GDPR21 Mar 2018 09:13
As I indicated earlier this doesn't just apply to our company. It applies countrywide. Our companies take on it. F.I.O.
Dear all,
On 25th May 2018, the new General Data Protection Regulations (GDPR) will replace the current Data Protection Act 1998 for the modern digital age. Many of the GDPR�s concepts are much the same but with some new elements and enhancements, which primarily strengthen individuals� rights and ensure stronger enforcement of the rules.
We take our data protection obligations in relation to the security of personal data with which we are entrusted extremely seriously and are committed to ensuring that the requirements of the GDPR are fully embedded within our culture, systems and policies, in advance of May 2018.
As such, our �GDPR project� is fully underway and all provisions are being carefully analysed, reviewed and evaluated. The project has the full support and sponsorship of our Board of Directors and all business functions. Some key areas of focus are:
� Awareness: all employees will receive GDPR training to ensure a thorough understanding of the impact of the regulations.
� Legal basis for processing data: reviewing all types of data processing carried out by ourselves to identify and document the legal basis for carrying it out.
� Communicating privacy information: revising our existing client privacy notices to ensure effective information is provided which informs individuals how their personal data will be used.
� Individuals rights: reviewing our existing procedures to ensure all rights are covered, including the �right to be forgotten� and �subject access requests�.
� Data Breaches: reviewing our existing procedures to ensure appropriate measures are in place to detect, report and investigate a personal data protection breach.
Further updates and training will be issued in due course. Particularly, we will be asking all business functions to undertake an audit of the data held within their particular area, both paper and electronic. Full instructions will be provided initially to Line Managers.
In the meantime, please may I remind everyone to treat client and personal data with the utmost care and respect, which we all have responsibility to protect and preserve. our current Data Protection procedures (including Clear Desk policy) should be adhered to.
From 25th May 2018, We will be required to report all breaches to the Information Commissioners Office, which has new powers to fine firms up to 4% of their annual turnover.
Finally, if you have any questions, please contact (Head of Legal Services) in the first instance.