Taking data protection seriously has always been important, but from the 25th May 2018 it’s going to be vital.
GDPR (General Data Protection Regulation) is a new EU-wide directive that comes into force on this date. Businesses large and small found to be not meeting the requirements could soon find themselves exposed to reputational risk and significant (potentially huge) fines. So, if you run a business or are self employed in the financial services sector, or you provide a service to a company that is, you need to put GDPR awareness and preparation at the top of your to-do list, because from the 26th of May this year, you must be able to demonstrate that good data protection is a fundamental part of your business’s policies and practices.
Here are some of the key things you need to consider:
You can’t afford to ignore it

Brexit doesn’t affect it

The definition of personal data is changing

Rules around ‘consent’ are getting tougher

1. Consent not being given by a pre-ticked opt-in box on your website
2. You must make it very easy and straightforward for people to withdraw consent
3. Use clear and plain language when explaining consent to users
4. If you already have consent from users, you’ll need to make sure it passes the above tests or it might be deemed invalid.
GDPR is all about strengthening the rights of the individual

1. The right to access – the right to request access to your personal data and to ask how your data is being used by the company. The company must provide a copy of the personal data, free of charge and in electronic format if requested
2. The right to be forgotten – the right to withdraw consent from a company to use their personal data and to have that data deleted
3. The right to data portability – the right to transfer personal data from one service provider to another. This must happen in a commonly used and machine-readable format
4. The right to be informed – the right to be informed before data is gathered. Consumers must opt in for their data to be gathered, and consent must be freely given rather than implied
5. The right to have information corrected – the right to have your data updated if it is out of date or incomplete or incorrect
6. The right to restrict processing – the right to request that your data is not used for processing. A record can remain in place, but not be used.
7. The right to object – this includes the right to stop the processing of your data for direct marketing. This right must be made clear to you at the start of any communication.
8. The right to be notified – the right to be notified of any data breach that compromises your personal data within 72 hours of the company first becoming aware of the breach.
GDPR, combined with the growth of cyber-attacks, makes digital security vital

How to find out more
The Information Commissioner’s Office (ICO) is the UK’s independent authority created to uphold information rights in the public interest, promoting openness by public bodies and data privacy by individuals. They have created a frequently updated guide to the GDPR for those who have day-to-day responsibility for data protection. It’s a useful resource for anyone wishing to learn more. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/
For GDPR compliance you will need to work with your own advisors.