,

GDPR – What should small businesses actually lay awake worrying about?

GDPR compliant

I won’t bore you with the usual General Data Protection Regulation (GDPR)lecture; you’ve probably heard that presentation at least a dozen times by now, complete with its tales of draconian fines,  devious small print and costly compliance.

Hence, such presentations tend to be ‘top-down’, applying GDPR rules to large companies and multinationals, rather than ‘bottom-up’, looking at the issues from the viewpoint of sole traders and SMEs.

At Thursday’s BLT meeting, David Banes of Cleartext Systems presented part of his practical GDPR Awareness Course.

What follows is my summary/interpretation of David’s presentation.

 

3 things every small business owner should do ahead of 26-May

Forget the 6 GDPR principles…well, don’t forget them, but let’s concentrate instead on the minimum that an SME should be doing ahead of 26-May.

1. Register under the Data Protection Act

“The Data Protection Act 1998 requires every data controller (e.g. organisation, sole trader) who is processing personal information to register with the ICO, unless they are exempt.”

[for the definition of ‘controller’ – see point 5 below]
  • This is compulsory (I wasn’t aware!)
  • It costs £35 pa (unless you’re a large company, >£25m turnover, in which case it’s £500) https://ico.org.uk/for-organisations/register/
  • If you’re a sole trader, you’re the data controller!
  • Register online https://ico.org.uk/for-organisations/register/

 

  1. You only need to clean up ‘dirty’ lists

  • If your mailing list is all through your own contacts, i.e. none of which were purchased from a 3rd party, and they provided ‘informed consent’ the first time round, then you don’t have to ask customers to opt-in.
  • Many larger organisations have, over the years, purchased mailing lists (bad) in addition to their own organic (good) contacts, and hence have had to email their entire database to ask for consent.

3. Beware special category data

  • If you are an SME but hold what is referred to as ‘special category data’ then you will have to take extra measures, as this data is considered more sensitive requiring special protection.
  • The ICO lists 10 types of special category data including race, politics, sexual orientation – see ICO for full information.

Two Optional Extras for ‘more than minimum’ GDPR compliance

If you’re bigger than a sole trader or hold/process more complex data than a simple Mailchimp database, then you should consider:

4. Registering for the Cyber Essentials Scheme

This isn’t essential for GDPR, but as this scheme introduces best practise for data security (for the prevention of common cyber-attacks) it helps to promote GDPR compliance.

https://www.cyberessentials.ncsc.gov.uk

5. Writing a data protection policy

Under Article 24 of the GDPR, the Regulation states that

“[w]here proportionate in relation to processing activities, […] measures […] shall include the implementation of appropriate data protection policies by the controller.”

For SMEs processing substantial amounts of personal data or with more staff doing so, a data protection policy will set out clear procedures for compliance with GDPR requirements.

How to write a data protection policy: https://www.itgovernance.co.uk/blog/how-to-write-a-gdpr-data-protection-policy/

 

Let’s remind ourselves of the 3 key GDPR issues

What is legitimate interest?

Legitimate interest introduces an element of context as to what is fair and reasonable for GDPR purposes.

The 3 elements underpinning legitimate interest are as follows:

  • Identification– can include commercial or individual interests or broader societal benefits.
  • Necessity if you can achieve the same result in another less intrusive way, it’s not a legitimate interest.
  • Reasonableness you must balance your interests against those of the individual; e.g. if they would not reasonably expect their information to be processed, their personal interests will override your business interests.

So if somebody gives you their business card or connects with you on LinkedIn, this qualifies as a legitimate interest.

What is the difference between a Controller and a Processor?

  • If you’re a sole trader, you are the ‘Controller’ (by default), otherwise this will be the Data Protection Officer (> 250 employees).
  • The IT systems you use which manage external data are referred to as ‘Processors’; e.g. CRM system, Mailchimp…etc.

What happens in practise if there is a GDPR breach?

David Banes tried this in respect of a UK nationwide mortgage broker which had inaccurately published his personal financial data.

  • Complained to the company in question
  • Filled out an online form to report the breach https://ico.org.uk/for-organisations/report-a-breach/
  • Received a reply from the ICO within 3 weeks, stating that it would be asking the firm to clarify its data security procedures

So, as a point of context in this GDPR debate, even despite a clear data breach and with previous complaints, no penal action was taken against this particular firm. Furthermore, when GDPR comes into force, one would expect the ICO’s workload to increase and an element of priority to be introduced.

 

Hence, the worst-case scenario for an average SME would probably be a request to provide more information to the ICO and to evidence that the appropriate safeguards had been put in place (as described above – Cyber Essentials Scheme, Data Protection Registration…etc). No draconian action is likely to be applied…at least not on the first offence!

 

 

 

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.