a good starting point for reading up on GDPR (with respect to the UK), but it leaves many questions unanswered. It seems the ICO is as in the dark as most people.

Another often overlooked point is that GDPR relates to personal data only, not business data. If the data relates to a business, it is not subject to GDPR. I've had questions from worried business owners who thought it applies to all data.
 
Last edited:
Thanks for putting this together - definitely helps simplify a few things. One thing I'm confused about, however, is:

"...so that is irrespective of whether or not you are operating in the EU yourself" - who is going to enforce that for someone operating in, say, the US? Why would anyone have to kowtow to laws that weren't enacted by their own government? I understand for global companies, but makes no sense for small businesses outside the EU, imo.

There are quite a lot of things about GDPR that the people who enacted it have not thought about. This is one of them. The short answer is that no-one can enforce their laws on the citizens of another jurisdiction. Of course, if the business has an office in the EU, it can, but if, say, a US developer based only in the US sells a browser add-on to a European citizen, the EU can do nothing.

The ICO's own website is a good starting point for reading up on GDPR (with respect to the UK), but it leaves many questions unanswered. It seems the ICO is as in the dark as most people.

Another often overlooked point is that GDPR relates to personal data only, not business data. If the data relates to a business, it is not subject to GDPR. I've had questions from worried business owners who thought it applies to all data.

I am not certain on the specifics of the first point; I would say most likely it does apply to anyone doing business with an EU based company, but in reality whether or not it would be enforced is another matter. Quite likely it would not be enforced upon a business outside of the EU.

And as always, the smaller the business, and the smaller the steaks, the less likely it is to be enforced.

As for data types, yes I beleive that’s right - it’s data that identifies an individual, not a business.

Edit: regarding the issuance of fines to non-EU businesses I think the answer is that it’s possible through international law, but extremely unlikely to occur unless it was a huge company (in which case they’d more than likely have a registered business in the EU anyway).
 
What needs added on the site end David? A new privacy policy detailing how data is stored now and these rules or ? Like how do you confirm on your site that you’re complying.

I use a third party for client management, I’ll be speaking with them. Just curious if I need to add anything to my site.
 
What needs added on the site end David? A new privacy policy detailing how data is stored now and these rules or ? Like how do you confirm on your site that you’re complying.

I use a third party for client management, I’ll be speaking with them. Just curious if I need to add anything to my site.

As far as I am aware there is no requirement to do this. The main points for you would be that you are-

Collecting data responsibly
Storing it responsibly
Retaining it only as long as necessry
Being transparent about how you do the above
Providing means for your clients to request data removal
Registering with the ICO
reporting data breeches if they occur

To cover yourself I would suggest revising your privacy policy - state that you are GDPR compliant, include a heading for each of the above points detailing your practices, retention policy and so on. Finally include a form, or contact method for anyone wishing to request access to or removal of the data you hold on them.
 
What needs added on the site end David? A new privacy policy detailing how data is stored now and these rules or ? Like how do you confirm on your site that you’re complying.

I use a third party for client management, I’ll be speaking with them. Just curious if I need to add anything to my site.

You'll need to update your privacy policy. Depending on how good your current one is, there might be big changes to make, or just small amendments. The Data Protection Act in the UK requires organisations to disclose certain things on their privacy policies currently, but many don't.

As an example, you need to communicate what data you process and on what basis you process it.

Search online and you'll find templates. I'll PM you with two in particular that I would recommend looking at.
 
As far as I am aware there is no requirement to do this. The main points for you would be that you are-

Collecting data responsibly
Storing it responsibly
Retaining it only as long as necessry
Being transparent about how you do the above
Providing means for your clients to request data removal
Registering with the ICO
reporting data breeches if they occur

To cover yourself I would suggest revising your privacy policy - state that you are GDPR compliant, include a heading for each of the above points detailing your practices, retention policy and so on. Finally include a form, or contact method for anyone wishing to request access to or removal of the data you hold on them.

Won't it also be a requirement that 3rd parties handling the data are also compliant. I think @t0mmy is referring to his CRM system used and if they are within the EU it should be fairly trivial for them to become compliant if they want to. If they are outside the EU and have no intention of becoming compliant it could be an issue.

I did look at the company's services in the past and they seem like they would want to become compliant.
 
Won't it also be a requirement that 3rd parties handling the data are also compliant. I think @t0mmy is referring to his CRM system used and if they are within the EU it should be fairly trivial for them to become compliant if they want to. If they are outside the EU and have no intention of becoming compliant it could be an issue.

I did look at the company's services in the past and they seem like they would want to become compliant.

Yes, I beleive that’s right - third parties need to be compliant if they’re handling your data. And further more, you as the data controller are responsible for those third parties compliance - so if there’s an issue it won’t be enough there for you to say - the third party were at fault and we assumed they were compliant.
 
Yeah we use SPP and they sent out a notification with a number of points detailing changes they’ve made to become compliant.. so I basically just need to update my privacy policy now.
 
Yeah we use SPP and they sent out a notification with a number of points detailing changes they’ve made to become compliant.. so I basically just need to update my privacy policy now.

Register with the ICO as well if you haven’t already.
 
Thanks for the guide man. I have to gulp em. Subbed to the thread ;)
 
Register with the ICO as well if you haven’t already.
Is that a requirement for compliance? I know from experience that sometimes it is best not to sign up to these kinds of organisations if it is not required by law as sometimes it can just put you on a radar to be looked into to confirm compliance.

If it is a requirement that is one thing but if not then I would be wary, unless you have a reason not to be.
 
Is that a requirement for compliance? I know from experience that sometimes it is best not to sign up to these kinds of organisations if it is not required by law as sometimes it can just put you on a radar to be looked into to confirm compliance.

If it is a requirement that is one thing but if not then I would be wary, unless you have a reason not to be.


Yeah inretested in the answer to that too for the very same reasons.. is it a requirement?
 
Is that a requirement for compliance? I know from experience that sometimes it is best not to sign up to these kinds of organisations if it is not required by law as sometimes it can just put you on a radar to be looked into to confirm compliance.

If it is a requirement that is one thing but if not then I would be wary, unless you have a reason not to be.

Yeah inretested in the answer to that too for the very same reasons.. is it a requirement?

I beleive it’s a requirement to report a data breech to the ICO within 72 hours of it happening. So I’m assuming it’s at least helpful to be registered with them beforehand.

Ref - https://ico.org.uk/for-organisation...ction-regulation-gdpr/personal-data-breaches/

But aside from gdpr, apparently it’s a criminal offence not to be registered with them if you handle data, as per -

Registration with the ICO
If you handle personal data, you may need to register as a data controller with the Information Commissioner’s Office. Registration is a statutory requirement and every organisation that processes personal information must register with the ICO, unless they are exempt. Failure to register is a criminal offence.

Ref - https://ico.org.uk/for-organisations/business/

Also, just read that if you have a pre-existing marketing list, it’s only gdpr compliant if the users on the list were notified about your privacy policy at the time of signup.

Ref - https://ico.org.uk/for-organisation...ion-regulation-gdpr-faqs-for-small-retailers/

But I guess that even having a link to privacy policy in footer on the page where they signed up would be adequate.
 
Also, just read that if you have a pre-existing marketing list, it’s only gdpr compliant if the users on the list were notified about your privacy policy at the time of signup.

Ref - https://ico.org.uk/for-organisation...ion-regulation-gdpr-faqs-for-small-retailers/

But I guess that even having a link to privacy policy in footer on the page where they signed up would be adequate.

If you're processing data using "consent" as the legal basis, then that consent needs to have been given under the same circumstances as it would need to be given once GDPR is enforced. For example, the person needs to have given consent specifically to receive marketing materials, and separately of signing up to any contract. The method of gaining consent also needs to be correct - pre-checked boxes and opt-out mechanisms aren't valid ways of consenting any more.

I've had a business approach me that wants to process old customer data on the basis of "legitimate interests" - that by not contacting them, the customer is at risk of harm. The business is a garage providing MOTs and wants to remind customers that unless they have a new MOT they'll be breaking the law. I personally don't think that it a great basis, but a lot of GDPR is subjective, and I do see the potential argument. My point is that for some businesses, consent isn't the only basis that could be used to contact previous customers with marketing messages.

Also remember that GDPR only relates to personal data - if the context in which the individual's data is used is a business one, then GDPR does not apply. For example, if I'm a freelance app developer and I ask someone from the BHW marketplace to design me a logo for an app I'm designing, that is a business to business service, and is not covered by GDPR. If I'm a member of BHW looking at the forum as to how to make money online, then I'm not a business and GDPR does apply to my data. Other data protection law might apply as well, so if you cover for GDPR, you're covering all bases.

Also, although you don't have to report all data breaches - just certain ones (read the page @davids355 gives all the way to the end) - the ones that you won't have to report are probably few and far between. Its another example of where GDPR lets the data controller make a subjective judgment.
 
Back
Top