GDPR - WHAT NOW?

Writing this article in the first few weeks of the GDPR era, it is clear that the 25 May start date was just a milestone and that data protection will be a topic we must continue to focus on in the weeks and months ahead. I am already hearing anecdotes about subject access requests being made on 25 May in reliance on the improved rights which have been granted to data subjects. It is clear that this is a significant change in the way things are and for us, as lawyers, the consequences include even more scrutiny of our systems, processes and responses.

t-calvert

 

I would hope and anticipate that the Information Commissioner’s Office’s attention will be concentrated on the big guns – the online companies and the large-scale data processors – but we are nevertheless in the spotlight. We know that the ICO was expressing opinions about our handling of personal data long before GDPR was on the agenda. It is unlikely we will be forgotten in this new age of data protection.

 

Think back to 2014 if you will. The ICO published a notice directed at the legal profession. In it, the incumbent Commissioner reported that he was disturbed by the number of breach reports the ICO had received about the handling of data by barristers and solicitors.  He had received reports of 15 data breaches in 3 months and had concerns about the serious personal data we processed and our over reliance on paper files. The warning was concluded in this way: “It is important that we sound the alarm at an early stage to make sure this problem is addressed before a barrister or solicitor is left counting the financial and reputational damage of a serious breach”. At first glance, this may appear to be a helpful ‘heads up”, but the body which can instigate the financial and reputational damage is the body which was issuing the warning! You’ll understand my unease.

 

Having said that, I am nevertheless confident that working in the legal services profession, we have a head start when considering the ways to respond to GDPR. After all, if there is one thing we know about, it’s confidentiality. Our clients expect us to keep the matters secret and most solicitors and most law firms have designed processes to manage the risk of inadvertent disclosure. This is a solid foundation stone on which to develop the GDPR response. My overriding message to the firms I have been working with over the last few months is not to panic about all of this. Another confidence-booster ought to be the familiarity of oversight and the understanding of the need to be able to have good conversations with stakeholders who have a right to be interested in what we do and how we do it. This is what we already experience with our relationship with the SRA.

 

So, whilst there is no need to panic, there is the need to make sure that answers to the GDPR questions are in your compliance response. Most of you will have revised and/or drafted new processes by now and, hopefully, rolled these out with suitable training within your firms. What’s next, in this honeymoon period with the new legislation? 

 

My compliance response in the next few months would be as follows:

  • Keep a watching brief on the guidance issued by both the ICO and from within our own industry. This has been a learning curve for all, including the thought leaders and their thinking is filtering down to us in a fragmentary fashion. The ICO publishes a monthly online newsletter. Subscribing to this (via the ICO website, ico.org.uk) will give you the alerts about additions to guidance, trends in their supervisory work and similar. The Law Society has also published its own downloadable guide to GDPR, available from www.lawsociety.org.uk
  • Ensure the topic is constantly part of your internal communications with your colleagues. It’s essential that everyone understands the impact of misunderstandings. Remind them about the need to think beyond the duties owed to the clients of the firm; be clear about the scope of the data subject definition; be clear about what happens if they are talking to a third party which may fall into the category of a data processor; have confidence that they will have the correct conversations with data subjects; that they know who to discuss data subject requests and all other concerns with; and that anyone undertaking any form of marketing or publicity is responding to the GDPR implications safely.
  • Ensure, therefore, that this topic is part of your induction exercises with new colleagues and that supervisors are considering this as part of their risk identification responsibilities.
  • Keep a watching brief on the system adaptations and new processes that you have rolled out. Your objective in doing this work will have been to manage the risk of breaching the GDPR data protection principles. Do your processes help with this?
  • Finally, if you are one of those firms for whom this topic has highlighted storage and destruction pinch points, think about a project to tackle archived files and historic computer-based records. Also, now seems a good time to look again at file closure processes and ensure that the data you retain at this end of your relationship with your clients and other data subjects is not inconsistent with your GDPR policies.

  

Tracey Calvert, 14 June 2018

Oakalls Consultancy Limited

tcalvert@oakallsconsultancy.co.uk

www.oakallsconsultancy.co.uk

 

 

Tracey Calvert is a lawyer who has worked as a senior ethics adviser with the Law Society and the SRA, and was part of the SRA policy team which drafted the SRA Handbook which was launched in 2011. She now provides compliance and ethics services to lawyers and others through her company, Oakalls Consultancy Limited, and also writes extensively on these topics. For further information about the services which Tracey can provide, please see her website, www.oakallsconsultancy.co.uk, or contact her by email or phone, tracey@oakalls.com, 07833 253057

 

 

 

 


Like   Back to Top   Seen 442 times   Liked 0 times
Subscribe to Updates And Join Over 1.2K Subscribers Today!

Subscribe to:
x

Subscribe to Updates

If you enjoyed this, why not subscribe to free email updates and join over 1275 subscribers today!

Subscribe to updates



Subscribe to:

Alternatively, you can subscribe via RSS RSS

‹ Return to

All email subscriptions must be confirmed to comply with GDPR.

I've already subscribed / don't show me this again