GDPR

25th May 2018 - Are you ready?

The countdown has begun!

0Hours0Minutes0Seconds

The General Data Protection Regulation was approved by the EU parliament on the 14th April 2016 and will take effect on the 25th May 2018 replacing the Data Protection Directive 95/46/EC. Designed to unify data privacy laws across Europe, protecting the privacy of any EU individual, ensuring by way of compliance that companies within the EU and outside of it (if they offer goods or services, or monitor the behaviour of, EU data subjects) process data lawfully.

Non-compliance can lead to fines of up to €20m (£17m) or 4% of annual global turnover (whichever is greater). What? Wait... How Much! OK this is the maximum fine that can be imposed, the supervising authority, the ICO in the case of the UK, will operate a tiered approach to fines and the levy imposed will directly relate to the seriousness of the infringement. Currently and for the next (look at the countdown above), the ICO under the DPA can impose a maximum penalty of £500,000 and this can only be levied against a 'data controller'. With the introduction of GDPR any fines levied can be against both a 'data controller' and a 'data processor'.

Don't Panic - A £17m fine is a huge amount and presently is the focus of many headlines. Elizabeth Denham, UK Information Commissioner, has sought to assure UK businesses stating, "It’s scaremongering to suggest that we’ll be making early examples of organisations for minor infringements or that maximum fines will become the norm". Furthermore, Denham says "Issuing fines has always been and will continue to be, a last resort. Last year (2016/2017) we concluded 17,300 cases. I can tell you that 16 of them resulted in fines for the organisations concerned". All things considered with less than 0.1% of cases resulting in a fine you could conclude the ICO have been fair when assessing negligence. It would also be fair to say that the DPA has been in need of modernisation and GDPR has been a long time coming. Prepare correctly, refer to the ICO website for guidance or engage with a third party to help you with the transition, Yeap there are several companies offering assistance if required.

What effect will Brexit have? - On the 21st June the Queen announced, "A new law will ensure that the United Kingdom will retain its world class regime, protecting personal data" and the government confirmed its intention to bring GDPR into UK law. No change post Brexit then, well expectations are that once the UK leaves the EU any changes will be minor and will largely follow the GDPR. Given that the UK Government and the ICO have supported and contributed to GDPR it would be natural to assume any changes post Brexit would be small. That said it's inevitable some changes will be required and the ongoing Brexit negotiations will influence these changes. The ICO represents the UK's interests in the EU's GDPR, however post Brexit what influence if any the ICO will have remains to be seen.

For those already deep in GDPR preparation you may well be familiar with the term 'one stop shop', the mechanics of which allows for the appointment of a 'lead supervisory authority' for organisations carrying out 'cross border processing' (operating across multiple EU member states). Essentially this allows organisations to identify a 'main establishment' (a supervisory authority - normally determined by where the organisations central administration is located in the EU) to communicate with regarding data protection compliance, negating the need to deal with multiple EU authorities, each potentially having slightly differing implementations of the GDPR. The benefits of a 'one stop shop' are not in question but these benefits only apply to organisations with a main establishment in the European Union. Post Brexit some UK businesses will find themselves unable to appoint a 'lead supervisory authority' as they will have no central administration in the EU. One would hope common sense prevails during the negotiations on this point.

If you as an organisation or business adhere to the Data Protection Act following best practice guidance, then you have a solid foundation to work on to ensure you are compliant with GDPR. One of the headline differences between DPA and GDPR surely must be many aspects of the former are 'best practice' whilst with the latter, much is a 'requirement' and so mandatory for compliance. Furthermore, and this I consider to be fundamental, GDPR emphasises accountability requiring businesses to be able to demonstrate compliance with its principles encompassing personal data.

Since April 2016 guidance has been subject to revision, creating clarity and at times uncertainty. One particular aspect is the appointment of a Data Protection Officer (DPO). Under GDPR you must appoint a data protection officer if you:

  • are a public authority (except for courts acting in their judicial capacity);
  • carry out large scale systematic monitoring of individuals (for example, online behaviour tracking); or
  • carry out large scale processing of special categories of data or data relating to criminal convictions and offences.

Confusion arose when early proposals suggested 'large scale' meant an organisation with over 250 employees or 5,000 personal data records, this led several to believe there was a DPO exemption for SMEs. Peter Brown, Senior Technology Officer with ICO at the Infosec 2017 Conference stated , "I’ve heard plenty of people talking about there being a DPO exemption for SMEs this is absolutely not the case."

If you have not started preparing for GDPR then time is now of the essence. Refer to the ICO website for the latest guidance, there is much to digest. A good starting point would be to compare your current DPA practices against the GDPR guidance noting where you need to amend or add to. Always keep in mind you need to be able to demonstrate compliance and don't overlook your software applications. Many businesses will likely still be using legacy applications, even if not seek assurance with your software vendor that their product is secure and all personal data held is encrypted at all times, including 'at rest'.

We all need to play our part to help secure personal data and respect the rights of individuals whilst processing their data. Being able to demonstrate your policies, processes, data subject controls and the technology supporting these are in keeping with GDPR, will not only avoid fines but will make the digital world a safer place to be a part of.

Mike Bull
** Yeap Ltd.**

Professional - Confidential - Domain Experts