Are you confident that your business is fully GDPR compliant?
With the General Data Protection Regulation (GDPR) in full effect, ensuring compliance is non-negotiable for businesses handling the personal data of EU citizens.
Failure to adhere to GDPR principles can result in hefty fines and severe reputational damage.
In this comprehensive guide, we’ll walk you through the essential steps to assess and fortify your GDPR compliance strategy for 2024 and beyond.
From conducting thorough data audits to implementing robust security measures, we’ve got you covered with actionable insights and best practices.
Don’t let GDPR compliance slip through the cracks – dive in now to safeguard your business and maintain customer trust in the digital age.
WHAT IS THE GDPR?Under GDPR, businesses must obtain explicit consent from individuals before collecting, using, or sharing their personal data. This means that consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes or implied consent are no longer sufficient. Individuals must actively opt-in, and businesses must provide a clear and easy way for them to withdraw their consent at any time.
DATA SUBJECT RIGHTSGDPR grants individuals several rights over their personal data, including:
Businesses must have processes in place to promptly respond to and fulfil these requests.
DATA BREACH NOTIFICATIONIn the event of a data breach that poses a risk to individuals’ rights and freedoms, companies must notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to individuals, the affected individuals must also be notified without undue delay.
This requirement emphasises the importance of having robust data security measures and incident response plans in place to quickly detect, investigate, and mitigate data breaches.
DATA PROTECTION OFFICER (DPO)Certain organisations, such as those that process large volumes of sensitive data or engage in regular and systematic monitoring of individuals, are required to appoint a Data Protection Officer (DPO). The DPO is responsible for overseeing GDPR compliance, providing advice and training, and serving as a point of contact for supervisory authorities and individuals.
Even if not legally required, appointing a DPO or assigning GDPR responsibilities to a specific team member can help ensure ongoing compliance and demonstrate a commitment to data protection.
GDPR PRINCIPLESThe GDPR is built upon seven key principles that guide how personal data should be handled:
By adhering to these principles, businesses can build a strong foundation for GDPR compliance and foster trust with their customers and partners.
GDPR COMPLIANCE CHECKLIST: ESSENTIAL STEPS FOR BUSINESSESNow that we understand what the GDPR is and why it matters, let’s look into the practical steps businesses need to take to ensure compliance. Adhering to GDPR involves a comprehensive approach that covers data management, security, and transparency. Here’s a detailed checklist to guide you through the process:
CONDUCT A DATA AUDITThe first step in GDPR compliance is understanding what personal data your business handles. This involves conducting a thorough data audit to identify, categorise, and document all instances of personal data collection, processing, and storage.
IDENTIFY PERSONAL DATA🚩MANUAL CHECK – Review your data audit documentation to ensure it covers all relevant data processing activities and is up-to-date.
UPDATE PRIVACY POLICIES AND CONTRACTSGDPR requires businesses to be transparent about their data practices and provide clear information to individuals about their rights. Updating your privacy policies and contracts is essential to meet these requirements.
REVISE PRIVACY POLICIES🚩MANUAL CHECK – Have a GDPR professional review your updated privacy policies and contracts to ensure your GDPR compliance.
IMPLEMENT DATA SECURITY MEASURESGDPR requires businesses to implement appropriate technical and organisational measures to ensure the security of personal data. This involves a multi-faceted approach to data protection.
ENCRYPT DATA🚩MANUAL CHECK – Assess your current data security measures and identify areas for improvement based on the requirements of the GDPR.
ESTABLISH DATA BREACH RESPONSE PROCEDURESGDPR requires businesses to notify the relevant supervisory authority and affected individuals in the event of a data breach. Having a well-defined data breach response plan is crucial.
DEVELOP A BREACH RESPONSE PLAN🚩MANUAL CHECK – Review your data breach response plan and ensure it aligns with GDPR requirements and industry best practices.
By following this GDPR compliance checklist, businesses can take significant steps towards ensuring the protection of personal data and meeting their legal obligations. Remember, GDPR compliance is an ongoing process that requires regular review and updates to keep pace with evolving data practices and regulations.
GDPR DATA PROTECTION REQUIREMENTSGDPR requires that businesses process personal data only when there is a legal basis for doing so. This means that you must have a valid reason, such as consent from the individual, a contractual obligation, or a legitimate interest, before collecting or using someone’s personal information.
Additionally, you must be clear and transparent about how the data will be used. This involves providing individuals with information about the purpose of data collection, how long it will be stored, and who will have access to it. This information should be presented in a concise, easily accessible, and understandable manner, such as in a privacy policy or notice.
CONSENT UNDER THE GDPROne of the most common legal bases for processing personal data is consent. Under the GDPR, consent must be freely given, specific, informed, and unambiguous. This means that:
🚩MANUAL CHECK – Review your consent processes to ensure they meet GDPR requirements. The UK’s Information Commissioner’s Office (ICO) provides detailed guidance on consent under the GDPR.
PURPOSE LIMITATION AND DATA MINIMISATIONThe GDPR requires that personal data be collected and used only for specified, explicit, and legitimate purposes. This means that you must clearly define the reason for collecting the data and not use it for any other incompatible purposes later on.
Moreover, you should limit the data you collect to what is necessary for the stated purpose. This principle of data minimisation aims to reduce the risk of data breaches and ensure that individuals have control over their personal information.
For example, if you’re collecting email addresses for a newsletter subscription, you should not use those email addresses for targeted advertising without obtaining separate consent.
ACCURACY AND STORAGE LIMITATIONUnder GDPR, you have an obligation to keep personal data accurate and up-to-date. This means taking reasonable steps to ensure that inaccurate data is rectified or erased without delay.
Additionally, you should only retain personal data for as long as necessary to fulfil the original purpose for which it was collected. Once that purpose has been achieved, the data should be securely deleted or anonymised. Unless there is a legal requirement to keep it for longer.
DATA RETENTION POLICIESTo comply with the storage limitation principle, it’s essential to have a clear data retention policy that sets out how long different types of personal data will be kept. This policy should take into account any legal obligations to retain data, such as tax or employment records.
🚩MANUAL CHECK – Review your data retention practices and develop a policy that aligns with GDPR requirements. The GDPR does not specify exact retention periods, so you’ll need to determine what is appropriate for your business based on the purposes of the processing.
INTEGRITY, CONFIDENTIALITY, AND ACCOUNTABILITYThe GDPR requires that personal data be processed in a manner that ensures its security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage. This involves implementing appropriate technical and organisational measures, such as encryption, access controls, and regular security testing.
Moreover, the GDPR introduces the principle of accountability, which requires businesses to demonstrate compliance with the regulation. This means not only implementing the necessary measures but also documenting them through policies, procedures, and records of processing activities.
DATA PROTECTION IMPACT ASSESSMENTS (DPIAS)One key tool for demonstrating accountability under GDPR is the Data Protection Impact Assessment (DPIA). A DPIA is a process that helps businesses identify and minimise the data protection risks of a project or processing activity.
DPIAs are mandatory for processing activities that are likely to result in a high risk to individuals’ rights and freedoms. This is such as large-scale processing of sensitive data or systematic monitoring of public areas.
🚩MANUAL CHECK – Identify any high-risk processing activities in your business and conduct DPIAs where necessary. The ICO provides a template and guidance on how to carry out DPIAs.
DATA SUBJECT RIGHTSThe GDPR grants individuals several rights over their personal data, which businesses must facilitate and respect. These include:
Businesses must have processes in place to handle requests from individuals exercising these rights, and must do so within the specified time limits (generally one month).
GDPR PRIVACY POLICY ESSENTIALSWhen crafting your GDPR-compliant privacy policy, it’s essential to use language that is easily understandable by your audience. Avoid legal jargon and complex terminology that may confuse or overwhelm readers. Instead, opt for plain, straightforward language that clearly conveys your data practices and policies.
Remember, the goal is to ensure that individuals can quickly grasp how their personal data is being collected, used, and protected. By using clear and concise language, you demonstrate transparency and build trust with your customers or users.
TIPS FOR WRITING CLEAR PRIVACY POLICIESTo comply with the GDPR, your privacy policy must specify what personal data you collect and the purposes for which it will be used. Be transparent about the types of data you gather, such as names, email addresses, IP addresses, or browsing behaviour.
Explain how this data is collected, whether through user input, cookies, or other tracking technologies. Additionally, disclose any third parties with whom the data may be shared, such as service providers or marketing partners.
🚩MANUAL CHECK – Ensure that your listed data collection practices align with your actual practices. Regularly audit your data collection to avoid discrepancies.
DATA RETENTION AND DELETIONIn your privacy policy, provide information on how long you retain personal data and the criteria used to determine retention periods. Under GDPR, you should only keep data for as long as necessary to fulfil the purposes for which it was collected.
Explain your data deletion practices and how individuals can request the erasure of their personal data. Be sure to outline any legal or operational reasons that may prevent immediate deletion.
DATA SUBJECT RIGHTSThe GDPR grants individuals specific rights regarding their personal data. Your privacy policy must inform users of these rights and provide clear instructions on how to exercise them. The key rights include:
🚩MANUAL CHECK – Ensure that your privacy policy includes all relevant data subject rights and that your procedures for handling these requests are up-to-date and efficient.
HANDLING DATA SUBJECT REQUESTSProvide a clear explanation of how individuals can submit requests related to their data rights. This may include a dedicated email address, an online form, or a postal address. Specify the information required to process the request and the timeline for your response.
Train your staff to recognise and handle data subject requests promptly and efficiently. Implement internal procedures to ensure that requests are forwarded to the appropriate team members. Ensure that responses are provided within the GDPR requisite timeframes.
Remember, a well-crafted and comprehensive privacy policy is not only a legal requirement under GDPR but also a powerful tool for building trust with your audience. By being transparent about your data practices and empowering individuals to exercise their rights, you demonstrate your commitment to data protection and privacy.
REGULAR REVIEW AND UPDATESAs your business evolves and data practices change, it’s crucial to keep your privacy policy up-to-date. Regularly review your policy to ensure that it accurately reflects your current data collection, usage, and sharing practices.
When making updates to your privacy policy, be sure to inform your users of the changes and obtain their consent if necessary. Provide a summary of the key modifications and the date on which the updated policy comes into effect.
🚩MANUAL CHECK – Set reminders to review your privacy policy periodically, at least annually or whenever significant changes to your data practices occur.
ACCESSIBILITY AND PROMINENCEYour GDPR privacy policy should be easily accessible to your users. Place a link to your policy in a prominent location on your website, such as the footer or main menu. Consider also providing a link during user registration or account creation processes.
Ensure that the policy is accessible across all devices, including desktop computers, tablets, and mobile phones. Use responsive design techniques to optimise the display and readability of your policy on different screen sizes.
ADDITIONAL RESOURCESFor more guidance on crafting GDPR-compliant privacy policies, consider the following resources:
Remember, while templates and guides can provide a starting point, it’s essential to tailor your privacy policy to your specific business practices and data processing activities. Consult with legal professionals to ensure that your policy fully complies with GDPR requirements.
GDPR CONSENT MANAGEMENT BEST PRACTICESObtaining valid consent is a cornerstone of GDPR compliance. Organisations must ensure that individuals freely give specific, informed, and unambiguous consent for the processing of their personal data. “Consent management is not just about ticking a box. It’s about building trust with your customers and giving them control over their data”.
OPT-IN CONSENTUnder GDPR, consent must be actively given by the individual. This means no pre-ticked boxes or implied consent. Users should take a clear, affirmative action to signify their agreement, such as clicking an unticked box or toggling a switch.
Recital 32 of the GDPR states: “Silence, pre-ticked boxes or inactivity should not therefore constitute consent”. Making consent opt-in rather than opt-out is critical for ensuring that users are making informed choices about their privacy”.
🚩MANUAL CHECK – Consider adding a screenshot or GIF demonstrating proper opt-in consent UI/UX.
GRANULAR CONTROLGDPR requires that consent is given for specific purposes. This means organisations should provide granular options for users to consent to different types of processing separately. For example, a user might consent to receive a newsletter but not to have their data shared with third parties.
Granular consent puts users in control, as they can pick and choose which data uses they are comfortable with. As the UK’s Information Commissioner’s Office (ICO) advises, “Consent requests must be prominent, unbundled from other terms and conditions, concise and easy to understand, and user-friendly”.
WITHDRAWING CONSENTJust as important as obtaining consent is the ability for users to easily withdraw it. The GDPR states that it must be as easy to withdraw consent as it was to give it. Provide clear information on how users can revoke their consent, such as through account settings or by contacting your privacy team.
Max Schrems, a renowned Austrian privacy activist, notes, “The right to withdraw consent at any time is a key element of the GDPR. It ensures that users remain in control of their data and can change their minds about how it’s used”.
RECORD-KEEPINGOrganisations must keep records of when and how consent was obtained from individuals. This includes information like what the user was told, when they consented, and how they consented (e.g., a click, or a form submission). Maintain these records to demonstrate compliance in case of an audit or investigation.
🚩MANUAL CHECK – Provide examples of consent management platforms or tools that can help with record-keeping, such as OneTrust, TrustArc, or Cookiebot.
Regularly review your consent records to ensure they are up-to-date. If you make significant changes to your data processing or if a long time has passed, consider refreshing consent by re-engaging with users.
As John Edwards, the UK Information Commissioner, advises, “Consent is not a one-off compliance box to tick and file away. It’s a dynamic, ongoing and actively managed choice, and there’s no limit on how often the customer can change their mind”.
By following these consent management best practices – opt-in consent, granular control, and diligent record-keeping – you can build trust with your users and ensure your organisation is meeting its GDPR obligations. In the next section, we’ll explore how GDPR applies to businesses outside the EU and the UK, particularly those in the United States.
DOES GDPR APPLY TO US BUSINESSES?The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect in the European Union (EU) on 25th May 2018. While it is an EU and UK regulation, its scope extends far beyond the borders of the EU, affecting businesses worldwide, including those in the United States.
EXTRATERRITORIAL SCOPE OF GDPROne of the most significant aspects of GDPR is its extraterritorial scope. Article 3 of the GDPR states that the regulation applies to the processing of personal data of individuals in the EU or UK by a controller or processor, regardless of whether the processing takes place in the EU or UK or not. This means that even if a US company has no physical presence in the EU, it must still comply with GDPR if it processes the personal data of EU citizens.
OFFERING GOODS OR SERVICES TO EU CITIZENSA US company is subject to GDPR if it offers goods or services to individuals in the EU, even if no payment is required. This includes:
GDPR also applies to US companies that monitor the behaviour of individuals in the EU. This includes tracking online activities through cookies, web analytics, or other means. For example, if a US website uses Google Analytics to track the behaviour of EU and UK visitors, it is in scope of the GDPR.
CONSEQUENCES OF NON-COMPLIANCEFailing to comply with GDPR can result in severe consequences for US businesses. The regulation allows for fines of up to £20 million or 4% of a company’s global annual revenue, whichever is higher. In addition to financial penalties, non-compliance can lead to legal action, reputational damage, and loss of customer trust.
NOTABLE GDPR FINESTo avoid these consequences, all businesses must take steps to ensure GDPR compliance when dealing with EU and UK citizens’ personal data. This includes implementing appropriate technical and organisational measures to protect data, obtaining valid consent, and providing individuals with their rights under GDPR, such as the right to access, rectify, and erase their personal data.
PROTECTING YOUR BUSINESS AND CUSTOMER DATA IN 2024GDPR compliance is essential for any business handling the personal data of EU and UK citizens. By following the checklist outlined in this article, you can ensure your company meets the strict requirements set forth by the regulation.
The key to GDPR compliance is understanding the principles behind the law and implementing appropriate measures to protect personal data. This includes conducting data audits, updating privacy policies, implementing security measures, and establishing data breach response procedures.
IS YOUR BUSINESS READY FOR GDPR?Take a moment to assess your current data protection practices. Have you obtained explicit consent from individuals before collecting their data? Do you have a plan in place to respond to data subject rights requests? Are you confident in your ability to detect and report data breaches within the required timeframe?
If you answered “no” to any of these questions, it’s time to take action. Start by reviewing your data collection and processing practices and make necessary changes to align with GDPR requirements. Appoint a Data Protection Officer if required and train your employees on their roles and responsibilities under the regulation.
Remember, GDPR compliance is not a one-time event, but an ongoing process. By staying vigilant and proactive in your data protection efforts, you can build trust with your customers and avoid costly penalties for non-compliance.
If you need help, call us today on 03333 22 1011 or email us at [email protected].
Fortis DPC is a specilaist Data Protection practice that helps SME and larger businesses too as well as charities, churches and schools. We have a 'keep it simple' ethos that helps you understamd…
Post articles and opinions on Professionals UK
to attract new clients and referrals. Feature in newsletters.
Join for free today and upload your articles for new contacts to read and enquire further.