Table of Contents
Introduction:
In 2018, most of our inboxes were flooded with emails about privacy policy changes from companies such as Facebook and Google. The GDPR or The General Data Protection Regulations had come into effect. This compliance if not adhered to now can draw steep fines from a business.
It seemed as though the GDPR was only applicable to large and multinational companies at the initial glimpse. However, that is a very common misconception, this regulation does affect small businesses vastly.
Irrespective of the size of a business, a company collects any sort of personal data about a citizen of the EU. Which could range from their email address to their medical records. Makes a company legally obligated to comply with the GDPR.
What is the GDPR:
The main objective of the GDPR is to assure that citizens of the EU get back control over their data. This regulation standardises data protection laws across the EU. This is done with the effort of ensuring that data laws are aligned with the changes in technology. The main aim of the GDPR is to:
- Ensure the privacy of an individual
- Ensure that they have more control over their data
- Deter businesses from collecting individual data sans permission or a legal purpose
- Penalise businesses that exploit personal data
Even if a business is located in the US without a location in the EU still falls under the ambit of the GDPR. So long as it has a web presence in the EU, collecting information via the internet. This regulation applies to any local content and marketing campaign, therefore if a US-based business offers a service or a product to an EU audience then it has to comply with the regulation.
The size of a business is not a matter of question, if in any way a business is collecting data from EU citizens it’s obligated legally to comply with the GDPR. Even a small business. However, there is a common misconception, an investigation found that 39% of the SMBs don’t know who the GDPR affects. About 1 in 10 are unaware of the rights that the GDPR gives to its consumers. There is a lack of awareness amongst SMB and therefore they have put themselves at risk.
As a business, they need to be aware of the rights an individual gets:
- They can confirm the personal data being stored about them
- Ask for details about how the data is being stored and its purpose
- Can ask for a copy of the data, free of charge
- Can stop them from sharing the data, can make that third parties also stop using the data and delete - this is known as the right to be forgotten
Three noteworthy pointers about the GDPR:
Although there was enough publicity about the GDPR, my companies remain unaware, non-compliant or have misunderstood the regulations, therefore the below-mentioned points are key for small businesses to remember:
- What does the GDPR mean for small businesses?
Companies that house more than 250 employees are liable to be GDPR compliant and need to appoint a data protection officer and an expert in data protection laws, However, companies with less than 250 employees are also required to follow the regulations if they process data that is personal or considered as sensitive data regularly.
Businesses that majorly are dependent on networking to expand may have to put in more work for themselves while taking on additional GDPR. It makes it illegal for companies to collect contact details from a business card or through LinkedIn and add it to their contact data without obtaining prior consent from the concerned person.
Small businesses may find it daunting to comply with the GDPR, however, they can do so by gaining knowledge of how their respective company collects data and lacunae for breaches. It is important to make a consent policy for acquiring personal data. It is important to offer an active opt-in choice.
- How to remain compliant?
If the regulations do not comply with it may lead to fines and penalties. Therefore, it is important to put in charge a data controller who can illustrate GDPR knowledge and processes for compliance. This process includes data protection policies, it is also important to understand how to comply with the GDPR code of conduct. The data controller must make sure that principles are followed through the whole data processing life span. Lawfulness, fairness, transparency, minimisation of data, storage limitation, data confidentiality and accuracy all need to be maintained. The appointed controller may be a company employee or a contractor.
- What can you do about the GDPR?
- If your business is new, ensure that data privacy policies are incorporated in your business plan - this would also be helpful for other regional and local regulations
- Know about the policies of the 3rd party applications and websites that you use - it is important to be aware of these use personal data and if they have a plan in place
- Ensure that your company remains compliant - While this is a huge task it is the most important. A business can always seek guidance from larger companies or seek inspiration from compliant businesses
- Ensure that your customer know how you protect data - protecting information may as well be accounted for as customer service, it is important for the customer to know how you implement transparent data policies and get ahead in the game much like larger companies.
Conclusion:
Many small businesses remain unaware of the GDPR in the US. Because it’s a European law. However, they must understand and become GDPR compliant if they process or store data of EU citizens. GDPR has altered the way businesses function, therefore businesses need to understand their data and safeguard the interests of their customers. The change of times has demanded more protection for consumer data increasing compliance requirements. Read more about other laws and acts that small businesses need to be aware of. We at security pilgrim are here to help you make your small business secure and compliant.
