Q&A: How will GDPR affect your business?

By Blue Wren Ltd

21 Aug 2017

GDPR, or the General Data Protection Regulation, is a modernisation of the existing 1998 Data Protection Act, and is set to roll out 25th May 2018.

Since 1998, the way data is shared and held has evolved. Internet use has rocketed and social media has changed the way personal data has been collected and even used.

With GDPR’s implementation just around the corner, we spoke to Dean Martin – data protection officer at Blue Wren – to ask just how GDPR will affect businesses, both locally and nationwide.

What is GDPR set to affect?

Everything and everyone.

The GDPR will affect all businesses, as well as providing extra protection for consumers. Nothing’s changed in the fact that businesses must continue to be ethical in the way they collect and process personal information, but the extent to which businesses control and document that data will be increasingly legislated and transparent.

In a nutshell, though, it applies to any personal data that can be considered a ‘personal identifier’.

What has changed?

The biggest change is around accountability. The new legislation creates an onus on companies to understand the risks that they create for others and, ultimately, mitigate those risks. Consumers will also have stronger rights to be informed about how organisations use their personal data.

With the consumer’s right to erasure, they can request that you delete them from your mailing lists and businesses need to comply with that. On the other hand, employee records may need to be kept for several years, as legally defined for tax purposes and so on.

In essence, businesses now need to define retention periods and stick to them, be it for the needs of the business or for legal reasons. For example, you can only keep CVs for recruiting a specific position… once that position is filled they must be destroyed, unless otherwise stated of course.

How would a business obtain GDPR compliance?

Whilst I’m sure most businesses are already committed to protecting customer information, there are more practices that will need to be put in place. Keeping more records, producing more documentation, essentially putting policies in place to demonstrate that your business is specifically focussed on compliance.

And while there is the more encompassing red-tape aspects of GDPR legislation, it’s also the simple things that are heavily affected. Things like leaving confidential or personally identifiable information lying around, like contact details jotted down on notepads or Post-it notes during a phone call. They’re completely against the general principles of GDPR.

What are the GDPR principles?

Well, there are seven, if you include the business’ accountability. And you can’t just follow some; you have to stringently adhere to all of them.

Listing them: starting with accountability, your business must be able to demonstrate that it is working in compliance with GDPR. Therefore, appropriate documentation must be kept, keeping track of any permissions you’ve been granted or refused.

Next is to be lawful, fair and transparent. So, any data you collect needs to be done fairly and for a legal purpose. You can’t just collect the data without expressing why, you need to be transparent about how it’s going to be used.

The third is that it’s limited for its purpose. Meaning, it can only be collected for a specific use. To give you a dubious example: if you were collecting CVs, say, you couldn’t then retarget those people with e-shots later down the line simply because they’ve ‘technically’ given you their email address.

Another principle is data minimisation. When you collect someone’s data, it needs to be done in a manner that isn’t excessive for its purpose. So, if you’re capturing e-mail addresses for future newsletters, you wouldn’t necessarily need to know their home address.

Next there’s data accuracy, which is self-explanatory, really. But all data that you hold must be kept up-to-date and accurate. Similarly, the sixth is data retention, which alludes to the fact that data shouldn’t be stored any longer than necessary.

Finally, and perhaps most importantly, there is integrity and confidentiality. All data that you keep must be kept safe and secure. No leaving computers unlocked or passwords scribbled down in the back of books…

In a nutshell, everything must be done in such a way that only those people who have the express permission to access the information, can. And when they do so, it must be utilised in a way that has previously been agreed upon.

So, is there any further important GDPR information that you’d like to mention?

Loads, but not for a quick Q and A! I’d suggest that everybody – employee, employer or consumer – check out the ICO (Information Commissioner’s Office) guidelines on their website (linked here). Ensuring you’re compliant with everything on there isn’t an option, it’s an absolute necessity for you, your business and your customer.

Latest news

1

EG On The Move completes Applegreen UK acquisition Zuber Issa

EG On The Move completes Applegreen UK acquisition

03 Feb 2025

2

CoolKit designated as Preferred Partner for MAN TGE Rupert Gatty, Andy Parker, Bodybuilder Manager, MAN Truck & Bus SE / Cameron Javed, Head of Fleet Sales, CoolKit

CoolKit designated as Preferred Partner for MAN TGE

03 Feb 2025

3

Multiversity compulsory purchase order confirmed in Blackpool Aerial photo of Multiversity in Blackpool

Multiversity compulsory purchase order confirmed in Blackpool

03 Feb 2025

4

JM Glendinning Lancashire boosts growth with two appointments Chris Newton and Rachael Hacking

JM Glendinning Lancashire boosts growth with two appointments

03 Feb 2025

5

Lancaster University green technology spin-out aims to boost biogas-bioenergy sector AdTech Optima

Lancaster University green technology spin-out aims to boost biogas-bioenergy sector

31 Jan 2025

Background image for hub sign up block

LBV Hub

Leverage Lancashire Business View platforms

Post your news
Post your events
Post your offers
Build your network
Improve your SEO
Gain coverage in the magazine
Sign-up
Events
Skills Bootcamp in Procurement - Cohort 3
Blue-Modern-Land-Travel-Youtube-Thumbnail-2-1024x576.png.png
LBV Hub Awards
14 Jan 2025 - 18 Mar 2025

Skills Bootcamp in Procurement - Cohort 3

Community & Business Partners CIC, Blackburn, BB2 3UA

09:30 - 13:00

February Preston Tech Connection Meet-Up: Tech & Our Planet
PRESTON TECH CONNECTION jan.ai.png.png
LBV Hub Networking
12 Feb 2025 - 12 Feb 2025

February Preston Tech Connection Meet-Up: Tech & Our Planet

Society1 Coworking Space, Preston, PR1 3LT

18:00 - 19:30

Police Apprenticeship event
Student Centre Autumn 2022.jpg.jpg
LBV Hub Social
12 Feb 2025 - 12 Jan 2025

Police Apprenticeship event

University of Central Lancashire, Foster Social Space , Preston , PR1 2HE

16:00 - 19:00

Amber River True Bearing Quarterly Investment Seminar
LBV Hub Seminars
13 Feb 2025

Amber River True Bearing Quarterly Investment Seminar

Mercure Blackburn Dunkenhalgh Hotel & Spa, Blackburn Rd, Clayton-le-Moors, Blackburn, Lancashire, BB5 5JP

16:00 - 18:00

The Business Network Central & East Lancashire
LBV Hub Networking
13 Feb 2025 - 13 Feb 2025

The Business Network Central & East Lancashire

Mytton Fold, Langho, BB6 8AB

11:30 - 14:15

Sub36 Networking - Behind the beans
Sub36 Social1200Atkinsons New
Networking
14 Feb 2025

Sub36 Networking - Behind the beans

Atkinsons Speciality Coffee, Lancaster, LA1 1 EX

09:00 - 11:30

National Apprenticeship Week 2025 Celebration - Business Breakfast Showcase
Student Centre Autumn 2022.jpg.jpg
LBV Hub Networking
14 Feb 2025 - 14 Jan 2025

National Apprenticeship Week 2025 Celebration - Business Breakfast Showcase

Media Factory , Preston, PR1 2HE

08:00 - 10:00

CMI Level 5 Management and Leadership Course
UCLanAerialCampus.jpg.jpg
LBV Hub Seminars
21 Feb 2025 - 21 Feb 2026

CMI Level 5 Management and Leadership Course

Preston Campus, Preston , PR1 2HE

09:00 - 17:00

CMI Level 5 Project Management Course
UCLanAerialCampus.jpg.jpg
LBV Hub Seminars
21 Feb 2025 - 21 Feb 2026

CMI Level 5 Project Management Course

Preston Campus, Preston, PR1 2HE

08:00 - 17:00

Preston Freelancer Meet-Up: February
Freelancer Meet-Up Feb.png.png
LBV Hub Networking
26 Feb 2025 - 26 Feb 2025

Preston Freelancer Meet-Up: February

Society1 Coworking Space, Preston, PR1 3LT

10:00 - 11:30

Employment Law, Tax and Payroll Update - East Lancashire
Employment updates - LinkedIn East Lancs-01.png.png
LBV Hub Seminars
26 Feb 2025 - 26 Feb 2025

Employment Law, Tax and Payroll Update - East Lancashire

Accrington Stanley Football Club, Accrington, BB5 5BX

08:00 - 10:00

Level 3 Emergency First Aid at Work Course - In Person
RKMS ACADEMY LOGO - BLACK AND ORANGE.png.png
LBV Hub Webinar
26 Feb 2025 - 26 Feb 2025

Level 3 Emergency First Aid at Work Course - In Person

RKMS Group , Blackpool, FY42DP

09:30 - 17:00

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more LBV120 Online Graphic 1
Subscribe now

Weekly news bulletin