GDPR – Is Your Organisation Ready?
Category: General
Published: 28/08/2017
The GDPR Deadline is Coming...
On 25th May 2018 the EU General Data Protection Act (GDPR) comes into force and it will apply to all companies and organisations that collects personal data relating to any EU citizen. Personal data means any information that relates to a person, whether it is private data, professional data or data relating to their public life. This means any form of data such as a person’s name, address, photographs, bank account details, email addresses, social media website posts, medical data and it also includes information such as mobile phone numbers and computer IP addresses.
Why is GDPR coming into force?
At the moment, the UK relies on exercising the Data Protection Act of 1998, following the 1995 EU Data Protection Directive. However, with cybercrime very much on the rise and with more and more personal business and social interaction taking place online, the data protection regulations of over two decades ago need to be updated. GDPR introduces new data protection standards to combat rising cybercrime and it introduces far more punitive fines for companies and organisations who do not take new data protection rules seriously. GDPR also unifies the data protection rules across the EU (including the UK, after Brexit) and also gives individuals more control over where and how their personal data is electronically stored. Overall it provides an upgraded EU wide standard for data protection.
How does GDPR affect your company and its website?
Almost all websites these days have some form of personal data collection element built into them, this may be a simple sales enquiry form, or a more sophisticated eCommerce section enabling customers to place orders online, collecting delivery addresses and processing payments by credit or debit cards. The GDPR compliance rules mean that every company and organisation will need to appoint a Data Protection Officer (some smaller companies may be exempt from having a dedicated DPO ) who will have the responsibility to ensure GDPR compliance. This includes keeping personal customer data in secure data storage whether on premises, via a third party service provider or in the cloud. This would include even simple names and addresses collected online and any other personal details collected via your website (or by any other commercial means).
The DPO must be able to ensure their organisation is compliant under GDPR compliance rules and should take steps to understand how to protect personal data against cybercrime. This means secure storage of collected data against the event of a data hack. It not only means protecting servers with secure firewalls but also extends to company’s own staff moving to highly secure IT login passwords. With 65% of data breaches being password related it is a big issue. Most IT users use weak, easily hacked and badly stored passwords. Along with secure server protection, secure passwords are a key area relating to GDPR compliance.
What are the fines for a GDPR breach?
If a company can show they have taken all reasonable steps to comply with GDPR then the GDPR regulators would be far more lenient than on a company that had not taken appropriate steps to protect against a cyber-attack. If found negligent, the fines are £20Million Euros or 4% of the Group Turnover, whichever is the greater!
This massive increase in potential fines is a huge driver for companies to ensure they comply. The well publicised data breach suffered by Talk Talk in 2016 brought them a record fine (at the time) of £400,000. Under the new GDPR rules that fine would total £59Million.
The fact is that the number of cybercrime incidences is rising and as more and more data is held by more and more companies by electronic means, the new GDPR rules go some way to encourage companies to take data protection more seriously than they have been to date.
Are You Ready?
If you're unsure if your current method of data collection, storage and use will be in breach of the new laws, Big Red can arrange a full and comprehensive data audit on your behalf. For further information, please don't hesitate to contact us.