- Apr 25, 2011
- 19,849
- 28,297
This is a quick guide to GDPR from my point of view (Looking at GDPR on behalf of small businesses). I am by no means an expert, but I have been studying GDPR for the past couple of weeks and I have been doing quite a bit of work in this area.
What is GDPR?
Basically GDPR is an updated version of the data protection act. It comes with a lot of new restrictions in terms of how data should be collected, stored and processed.
The GDPR brings with it a number of changes and improvements to the data protection act including:
Enhanced documentation requirements
Enhanced Fair processing notice
Stricter rules on consent to data processing
Mandatory requirement to notify the ICO of a data breach
Enhanced rights for data subjects or owners
New rules requiring the appointment of Data Protection Officers
Tougher penalties
Who does GDPR apply to?
It applies to anyone who processes data belonging to EU residents - so that is irrespective of whether or not you are operating in the EU yourself.
What does this mean in reality?
It relates to identifiable data - for example any data where you could identify a specific individual. This could be as little as a full name and as much as the collection of bank details, social security numbers and so on.
When you are collecting this data you have to do so responsibly, in particular you should be collecting the data with consent, you should only be collecting as much data as necessary to undertake whatever work you are doing for the subject and you should also only retain the data for as long as required.
In addition you need to take care when storing the data - ensuring that it is held securely - and lastly you should be transparent with the ways in which you store and use the data. The subject has a right to ask about this process and also has a right to request removal of the data from your system - which you must make easy for them to do.
What about if you outsource your data storage to a third party?
If a third party is handling your client data on your behalf that does not abscond you from any responsibility. In fact as the data controller you are responsible for it still and as such it is also your responsibility to ensure that any third parties who handle data on your behalf are doing so in compliance with GDPR.
This also means that if you handle data for third parties yourself then you might find yourself losing work if you are not GDPR compliant, because lots of companies within the EU are going to start requiring this.
Some questions answered
Do I have to re-opt in all of my marketing contacts?
No you dont have to do this. as long as you do have an audit trail and you can confirm that you have consent to send marketing to those contacts.
Do I have to encrypt data at rest?
The level of security required will generally be proportionate to the risks posed to the rights and freedoms of data subjects. Moreover, cost considerations, the nature, scope, context, and purposes of data processing, and the current state of the art will also be factored into determining what is appropriate.
I take this to mean that no, data does not necessarily need to be encrypted at rest, but it depends on the nature of the data, how big a risk there is of it falling into the wrong hands and also how proportionate the costs of encryption would be.
How long do I have to retain client data?
The Act does not set out any specific minimum or maximum periods for retaining personal data. Instead, it says that:
Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
This is the fifth data protection principle. In practice, it means that you will need to:
review the length of time you keep personal data;
consider the purpose or purposes you hold the information for in deciding whether (and for how long) to retain it;
securely delete information that is no longer needed for this purpose or these purposes; and
update, archive or securely delete information if it goes out of date.
Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
This is the fifth data protection principle. In practice, it means that you will need to:
review the length of time you keep personal data;
consider the purpose or purposes you hold the information for in deciding whether (and for how long) to retain it;
securely delete information that is no longer needed for this purpose or these purposes; and
update, archive or securely delete information if it goes out of date.
References
https://ico.org.uk/for-organisations/guide-to-data-protection/principle-5-retention/
https://www.signupto.com/news/digital-marketing/gdpr-double-opt-in-and-re-consent/
https://www.itgovernance.eu/blog/en/does-the-gdpr-apply-to-me
GDPR Audit and Policies
https://www.blackhatworld.com/seo/gdpr-site-survey-guidance-and-policies.1023467/
What is GDPR?
Basically GDPR is an updated version of the data protection act. It comes with a lot of new restrictions in terms of how data should be collected, stored and processed.
The GDPR brings with it a number of changes and improvements to the data protection act including:
Enhanced documentation requirements
Enhanced Fair processing notice
Stricter rules on consent to data processing
Mandatory requirement to notify the ICO of a data breach
Enhanced rights for data subjects or owners
New rules requiring the appointment of Data Protection Officers
Tougher penalties
Who does GDPR apply to?
It applies to anyone who processes data belonging to EU residents - so that is irrespective of whether or not you are operating in the EU yourself.
What does this mean in reality?
It relates to identifiable data - for example any data where you could identify a specific individual. This could be as little as a full name and as much as the collection of bank details, social security numbers and so on.
When you are collecting this data you have to do so responsibly, in particular you should be collecting the data with consent, you should only be collecting as much data as necessary to undertake whatever work you are doing for the subject and you should also only retain the data for as long as required.
In addition you need to take care when storing the data - ensuring that it is held securely - and lastly you should be transparent with the ways in which you store and use the data. The subject has a right to ask about this process and also has a right to request removal of the data from your system - which you must make easy for them to do.
What about if you outsource your data storage to a third party?
If a third party is handling your client data on your behalf that does not abscond you from any responsibility. In fact as the data controller you are responsible for it still and as such it is also your responsibility to ensure that any third parties who handle data on your behalf are doing so in compliance with GDPR.
This also means that if you handle data for third parties yourself then you might find yourself losing work if you are not GDPR compliant, because lots of companies within the EU are going to start requiring this.
Some questions answered
Do I have to re-opt in all of my marketing contacts?
No you dont have to do this. as long as you do have an audit trail and you can confirm that you have consent to send marketing to those contacts.
Do I have to encrypt data at rest?
The level of security required will generally be proportionate to the risks posed to the rights and freedoms of data subjects. Moreover, cost considerations, the nature, scope, context, and purposes of data processing, and the current state of the art will also be factored into determining what is appropriate.
I take this to mean that no, data does not necessarily need to be encrypted at rest, but it depends on the nature of the data, how big a risk there is of it falling into the wrong hands and also how proportionate the costs of encryption would be.
How long do I have to retain client data?
The Act does not set out any specific minimum or maximum periods for retaining personal data. Instead, it says that:
Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
This is the fifth data protection principle. In practice, it means that you will need to:
review the length of time you keep personal data;
consider the purpose or purposes you hold the information for in deciding whether (and for how long) to retain it;
securely delete information that is no longer needed for this purpose or these purposes; and
update, archive or securely delete information if it goes out of date.
Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
This is the fifth data protection principle. In practice, it means that you will need to:
review the length of time you keep personal data;
consider the purpose or purposes you hold the information for in deciding whether (and for how long) to retain it;
securely delete information that is no longer needed for this purpose or these purposes; and
update, archive or securely delete information if it goes out of date.
References
https://ico.org.uk/for-organisations/guide-to-data-protection/principle-5-retention/
https://www.signupto.com/news/digital-marketing/gdpr-double-opt-in-and-re-consent/
https://www.itgovernance.eu/blog/en/does-the-gdpr-apply-to-me
GDPR Audit and Policies
https://www.blackhatworld.com/seo/gdpr-site-survey-guidance-and-policies.1023467/