<img src="https://certify.alexametrics.com/atrk.gif?account=b2hlr1ah9W20em" style="display:none" height="1" width="1" alt="">

data protection laws

The General Data Protection Regulation (GDPR) is fast approaching and compliance with data protection laws is more important than ever.

Over the years, there have been many high profile cases which highlight the consequences of getting it wrong.

Just last year, financial firm Nouveau Finance Ltd, a loan company registered with the Financial Conduct Authority (FCA), was fined £70,000 for sending spam texts.

Over a 6-month period, more than 2 million texts were sent unlawfully by a marketing agency contracted by the firm. It is illegal for companies to send text messages to people without their consent. The ICO warned that firms cannot dodge responsibility when services are outsourced.

Fines for failing to comply with data protection laws are set to become a lot higher when GDPR comes into effect on 25th May 2018. So, what can you do to avoid any hefty fines which could potentially cripple your business?

Follow these top tips to comply with data protection laws:

  1. Be open, tell people what you're doing with their data and get consent - before collecting personal data, explain upfront what data you're collecting, how you'll use it, and who it may be disclosed to. Most companies do this via privacy statements.
  2. Take extra care with sensitive personal data - for example, data on race or ethnicity, age, political opinions, religion (beliefs or non-beliefs), physical or mental health (including disability), sexual orientation, membership of trade unions, etc.
  3. Uphold individuals' rights - remember individuals are entitled to see what personal data you hold data protection laws about them, to have inaccurate information corrected, to stop their data being used for marketing purposes, and so on. Under GDPR, there is also the new right 'to be forgotten'.
  4. Store information securely - follow company protocols at all times to prevent unauthorised access, as well as data loss or theft. Use strong passwords and encrypt all personal data held on portable devices (such as laptops, memory sticks and tablets).
  5. Data minimisation - don't keep personal data for longer than is necessary; make sure that personal data is destroyed securely and in full.
  6. Take care when sharing personal information with third parties - make sure you have the necessary consent first.
  7. Avoid transferring data outside the EU - other countries don't have the same data protection guarantees so prior consent is always required for this.

Leave a comment

Tick

eBook: Essential Uncovered

Skillcast Essentials is our best-selling library and there's a reason for that. Essentials library provides comprehensive coverage of the key compliance / conduct issues that companies in the UK face today.

Download now

How to Manage the Compliance Personas in Your Company

Rory has no time for rules, especially the pointless ones that add a lot of work for no apparent benefit. When he encounters such rules, his first thought is to find a work-around. Andy doesn't mind ...

Read More
FCA Compliance News - November 2018

An overview of the most recent and upcoming changes to FCA guidelines for senior managers...   Regulatory Update The last six weeks have been a very busy time for the UK regulators, with both the ...

Read More
Compliance Essentials News - November 2018

This blog is dedicated to bringing you the news that touches the people dimension of regulatory compliance. It's not only about regulations, policies, procedures and systems. It's also about people, ...

Read More
Getting personal: five ways to engage staff with compliance training

It's an on-going struggle for most companies to engage their staff with compliance training. There's a constant stream of new regulations and tweaks to existing ones. And many of these require ...

Read More