A 7 Point GDPR Checklist to Ensure Your Business Remains Compliant

Introduction:

The General Data Protection Regulation (GDPR), came into effect in May 2018 and changed the way businesses handle their personal data. These new regulations assert extensive rights over individual personal data. The regulation has introduced stern rules over how businesses get, store and US data. 

Although this an European Union (EU) directive, it is being mirrored globally and affects any business that in any form uses data of EU citizens. GDPR follows two key principles that need to be adhered to by businesses:

  1. Businesses need to have appropriate legal grounds for acquiring and processing data, which needs to be done transparently
  2. The information can only be collected for a specific purpose and can merely be used for that specific purpose. 

Almost all businesses process hold personal information about their customers, be it their email, postal address or even their personal finance or health data - it’s quintessential for the business to become GDPR compliant, irrespective of company size. If your business is not compliant you can attract a fine of 4% of your annual turnover or a fine of €20 million (about $23 million). Therefore, it is better to ensure GDPR compliance, below is a checklist to ease your journey for the same.

A Small Business GDPR Checklist:

1. Recognise your GDPR Responsibilities:

The GDPR brings in two new terms that may be used to describe an organisation, person or company that collects and processes data. Both these processors, as well as the controllers, need to become compliant with the regulations.

  • The Data Controller: This is a company, business or person that gauges the reason and the process of the data that is being collected. They must be fully compliant with the regulations, which includes ensuring:
    • Data transparency
    • Data confidentiality
    • Accuracy of data

They also have the responsibility of making sure that in case a data breach does occur it is conveyed to the Information Commissioner’s Office (ICO).

  • The Data Processor: This company or person on behalf of the data controller processes personal data. This is almost anyone who has access to personal information and may use it to send even marketing emails. They too must ensure that they are compliant with the regulations while ensuring the security of the data.

2. Recognise your Data:

It is important to audit your data on customers, clients, suppliers and even employees both in present and of the past.  Data may include many aspects such as names, financial data, address, email id, birth dates etc. Ensure that you only hold as much data as is required for GDPR needs a business to only store necessary data, stockpiling of data may be frowned upon. 

The regulation also categorizes political affiliation, religious belief, sexual orientation data etc.. under special categories of data. This type of data can be used to discriminate against particular individuals therefore explicit consent is required.

3. Review your Consent Policy:

Before a small business acquires and stores personal information, clear, explicit consent must be given by the concerned individual. This entails a clear explanation about what data is being collected and why and how it will be used. It is necessary for the said individual to actively consent to this. To remain GDPR compliant it is necessary to show that the business has obtained consent for the stored data. If consent does not exist then it attracts a fine. It is also important for the business to provide easy ways for the concerned individual to provide consent.

4. Appoint a Data Protection Officer and Train Staff on Data Handling:

While businesses that have more than 250 employees are required to hire a data protection officer, however, a small business that has less than 250 employees can be exempted from this regulation unless they process special categories of data at high volumes or if the business intends to conduct large scale data processing.

Data breaches that occur unknowingly are not exempt from the law, therefore, it is important to train your staff. If any data loss occurs, due to losing a hard drive or a memory stick that contains the personal data of a client or customer, heavy fines can be attracted. It is necessary to train staff on compliance with the policy and data handling. Any data breach must be reported to the ICO within 72 hours. This needs to be detailed and must include plans to contain the breach.

5. Dispose of Old Data:

Many companies and businesses have a database of customer information. According to this regulation, it requires a business to ensure that the customers are re-consented. That means if your company holds data of customers before May 25, 2018, then it is required to seek their permission to continue using old data. If you don’t obtain consent then you simply have to delete data to remain compliant, when the data is no longer in use it must be deleted.

6. Make Sure that your Suppliers Compliant:

Small businesses are heavily reliant on a string of contractors or suppliers. Therefore even if your own business is 100% compliant it is very important to make sure your suppliers are also compliant. For a business that works with a supplier that is also GDPR compliant it could reduce the chances of being impacted by a data breach. It also reduces the chances of being fined. As a business, you could ask the supplier to confirm on a form their compliance and the measures they’ve undertaken.

7. Create a Subject Access Request (SAR)Plan:

As per the regulation, any EU citizen has the right to access the data that is stored by your business. This is known as a Subject Access Request (SAR). They also have the right to rectify any incorrectly stored data or can request you to even delete the data. Dealing with this aspect of the regulation can be time-consuming, there even exists a timeline of 30 days to complete a SAR, therefore it would be easier to have a plan of action to deal with any such requests raised from customers, suppliers etc.

Conclusion:

There is a common misconception that the GDPR is concerned only as an IT issue. However, it is a regulation that has implications on the entire company even how sales and marketing activities are conducted. This may seem a little much for small business, however, the key remains in understanding various areas of concern. This guide hopes to make your GDPR journey a bit smooth, for more information on GDPR read here. As businesses grow it is important to be mindful of all the regulations that are in place to ensure the safety of the business and the people associated with it. We at Security Pilgrim are here to help your business transition into a secure and compliant business.

Please follow and like us:

Leave a Comment

Your email address will not be published. Required fields are marked *

RSS
Follow by Email
Facebook
Facebook
fb-share-icon
Twitter
Visit Us
Follow Me
Tweet
YouTube
YouTube
LinkedIn
LinkedIn
Share
WhatsApp