The General Data Protection Regulation (‘GDPR’) and the Data Protection Act 2018 came into force on the 25th May 2018. Despite the long lead in time, a considerable amount of confusion still remains about what firms need to do to ensure on-going compliance with the new rules.
So what are the key challenges that firms face?
First, they need to comply with the new accountability principle. In practice this means more user-friendly information for clients about what is being done with their personal data.
Secondly, they need to think about what the basis for their processing of personal data is. An awful lot of noise has been made about consent but there are other grounds that can be relied upon and this also applies in respect of marketing.
Thirdly, firms need to be aware of changes to the rights of data subjects including
access to information and the ability to request deletion of their personal data.
Fourthly, firms need to update their procedures in respect of security breach reporting. Previously entirely voluntary, this is now mandatory in a number of scenarios and firms need to ensure that employees are aware of the relevant time frames and information to be provided.
Fifthly, firms need to review their marketing to ensure that it is compliant with the GDPR and other relevant rules. They also need to keep a watchful eye on the forthcoming E-Privacy Regulation and consider what changes, if any, need to be made in the light of this.
Sixthly, firms need to consider whether it is appropriate to appoint a data protection officer. Although in most cases this will not be mandatory it is still good practice to have a person who has responsibility for this area.
Failure to comply with the new rules can potentially lead to very large fines, compensation claims and reputational damages.
![]() |
|
|
|
|
Keith Markham will be giving his seminar on GDPR - where are we now and where are we going? on 18 October at Exeter Racecourse. To reserve your place go to DASLS website or email harry@dasls.com |