<img src="https://certify.alexametrics.com/atrk.gif?account=b2hlr1ah9W20em" style="display:none" height="1" width="1" alt="">
    Login
    Get started

    5 steps to stay compliant when sharing data under GDPR

    Published on 29 Dec 2017 by Lynne Callister

    sharing data under gdpr

    On 25th May 2018, the General Data Protection Regulation (GDPR) brought significant changes to data protection laws. The new regulation aims to harmonise data privacy laws across Europe and to protect consumers.

    The sharing of personal data by businesses and organisations within Europe is subject to the GDPR. For any organisations sharing personal data with another organisation, they need to be thinking about the regulatory implications.

    Consider the healthcare provider who passes the patient's medical history onto a consultant in readiness for an operation. Or, a finance company who shares data with a credit rating agency to establish creditworthiness. GDPR requires that they need permission from the individual first to share that data.

    Now that the initial buzz of GDPR has faded, we thought it would be time for a refresher on how to stay compliant when sharing data under GDPR.

    5 steps to stay compliant when sharing data under GDPR

    1. Consider legitimacy - why are you sharing data in the first place? What are you hoping to achieve? Is it justified? Is the data sharing proportionate? What and how much data will be shared? With whom?
    2. Weigh up the benefits versus the risks - What are the benefits and risks in sharing or not sharing the information? Remember, if there is a high risk to the rights and freedoms of data subjects, conduct a Data Protection or Privacy Impact Assessment.
    3. Ascertain whether you have the right to share information - for example, what type of organisation do you work for, what relevant powers or functions does it have, what is the nature of the information you're planning to share (eg is it confidential, especially sensitive, etc), and is there a legal obligation (such as a legal requirement, a court order, a safeguarding duty, etc).
    4. Develop sharing protocols and agreements - is there any sharing protocol or agreement currently in place with the third party? How frequently is information shared with them? What information will you give to data subjects about this? At what point and how will this be communicated? What specific measures (eg encryption) are in place to maintain security?
    5. Keep data up-to-date and accurate - how will you ensure that the data you have shared remains up-to-date and accurate? Who is responsible for doing this (the company doing the sharing or the recipient company)? What arrangements are in place if data subjects want to access it? How long should the data be retained by each party, and what processes are required to ensure it is deleted by all parties when it is no longer needed?

    Want to know more about GDPR?

    As well as 30+ free compliance training aids, we regularly publish informative GDPR blogs. And, if you're looking for a training solution, why not visit our GDPR course library.

    If you've any further questions or concerns about GDPR, just leave us a comment below this blog. We are happy to help!

    Leave a comment

    Tick

    eBook: Essential Uncovered

    Skillcast Essentials is our best-selling library and there's a reason for that. Essentials library provides comprehensive coverage of the key compliance / conduct issues that companies in the UK face today.

    Request now

    Transparency International & Skillcast Relaunch Anti-Bribery Training

    Transparency International (UK) have partnered with Skillcast to develop free anti-bribery training resources, including a refreshed version of the acclaimed 'Doing Business Without Bribery' ...

    Read More
    5 Steps You Should Take To Avoid Facilitating Tax Evasion

    Even if a company has no knowledge of its employee or associated person facilitating tax evasion, they could still be held liable for 'failure to prevent' the offence. The UK Government introduced ...

    Read More
    10 Things You Should Do To Improve Risk Management At Work

    Whether it's catching the train to work, crossing the road, investing in financial products, or making dietary choices, life is full of risk. You can't remove it, but you can contain or mitigate it.  ...

    Read More
    Skillcast at World of Learning 2019

    Skillcast are hosting a 30-minute seminar at World of Learning (#WOL19) the UK’s most comprehensive event for all aspects of learning and development. About World of Learning 2019 Showcasing a ...

    Read More