GDPR: Next steps, post-enforcement
The 25th May 2018 is the day that the General Data Protection Regulation (“GDPR”), with its tightened rules around ‘consent’, came into force across the EU.
One of the reasons why the GDPR has caused such a stir, is that it not only creates tighter data protection obligations but the penalties for breaching the provisions have also been bolstered markedly.
The UK Information Commissioner, Elizabeth Denham, has made it clear that the regulator will not be seeking to punish businesses for minor transgressions immediately. Rather, she sees data protection as an evolutionary process where businesses that are moving towards compliance and raising the general standards of data protection will be treated sympathetically and with a proportionate response in the event of a breach of the rules.
If you are taking your GDPR obligations seriously and working towards compliance then you need not fear the regulator coming down on you. Those who are wilfully ignorant, deliberately disregarding or negligent of their data protection obligations however should feel slightly more uneasy.
If you, like many, are unsure of the steps to take towards compliance then the following check-list will assist:
- Consider and document your lawful grounds for processing personal data.
- Consider and update your privacy notices.
- Identify, draft and implement the necessary policies (both internally and externally).
- Review your data processing agreements.
- Establish a lawful gateway for international data transfers.
- Develop mandatory breach notification procedures.
- Develop procedures to observe new and enhanced individual’s rights.
- Designate a privacy officer / data protection officer.
- Maintain adequate records.
- Contact a legal professional to review your GDPR compliance.
Events series: Spotlight on GDPR
We are running a series of events during 2018 to help our clients better understand particular issues under the GDPR. The first, 'Dealing with subject access and other subject rights' is scheduled for 3 July 2018. Please email our events team if you are interested in attending this seminar.
News & Insights
Operational Resilience third party service provision and outsourcing - the new normal
The Bank of England,the PRA and the FCA published consultation papers to implement a stronger regulatory framework.
ASA continues to focus on Influencer Marketing in 2020
In the first round of published adjudications for 2020 the ASA upholds complaints about Instagram Posts promoting Southern Comfort.