EIGCA

GDPR – are you ready?

| News

Estimated reading time 4 min

On 25th May, the European Union’s new rules surrounding how the personal data of EU citizens can be stored and processed come in to effect, with hefty financial penalties for breaches. These regulations are called GDPR (General Data Protection Regulation).

GDPR means that organisations need to choose the correct legal basis for processing personal data, i.e. anything which identifies an individual, and ensure the needs of that basis are met. Do not make the mistake of thinking that GDPR does not apply to you … all businesses that process personal data of EU citizens, regardless of whether the business operates in or outside the EU, must comply with these new regulations.

The two most likely options which permit you to process personal data are consent and legitimate interest.

Consent

Consent is always the best option for compliance and provides more legal certainty than Legitimate Interest, which is subjective.

If you are basing the processing of personal data on the consent of an individual to do so, your organisation must prove an individual has completed an action to say Yes. This consent must be freely given, specific, informed and unambiguous, e.g. cannot have been obtained via pre-ticked boxes or implied. You must also have obtained consent for each type of data collected and for each method of communication, e.g. invoices, human resources, marketing, email, post, telephone.

Legitimate Interest

If you are not obtaining consent, you must have a lawful basis to process personal data, called Legitimate Interest. This could be where you have a relevant and appropriate relationship with the data subject, such as where the data subject is a client. Ask yourself if the processing of personal data is necessary for the pursuit of your commercial or business objectives? If yes, then you could say that you have a legitimate interest to make contact.

Data Subject Rights

GDPR states that individuals (or data subjects) have the following rights:

  • be informed of the data held
  • access the data held
  • rectification
  • erasure
  • restrict processing
  • data portability
  • object to being profiled (GDPR and ICO have not yet defined profiling)
  • have the data held supplied in an easy-to-access format at no cost

The system you use to hold personal data must allow you to respond to the above rights otherwise you will be in breach of GDPR.

What to do before 25th May 2018

  1. Decide if you will use consent or legitimate interest as the basis for processing personal data.
    a. If consent, contact all data subjects to obtain explicit consent for what you will communicate and how. Record and store all responses.
    b. If legitimate interest, contact all data subjects to inform them that this is the basis on which you will process their personal data and that they are able to opt-out at any time. Record and store responses.
  2. Review contracts with third-party suppliers, e.g. accounting, customer database, human resources, to determine if your contract with them contains adequate contractual protection to meet the needs of GDPR.
  3. Review insurance policies to determine if you are covered for data breaches and what you are covered for.
  4. Advise staff of GDPR and how it will affect the way they hold and process personal data. In addition to fines against your company for any data breaches, criminal sanctions exist where employees wilfully or negligently are responsible for data breaches. Be aware of the risks associated with employees working remotely in public spaces using free public wi-fi. Employees should only use secure wi-fi connections at home or in the office.
  5. Ensure you have a clear data protection policy / privacy notice. This should include: the data you hold; what you do with it; who you share it with; how requests to reveal, change, or delete data are handled; and how data is kept secure.


Definitions

  • Consent = “freely given, specific, informed and unambiguous indication of a data subject’s wishes by which he or she, by statement or clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”
  • Legitimate Interest = a valid reason refers to the stake that the company processing the personal data may have in that processing and ‘must be real and not too vague’. Would or should a user expect the processing to take place?
  • Personal data = any information relating to an identifiable person who can be directly or indirectly identified, e.g. name, phone number, location, online ID, genetic, mental, economic, cultural, social, physical, trade union membership, sexual orientation, politics, etc
  • Processing = segmentation, targeting, profiling, tracking links clicked, predictive analysis.