×

The General Data Protection Regulation

The deadline for General Data Protection Regulation (GDPR) is fast approaching. The implementation date is 25th May 2018. Many SMEs will think that this does not affect their business. This affects all types of organisations who have an EU establishment and also those who transact within the EU.

Under the GDPR, the data protection principles set out the main responsibilities for the organisation. They are similar to those in the Data Protection Act but with additional detail. There is also a new accountability requirement included in the main responsibilities.

The new accountability requirement is a significant addition. The GDPR requires you to show how you comply with the principles. You are required to document the decisions you take about a processing activity. GDPR expects you to put in place appropriate measures to demonstrate you comply. This may include internal data protection policies such as staff training, internal audits of processing activities, and reviews of internal HR policies. These measures should minimise the risk of breaches and uphold the protection of personal data.

Organisations who fail to comply will face fines from 4% of annual turnover up to £500,000.

The Information Commissioner’s Office (ICO) has published some guidance including 12 steps to take now.

Amanda Menassa

Amanda graduated from Brunel University, with a joint honours degree, achieving a BSC and BA degree in Leisure Management and Television and film studies. Amanda started her career in a customer service role before joining the hotel group Le Meridien as an Events coordinator, she was in the hotel industry for seven years and during her time won an award from a major international airline for her outstanding attitude and dedication to customer service, which she achieved while working for the Rezidor hotel group in the position of Airline Crew Manager. Amanda has over 20 years experience in customer relations and event management.

Show More...