Friday, 9 March 2018

What is GDPR and should you care?


If you haven’t heard about GDPR yet, it stands for General Data Protection Regulation. It is an attempt modernise existing data protection laws, bringing them into line with the many different ways personal data is stored and used in the 21st century across the EU (and it will still apply in the UK even after Brexit).

That means new regulations concerning how businesses can use personal data, promising greater levels of protection and additional rights for individuals. The regulation will come into effect from 25th May 2018, and businesses failing to meet the new guidelines will be subject to heavy fines from the regulator.

Who does GDPR apply to?

The regulation will effectively apply to any businesses holding personal data of EU citizens, and that includes things like names, email addresses, bank details, photos, identification numbers, medical information and even information like IP addresses and social media posts.

That essentially means that every one of us will be protected by the new regulation to some extent.

GDPR is a very welcome improvement to consumer data protection and is based on an EU Directive that the UK has adopted through a British act of parliament. Even if brexit happens, we will still have GDPR.

What protection is provided?

Businesses will be required to safeguard the personal data they hold on individuals, to ensure that it does not fall into the hands of unauthorised third parties.

In addition to the safeguarding of personal data, businesses will need to ensure they have consent from their customers before they can send marketing activity to them. Consent must be kept in a secure place. Moreover, from this point forward consent must be positively given.

Another important development is that customers will have the right to withdraw their consent at any time, and they will also have the right to be forgotten. That means businesses will need to know exactly where the personal information of all their customers is held, because they will have to permanently delete it if requested to do so.

What's in it for me?

After GDPR comes into effect your personal data held by various businesses should be more secure, and you should also have more control over it.

In the short term, you might find it means that you will receive a great deal more communication than usual from those businesses holding your personal information. After all, they will all require your consent before 25th May.

While this might seem inconvenient, it is a good opportunity for you to have a ‘spring clean’ by only consenting to those businesses you are happy to continue to use your personal data, and to contact you.

The final point to be made is that if you are a current customer of a business, they will still be entitled to send you service and transactional emails.

I'm a business, what do I need to do?

The short answer is "it depends".
  • If you don't hold customer data
    You don't need to do anything
  • If you hold contact information for your customers
    It needs to be secure from theft.
  • If you hold information about your customers so you can market to them
    You need to ask for consent. You may have done this already, if you can prove that, you don't need to do anything. If you can't prove it, you must ask everyone individually if they now consent. In future, you must also ask this question when you sign people up.
    This data needs to be secure from theft.

I don't know what to do

If you are a business and you're not sure what you need to do to become compliant or you're not sure if your data is secure, please get in touch with Fear of Mice. We can help.