Delve Into GDPR - Questions & Answers

Interview with the GDPR Advisory Board – a team of GDPR experts providing straightforward advice and help for those with queries about this new legislation. For more details visit www.gdpr-board.co.uk
 
How will GDPR effect data that businesses keep on employees? 
Answer provided by Piers Clayden, founder of data privacy legal specialists, Clayden Law and a member of the GDPR Advisory Board 
“The GDPR will put greater obligations on employers on how they use their employees’ personal data and how they look after it. 
Employers will have a greater obligation to be transparent about how they use their employees’ personal data. They will be required to issue a new “information notice” to their employees which will need to detail, amongst other things, what kind of personal data they hold, what legal grounds do they use it for and informing employees about their new enhanced rights under the GDPR. 
These new rights include the “erasure” right (right to be forgotten), amended subject access rights and the right to appeal any decision based on automated decision-making.
Employers will also have a greater obligation to be accountable about how they use personal data, and be able to demonstrate their compliance – in short this means a much greater record-keeping obligation and ensuring that staff are properly trained in their responsibilities under the GDPR.” 
 
Do you expect most businesses to be compliant in time for implementation or is there going to be a problem? 
Answer provided by Piers Clayden, legal expert at the GDPR Advisory Board
“Because of the lack of clarity in some of the drafting of the GDPR, and the slow release by the regulators of any useful guidance, it is going to be very difficult for businesses of any great complexity to say they are 100% GDPR compliant by 25 May 2018. But it is important that they nevertheless try to move towards compliance as quickly as possible – we suggest taking a risk-based approach and prioritising those areas where the business faces the greatest exposure or liability.”
 
What are the top 5 things to get right under GDPR?
Answer provided by Piers Clayden, legal expert at the GDPR Advisory Board
• demonstrating that they are taking data protection seriously – up-to-date policies, record keeping and staff training are all important elements of this
• ensuring that the public-facing information notice reflects the reality of how the business actually does use and treat personal data behind the scenes
• ensuring that the business has proper organisational and technical measures and policies in place to keep personal data safe and secure – having a robust information security policy which is actually adhered to throughout the business is part of this
• making sure that if the business were to suffer a security breach (ie. in short where personal data was accessed outside of the organisation without authorisation) you would be able report this to the regulator (the Information Commissioner’s Office) within 72 hours of becoming aware of this breach
• making sure that, where personal data is processed on your behalf by an external organisation, you have contracts in place that meet the requirements of the GDPR
Failure to comply with the GDPR could expose the business to fines (potentially up to 4% of annual turnover or €20m, whichever is higher), claims for damages from individuals, but perhaps more damagingly, loss of reputation
 
How will GDPR effect all different types of marketing, such as email marketing, loyalty cards/schemes?
Answer provided by CIM (Chartered Institute of Marketing), who has worked in association with Me Learning to launch a tailored GDPR online course for marketers – GDPR for the Marketer. More details can be found at www.melearning.co.uk/gdpr . Nick Richards, CEO at Me Learning is a member of the GDPR Advisory Board 
“GDPR has an impact on a wide range of marketing activities including how data is used, how customers are contacted and how data is held – which in turn affects email marketing, loyalty schemes and general marketing activities. With potential fines for non-compliance amounting to €20 million (or 4% of a business’s global annual turnover), GDPR needs to be taken seriously and embraced by all organisations quickly and with diligence. It’s not all doom and gloom, marketers in particular should see the positive side of the new legislation, which provides a once-in-a-generation opportunity to wipe the slate clean and radically overhaul the way customer data is collected and used.
 
Now is the ideal time for marketers to persuade their organisation’s financial team to invest in new data analytics tools – perhaps even those with predictive analysis and artificial intelligence (AI). By populating these tools with only the most important, useful and legally compliant data, organisations will be able to operate in a far smarter manner – securing higher response rates for email marketing and driving closer relationships with customers in loyalty schemes.
 
Data rationalisation should mean an end to customers getting multiple email mailshots because they appear more than once on a database (or are duplicated across legacy databases). Furthermore, having a single, consolidated view of the customer should also facilitate more informed responses when that customer engages with a call centre or other service point.
 
It’s worth remembering when looking to deploy an email marketing campaign that after May businesses will no longer be able to include a pre-ticked box, which the customer must untick in order to opt out of consent. Instead, the customer must actively choose to opt in, giving their consent freely and of their own accord, without coercion, undue incentives or penalties. As such, gaining this GDPR-compliant consent should be among your organisation’s top priorities in the run-up to the legislation’s launch.
 
Why is training relevant?
Answer provided by Nick Richards, training expert for the GDPR Advisory Board and CEO of Me Learning
Training is important when it comes to GDPR. In many cases GDPR requires a cultural shift in organisations that ensures personal data is handled appropriately – and this just as important for the marketing team as it is the receptionist. Training enables this transition to take place across the company – and if you are questioned over GDPR compliance, prove that training has taken place is a very good step to show intent for compliance and might help avoid unwanted fines. 
 
What training should businesses consider?
There are many classroom courses available for GDPR but these can be costly and limiting. E-learning provides a cost effective solution to train a large number of the workforce in a consistent manner (good for new starters) without taking employees out of the office to do so. Me Learning has teamed up with legal experts at Clayden Law to produce a range of easy-to-understand and legally compliant GDPR e-learning. To find out more visit www.melearning.co.uk
 

For more details visit www.gdpr-board.co.uk

You Might Also Read: 

Cyber Threats Will Grow With GDPR:

« Cyber Threats Will Grow With GDPR
Police Prepare for Cyber Attacks »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

See how to use next-generation firewalls (NGFWs) and how they boost your security posture.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

HireVergence

HireVergence

HireVergence is a full service IT staffing and recruiting firm with a focus on cyber and information security.

SecureBrain

SecureBrain

SecureBrain software and services help protect against Japanese-specific cybercrime and global internet security threats such as online fraud, phishing, drive-by downloads and malware attacks.

Excellium Services

Excellium Services

Excellium’s Professional Services team combines expertise and experience that complements your in-house security resources.

BA-CSIRT

BA-CSIRT

BA-CSIRT is a center which is dedicated to assist and raise awareness among citizens and the Government of the City of Buenos Aires in everything related to information security.

Secure Soft

Secure Soft

Secure Soft are experts in Computer and Information Security with a presence in Peru, Colombia and Ecuador.

KOVRR

KOVRR

Kovrr financially quantifies cyber risk on demand. Our technology enables decision makers to seamlessly drive actionable cyber risk management decisions.

Blockchain Firm

Blockchain Firm

Blockchain Firm is a leading Blockchain based software solutions and service provider with our roots of expertise running deep into the technology.

UK Research & Innovation (UKRI)

UK Research & Innovation (UKRI)

UKRI works in partnership with universities, research organisations, businesses, charities, and government to create the best possible environment for research and innovation to flourish.

Hyperwise Ventures

Hyperwise Ventures

Hyperwise Ventures lead seed investments in startups in the cyber security and enterprise software spaces.

Rostelecom

Rostelecom

Rostelecom is Russia’s largest integrated provider of digital services and solutions, covering all market segments including consumer, governmental and private organizations.

Epiphany Systems

Epiphany Systems

Epiphany enhances your defensive security controls by providing you with an offensive perspective. We expose the most likely attack paths to your most critical IT assets and users.

Stripe OLT

Stripe OLT

At Stripe OLT, we provide complete business technology solutions - Our team has an unrivalled reputation as a Microsoft Gold Partner, specialising in secure, cloud-first technology.

Arcserve

Arcserve

Defend your data with Arcserve all-in-one data protection and management solutions designed to be the right fit for your business, regardless of size or complexity.

Ruptura InfoSecurity

Ruptura InfoSecurity

Ruptura InfoSecurity provide CREST Accredited Penetration Testing & Offensive Security Services. We secure your critical assets through targeted and research driven penetration testing.

ID R&D

ID R&D

ID R&D is an award-winning provider of AI-based facial liveness, document liveness, and voice biometrics.

CloudGuard

CloudGuard

CloudGuard is an AI-driven XDR platform that helps organisations to proactively detect and automatically remediate threats in real-time.