Find our more about GDPR and how you can prepare for the new legislation.
The General Data Protection Regulation is new EU wide legislation which aims to put the control of personal data back into the hands of the individual. New rules and regulations on data collection and data processing will allow individuals enhanced rights to access or withdraw their data.
This new legislation will replace the existing Data Protection Act (1998) for companies based within the United Kingdom. However, the GDPR applies to all companies worldwide that process personal data, or monitor behaviour, of data subjects who reside in the EU.
GDPR was agreed upon by the European Parliament in April 2016, starting the countdown to enforcement from May 25th 2018. Companies that fail to reach compliance by this date will be subject to potentially large fines and penalties of up to €20m or 4% of global annual turnover, whichever is greater. The GDPR goes further than previous legislation, enabling consumers to claim compensation from data controllers or processors who infringe the regulation for the damage they have suffered.
We, as a data processor, are committed to supporting our customers as we all navigate the necessary changes and enhancements to our processes and business practices in preparation for the enforcement date. This initial guide lays out key information about GDPR, including links to useful resources to assist you in preparing your organisation for compliance.
Please note: Whilst we will support our customers by presenting the key concepts within the GDPR, this document and any other relating to GDPR created by Esteiro Business Solutions Ltd. is only intended to provide general guidance. Please contact a legal representative for any formal legal advice.
The new regulation applies to ‘controllers’ and ‘processors’, meaning a business is a data controller which has control of how and why personal data is processed. A processor is a third party who processes that data on the controller’s behalf. If you process any form of personal data either in the EU, or of data subjects who are in the EU (even if only temporarily), then the GDPR applies.
There are a small number of exemptions for specific activities, such as processing covered by the Law Enforcement Directive, processing for national security or processing carried out by individuals purely for personal (not business related) reasons.
The legislation technically does not apply to some businesses with less than 250 employees. However, it is stipulated that it will apply to small businesses if the processing carried out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as defined in Article 9. When you consider how often you deal with personal data, which includes present and past employees, then most organisations will be affected.
Making data protection your business self assessment
Almost every organisation, whether B2B or B2C, will process personal data under the new regulations. If the Data Protection Act currently applies to your business, you can safely assume GDPR will too.
Under GDPR’s definition, personal data is essentially any information that could be related to an identifiable and living human being. The official definition from Article 4.1 describes personal data as:
‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
This can include obvious details such as name or address, but also online identifiers such as an IP address.
The GDPR has similar principles to the current Data Protection Act (DPA), so current compliance with the DPA will provide a firm foundation. However, there are significant enhancements and additional requirements under GDPR which you will need to review and bring in to your existing data protection framework within your organisation.
The most useful resource, alongside the actual GDPR itself, will be the Information Commissioner’s Office (ICO) website. The ICO will be responsible for regulating GDPR in the UK, and they will also be ensuring compliance. They have a useful livechat feature which can be helpful to check if an assumption you are making is compliant.
If you do not currently have a GDPR plan in place, the ICO’s Getting Ready for the GDPR will help you to create a quick assessment of your current position.
The Information Commissioner’s office have a suggested list of processes to run through to become GDPR compliant. We’ve summarised the key points as general guidance, refer to the Preparing for the General Data Protection Regulation PDF for more information.
The Information Commissioner’s office are specifically addressing consent as a legal basis with their detailed guide to consent. If you currently hold personal information under consent, you will need to review this information and determine if your current consent meets with the additional requirements of the GDPR. For example, pre-ticked boxes cannot be used as a basis of consent.
Consent for marketing calls, messages, website cookies or other online tracking methods is detailed in the current Privacy and Electronics Communications Regulations 2003 (PECR). However, there will be a new ePrivacy Regulation due to come into force alongside the GDPR in May 2018. This new EU wide legislation is currently in development, with a deadline of December 2017 for the new legislation to be finalised. As yet the ICO are not releasing guidance as the legislation is not yet available to review.
It is worth familiarising yourself with the six legal basis for processing personal data under the GDPR. After your data audit, you will need to document which legal basis each group of data is processed under. Consent is one option out of six, and is likely to be the most difficult to comply with.
Gold-Vision, as with other business software products, will be one element of your GDPR strategy. After completing a GDPR compliance review and formulating a plan it is likely you will need to map some of it into your CRM.
Whilst each Gold-Vision instance is uniquely configured to suit individual processes and business practices, there are central themes that will assist you in recording your GDPR compliance.
Once you have identified your processes, legal basis for processing personal data, special requirements such as sensitive/personal data, and have carried out a data audit or DPIA, you will be ready to map these processes to your specific Gold-Vision instance. See more
If you have specific questions regarding Gold-Vision and GDPR please contact your account manager directly.
Getting Ready for the GDPR
Preparing for the General Data Protection Regulation
Detailed guide to consent
Six legal basis for processing personal data
ICO’s guide to conducting Privacy Impact Assessments