On 27th April 2016, the General Data Protection Regulation (GDPR) was officially adopted. After a two-year transition period, it was enacted on 25th May 2018, replacing the Data Protection Act of 1998 and the EU E-Privacy Directive. If you’re unsure about the GDPR or how it will affect you, Five 7T is here to help.
Today’s world vastly differs from when data protection laws were implemented around 20 years ago. With the rise of smartphones, tablets, laptops, and personal computers, there has been a significant increase in digital information being created, captured, and stored. The existing data protection laws have become inadequate, leaving too many opportunities for data misuse.
The GDPR is a new set of laws designed to regulate better how businesses handle sensitive personal data. It governs how companies communicate, store, and use customer information, applying to any business associated with a European member state.
Unlike its predecessors, the GDPR is a regulation, not a directive.
Directives outline goals, but their interpretation can vary from country to country. However, a regulation is a binding legal agreement with severe penalties for non-compliance. All countries must follow one set of rules without any exceptions.
Brexit has no impact on GDPR’s implementation. Even after leaving the EU, UK businesses with European contacts or subscribers must adhere to the GDPR or face consequences. The Information Commissioner’s Office will enforce the GDPR in the UK. The UK will also implement a new Data Protection Bill, including all GDPR provisions with minor alterations. The rules will be the same for businesses in any EU member state.
The upcoming Data Protection Bill will incorporate nearly all GDPR provisions, with minor changes to protect specific groups like researchers, anti-doping agencies, and journalists. Although the bill is still under review and subject to amendments, it will replace the existing data protection laws and come into full effect once passed.
The GDPR affects any business responsible for controlling or processing personal data, covering any data that can identify an individual. Essentially, any information about a person your business acquires falls under the regulation. This data is categorised into two types: personal and sensitive.
This includes, but is not limited to:
Personal Information:
Sensitive Information:
Additionally, pseudonymised data is covered if the pseudonym can identify the individual.
The GDPR places a greater emphasis on transparency between businesses and their customers. Here are some fundamental changes:
Individual Rights Under GDPR
The GDPR introduces several new rights for individuals:
Personal data includes anything that can be used to identify an individual, even a social media ID. This information must be obtained and processed only with the individual’s permission, which should be clearly stated in your terms and conditions.
Businesses are now more accountable for handling personal information. They must adhere to several stringent requirements to remain compliant with the GDPR:
Individual Access to Personal Data
Under GDPR, the process for individuals to access their data has been simplified:
In the past, if you requested access to personal data being held about you by a company or organisation, you had to submit a Subject Access Request or SAR. This typically involved a £10 fee which under the GDPR is being scrapped. Upon a request for information being made, a company or organisation has one month to provide the requested data – free of charge!
In cases where consent is withdrawn, information was unlawfully collected and processed, or the information is no longer relevant, an individual can request that their data be deleted. The individual also has a right to an explanation of a decision made about them rather than being subject to automated processing of data.
Navigating the complexities of GDPR compliance can be challenging. Five 7T offers comprehensive support to help businesses prepare for and comply with the GDPR.
Contact Five 7Tfor GDPR Assistance.
If you are concerned about how GDPR affects your business, contact Five 7Ttoday. Our expert, Ollie Lawson, will provide tailored advice to meet your business needs. With our support, you can ensure your business fully complies with the General Data Protection Regulation, protecting your company and customers’ data.
For more information and to speak directly with our in-house GDPR expert, contact Edirect. We are here to help you navigate the complexities of GDPR and ensure your business remains compliant.
SSL Certificate
Adding an SSL Certificate to your website is essential to protecting your users’ data. Here’s how it benefits your site:
Privacy Policy
A Privacy Policy is crucial for GDPR compliance. Here’s how we can assist:
Check Boxes for Consent
Under GDPR, obtaining and proving consent is mandatory. Here’s how we implement this:
The checkboxes will read as follows:
“I have read and accept the Privacy Policy and consent to [COMPANY NAME] contacting me about my enquiry.”
“I consent to [COMPANY NAME] contacting me with future updates.”
By implementing these measures, you ensure your business is aligned with GDPR requirements, safeguarding personal data and maintaining user trust. For more detailed assistance on achieving full GDPR compliance, contact us at Five7T today.
The following are the most asked questions regarding GDPR:
What Is a Breach of Data Protection?
A breach is any situation where personal data is destroyed, lost, altered, disclosed, or accessed without positive consent. Data breaches involving individual and sensitive information must be reported to the Information Commissioner’s Office (ICO).
What Is Personal Data Under The GDPR?
Under the GDPR, personal data includes any information that can be used to identify an individual. This can include, but is not limited to, their name, address, telephone number, and social media ID.
What Are the Fines?
Any violation of the GDPR can result in significant fines. For example, not employing or assigning a Data Protection Officer (DPO) when required or improperly collecting or processing data can lead to penalties. The severity of the violation determines the acceptable amount:
Smaller offences: Up to €10 million or 2% of the firm’s global turnover, whichever is greater.
More serious offences: Up to €20 million or 4% of the firm’s global turnover, whichever is greater.
What Is the Difference Between a ‘Controller’ And A ‘Processor’?
Following is the easy and straightforward definition:
Controller: An entity responsible for determining how personal data is used and for what purpose.
Processor: A person or group responsible for processing any information the controller collects. This includes obtaining, recording, adapting, or holding personal data.
While GDPR might seem daunting, its long-term benefits for businesses and individuals are significant. It demonstrates your commitment to privacy and security, helping build trust with your customers and making them more comfortable sharing their information.
To find out how Five 7T can help, email us or call us.