Data protection and GDPR: 7 business changes you really need to make

1. Review…

Review what personal data you collect, where it is held, who you share it with, and when it is deleted.

2. Develop…

Develop a data strategy.  Consider what data you really need to hold and how long you need it for.  Conduct a risk-assessment on the risks of data breach and what you can do to minimise it.  Develop a plan as to how you will deal with a data breach, and how you will assess whether a breach needs to be reported to the Information Commissioner’s Office (ICO).

3. Consider…

Consider whether you need to appoint a Data Protection Officer.  Even if you are not required to, assess whether it would be beneficial to give nominated individuals responsibility for data compliance issues.

4. Update…

Update your privacy policy to comply with the additional information requirements of the GDPR, and make sure it is available on your website.

5. Check…

Check how you obtain consent and update your T&Cs.  Most businesses currently collect marketing data from any individual they deal with who fails to “opt-out”.  Going forward consent must be “explicit, freely given and informed”.  Your T&Cs should be updated to provide that individuals must opt-in to be added to your database.

6. Cleanse…

Cleanse your database.  If you have relied on opt-out or “passive” consent to contact people in the past (e.g. for marketing purposes), you need to get fresh consent from those in your existing database.  Do this sooner rather than later and beat the rush.

7. Educate and Train…

Educate and train your staff on the GDPR. Make sure your staff know what your internal policies are, who to go to with a data problem, and how they need to deal with requests to be forgotten and subject access requests.
For more information on data protection or the GDPR, please contact Stephen Thompson on 029 2082 9100 or come along to Stephen’s session at CHC’s One Big Housing Conference next month. Book your place on our website: https://chcymru.org.uk/en/events/view/2017-one-big-housing-conference

Stephen Thompson
– Partner, Darwin Gray LLP