GDPR - an evolution, not a revolution
GDPR - an evolution, not a revolution
A recent Data IQ research report in association with Experian revealed that 7 out of 10 organisations are either currently reviewing their privacy policies or have already done so. But in case you’ve been in a time warp, or just so busy you haven’t had time to get to grips with preparing for GDPR in May this year, we’ve put together a handy bite-size guide, with the key points you need to know about the new legal framework.
We’re going to start by saying DON’T PANIC!
GDPR: Basics
GDPR as you will know, is the new data protection bill coming to force in the UK on 25th May 2018. All organisations handling personal data will need to comply with the GDPR and even Brexit won’t impact on the adoption of the new regulation.
As the growing digital economy continues to impact on how businesses operate, there are increasing concerns about current data protection laws, rights and privacy for both consumers and companies. The result of this is that the latest GDPR changes are set to lay the foundations for the long-term future of data handling in the UK.
Elizabeth Denham, the UK's information commissioner responsible for data protection enforcement, emphasises the unnecessary "scaremongering" taking place relating to the possible repercussions for companies. She stated “The GDPR is a step change for data protection…It’s still an evolution, not a revolution".
So, what do we need to know?
Under the GDPR, data collection must exist for a specific purpose, and can only occur when:
1. There is consent - this must be freely given, specific, informed and unambiguous;
2. It is legitimate - the data is required to fulfil contracts or activity;
3. It is a Legal requirement - when the data is needed to comply with certain legislation

Personal data
Similar to the DPA (Data Protection Act), the GDPR covers ‘personal data’. The definition is more comprehensive under the GDPR however. For example, it states that an online identifier i.e. an IP address- can be considered as personal data.
This typically includes:
● Basic identity information such as name, address and ID numbers (although not limited to name, address or date of birth)
● Web data such as location, IP address and cookie data
Marketing lists, contact details and HR records largely consist of this type of information and it applies to both automated information and manual filing systems where data is made available based on specific criteria. The GDPR definition is wider than the DPA’s definition, so be careful, as a chronologically-ordered set of manual data that contains personal information may fall under this definition.
Note: Pseudonymised data i.e. information that may be key-coded could also be relevant, depending on how difficult it is to relate the pseudonym to a particular person.
Sensitive personal data
There are minor changes between the DPA and GDPR in this area. Under the GDPR, for example, these special sensitive personal data categories include genetic data and biometric data, where companies use this to identify a specific individual.
Personal data exclusions exist in relation to specifying criminal convictions and offences. However, there are a variety of measures that relate to its processing (Article 10). This sensitive category also covers health, political opinions and financial information.
Under the GDPR, full restrictions apply to several categories of data. As a result, in gathering the below data, companies must receive explicit consent. This includes data relating to:
● Racial or ethnic origin
● Political opinions
● Religious or philosophical beliefs
● Trade union membership

Processor and controller roles
The GDPR will apply to both ‘controllers’ and ‘processors’. The controller handles the ‘hows’ and ‘whys’ of data processing, while the processor then acts on the controller’s behalf.
The GDPR places specific legal obligations on both. A processor, for example, must keep records of personal data and activities. Following its introduction, you will have greater liability if a breach occurs. This is a new requirement. As a controller, you will also have significantly more obligations on you to confirm and clarify that you, as a processor, comply with the new GDPR.
Next steps
The ICO has produced a 12-step plan to inform businesses about the changes under the new regulation and best practices to meet compliance standards.
We’ve simplified for you, but check the ICO website for more detail if needed.
1. Inform main decision makers
Awareness is key. Start by considering or looking at your organisation’s risk register, to consider resource implications.
2. Assess all information
Run an audit of the personal data that you store. Consider and record where it came from and who has (or has had) access to it. While this may be a big shift initially, it will help keep data organised and contribute positively to effective marketing strategies over the long-term.
3. Privacy information
Look at your current privacy notices and make updates where necessary so that these comply with the new legislation; as along with providing specific information such as your identity and how you propose to use their details, additional measures will come into play relating to explaining the lawful basis for processing data, data retention periods and individuals’ right to privacy.
4. Individuals’ rights
Under the GDPR, individuals have clear rights. These are:
● the right to be informed;
● the right of access;
● the right to rectification;
● the right to erasure;
● the right to restrict processing;
● the right to data portability;
● the right to object; and
● the right not to be subject to automated decision-making including profiling.
These are similar to those that already exist under the DPA, so the transition should be swift and simple. However, the right of data portability, right to erasure and right to cease profiling are all new.
5. Subject access requests
You must be aware of, and prepare for questions and requests relating to how you will handle customer and consumer data. This has changed somewhat from DPA in that the time to comply has reduced from 40 days to a month. And in the majority of cases, it will now not be possible to charge for complying with a request.
6. Lawful basis for processing personal data
Identify. Document. Update. The ICO recommends this process when it comes to managing the lawful basis for your processing activity. At present, there are no practical implications relating to how we, as businesses, process personal data, but this will change following the introduction of the GDPR.
7. Consent
Businesses must review current processes on how consent is gathered, recorded and maintained. Update existing consents now if they do not meet this standard. Remember, consent must be freely given, specific, informed and unambiguous. It cannot be inferred from silence, pre-ticked boxes or inactivity. This means recipients must manually accept your offer to communicate with them. Opt-in must be separate from other terms and conditions and it must be simple for people to withdraw their consent.
8. Children
The GDPR will introduce special protection for children’s personal data, especially in reference to commercial internet services such as social media websites. If applicable, think about how you can verify individuals’ ages and obtain consent from parents or guardians.
9. Data Breaches
You will need to have suitable processes in place to detect, report and investigate a personal data breach. Under the new rules, businesses must report a breach to the ICO. These largely relate to when these risks jeopardise an individual's rights or freedoms.
10. Data Protection
Privacy by design will become an express legal requirement. Using the term ‘data protection by design and by default’, ‘Data Protection Impact Assessments’ (DPIAs) will be obligatory in some situations, particularly where activities are likely to lead to a high risk for individuals.
11. Data Protection Officers
Some businesses are formally required to take on a Data Protection Officer as those with more than 250 employees must have information on data collection and processing, its retention period and the technical security measures that are in place.
Companies need to have clear and compliant processes that gather, handle and store data in an appropriate, secure and timely fashion.
12. International
If your business operates in more than one EU member state, it must assign a lead data protection supervisory, i.e. the location where your central administration is, and document this information.
So, there you have it! Once broken down into the 12 steps you should be able to clearly see what you’ve already covered, and what still needs to be addressed.
The EU's GDPR website says the legislation aims to "harmonise" data privacy laws. Therefore, it may be best to interpret any work you need to do and changes you need to implement as short-term pain for long-term positive, accurate and protective gain.
Don’t forget, if you need a refresher, sign up for our CPD approved Data Protection online course now.




