Data protection reform is less than a year away.
If you are a business owner or key decision maker or involved in compliance you need to know now what is coming so as to plan for it.
Wake Smith director Holly Dobson, who specialises in employment, data protection, and dispute resolution, looks at the headline changes and asks if you are ready?
The reforms apply from 25th May 2018. This is the date when the General Data Protection Regulation (“GDPR”) takes effect – so that’s less than 160 working days from now.
- If you are 100% compliant with the current Data Protection Act, you are in a good place to start. Are you in a position to say that or do you need to play “catch-up” fast?
- GDPR applies to data processers as well as data controllers. Some businesses won’t have a compliant model to build on.
- There will be mandatory self-reporting of breaches. Yes, you’ve read this right and what’s more within the 72 hours of the breach.
- There will be a mandatory requirement to contact all potentially affected data subjects promptly in the event of a breach.
- Fines up to the greater of €20million or 4% annual global revenue will be imposed. If nothing else grabs your attention this should. Even if your business survives any publicity that arises, can it survive the fines? If it can, what will be the effect be on profitability?
- There will be a mandatory requirement to appoint a Data Protection Officer in some businesses and across some sectors.
- The current compliance principles will be replaced with new ones. As a result, there will be a transformational change to governance and compliance. You will find a greater emphasis is placed on accurate documentation enabling audits of your compliance.
- New data subject rights and an enhanced emphasis on existing data subject rights will come in. These rights include the right to free data subject access requests to be complied with within a month. All new and enhanced data subject rights, of which this is only one, apply equally to your customers or clients and to your employees.
- Privacy notices and consent. One consequence of the changes will be a greater focus on the processing of data that you do and your explanation as to the lawfulness of what you do. You should “future proof” your processes now.
- Data Protection by Design and Data Protection Impact Assessments. Putting privacy at the heart of all that you do will be the effect of the reform. That is what they have been designed to achieve. The reforms make Data Protection Impact Assessments mandatory in certain circumstances.
Mandatory Self Reporting
We are all in for a culture shock from the morning of 25 May 2018. From then on we have to report a data breach to the regulator within 72 hours. What’s more there are very few exemptions.
It is not just the fact of the breach report which will impact on us all, but the level of detail we will have to report will place the organisation’s compliance model under the spotlight.
From that first breach the details that must be reported will provide evidence to the regulator of our business culture; policy and procedures; training and awareness in connection with our data and the circumstances of the data breach.
By its very nature we will all be ensuring that the regulator knows which businesses and which sectors to target.
Data Protection Officers
A designated Data Protection Officer will be mandatory for public bodies, and also for businesses where the core activities are large scale, regular and systematic monitoring of data subjects. Also, where the core activities are large scale processing of special categories of data, so this includes issues relating to health information, for example.
The obligations of the Data Protection Officer are set out in detail in GDPR and this is an important role which requires support and resource from the organisation concerned.
Need help?
The good news is that there is plenty help on hand to prepare for the reforms.
The Information Commissioners Office (“ICO”) have a good landing page and they have just updated their “12 Initial Steps To Take Now” leaflet.
Wake Smith is running a series of free seminars in 2017 to help businesses prepare. So far these have been fully booked but keep a look out for further events on our website or contact [email protected]
We are designing in-house training on the issues for some clients and are happy to discuss your organisation’s budget and needs.
For a discussion on how GDPR will impact your particular business and for any further assistance, contact [email protected]