You know you need to protect your users’ data and have a privacy policy in place that outlines how you do this. But what about a Data Protection Policy? And no, it’s not the same thing.

A Data Protection Policy is a policy that outlines how a company uses, manages, secures, and protects its data. Its main objective is to ensure the security of the data it handles and maintains. It covers what kind of data you collect and store, how your company handles and processes it, and how you handle any breaches in security.

data protection policy

The Difference Between a Data Protection Policy and a Privacy Policy

A Data Protection Policy is an internal policy for handling corporate data, so employees are aware of and can follow best practices. A privacy policy, on the other hand, is for your users, and outlines how you collect, use, manage, and store their personal data. The privacy policy is published on your website; the Data Protection Policy is not.

Do I Need a Data Protection Policy?

Before answering this, it’s worth asking whether you need a Data Protection Officer (DPO): the answer to that question determines the answer to this one.

A DPO is required if:

  • You are a public authority or body
  • You carry out regular, large-scale monitoring of individuals
  • Your company’s core activities involve processing data related to criminal offences and/or convictions

If your company requires a DPO, you’ll also need a Data Protection Policy so your DPO can demonstrate compliance with GDPR principles. If you don’t need to appoint a DPO, you’re not required to have a Data Protection Policy in place.

Main Elements of a Data Protection Policy

Your Data Protection Policy should include the following elements:

  1. The purpose of the policy: a description of why the policy exists and the importance it holds for the company. This is your company’s vision for data privacy.
  2. Definitions: the GDPR encourages plain, clear language, so a short glossary helps staff unfamiliar with terms like “data subject,” “data controller,” or “territorial scope.”
  3. Scope of data protection: who the policy applies to, and the type of data it covers.
  4. Data protection methods: the safeguards your company has in place to protect personal and sensitive data once collected, and a guide for individuals and departments.
  5. The principles: the GDPR’s principles for processing personal data, followed by an explanation of how your company implements them.
  6. Data subject rights: a list of the eight data subject rights, with a statement that your company will adhere to them.
  7. Roles and responsibilities: the key roles and responsibilities of staff and your data protection officer, if you have one.
  8. Accountability: a statement of the company’s responsibility for, and compliance with, the Data Protection Principles.
  9. Legal requirements for data protection: the data protection principles all staff handling personal data must follow.
  10. Reporting data breaches: how your company defines a data breach and the process for reporting one when required.
  11. Training: if your company trains staff on data protection, that should be documented here too.

1. The Purpose of the Policy

This is the introduction: an outline of what the policy covers and its purpose, stating the company’s data privacy and protection vision, and who it applies to (typically both clients and employees).

This image has an empty alt attribute; its file name is Screen-Shot-2020-05-29-at-2.35.37-pm-1024x654.png The Introduction to Axiomatic’s Data Protection Policy

2. Definitions

Many of the terms used in a Data Protection Policy, “data protection officer,” “data subject,” “personal data”, will be unfamiliar to staff without a data protection background. A clear list of definitions, often placed in an appendix, helps everyone understand the rest of the policy.

Part of the list of definitions in HSE's Data Protection Policy Part of the list of definitions in HSE’s Data Protection Policy

3. Scope of Data Protection

This section states who the policy is aimed at (for example, agents and contractors who handle personal information on the company’s behalf) and what kind of personal information it covers.

Solvay's Scope Clause Solvay’s Scope Clause

4. Data Protection Methods

This is where your company’s security measures live: what procedures staff need to follow, and what technical and organisational safeguards are in place (for example, restrictions on using personal devices for company data).

Part of the Data Security Section in Hope Learning Trust York's Data Protection Policy

Part of the Data Security Section in Hope Learning Trust York's Data Protection Policy Part of the Data Security Section in Hope Learning Trust York’s Data Protection Policy

5. The Principles

The GDPR sets out data protection principles your company needs to comply with. This section lists those principles, then explains how your company implements each one.

The NHS's Data Protection Principles clause The NHS’s Data Protection Principles clause

6. Data Subject Rights

The data subject is your customers, clients, and/or users. This section lists their rights under the GDPR and confirms your company’s commitment to upholding them.

Data subjects Rights clause from Daimler's Data Protection Policy Data subjects Rights clause from Daimler’s Data Protection Policy

7. Roles and Responsibilities

This outlines the responsibilities of staff members and your data protection officer (if you have one), including what happens if an employee doesn’t comply.

Responsibilities clause from Solvay's Data Protection Policy Responsibilities clause from Solvay’s Data Protection Policy

8. Accountability

This section states that the company is responsible for, and must be able to demonstrate compliance with, the Data Protection Principles, typically naming the data controller and what they’re accountable for.

Accountability Section from the Data Protection Policy of The University College Cork, Ireland Accountability Section from the Data Protection Policy of The University College Cork, Ireland

Under the GDPR there are six lawful bases for processing personal data. This section lists them and explains how they apply to your company’s processing activities.

Legal requirements for data protection example

Section for Lawful Basis for Processing from International General Insurance Group's Data Protection Policy Section for Lawful Basis for Processing from International General Insurance Group’s Data Protection Policy

10. Reporting Data Breaches

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

It’s crucial to have a data breach policy so you can report a breach as quickly as possible. Not all breaches require reporting: first consider:

  • Does the breach pose a risk to people?
  • Does it pose a risk to their rights and freedoms?

If there’s a likely risk, you need to contact the relevant supervisory authority (in the UK, the ICO); if the risk is unlikely, you don’t. The ICO publishes a self-assessment questionnaire that’s a useful starting point for this risk assessment.

University of Sussex Reporting Data Breaches Section of their Data Protection Policy University of Sussex Reporting Data Breaches Section of their Data Protection Policy

11. Training

If your company trains staff on data protection, document that here: training helps ensure staff understand what’s required of them and how important protecting customer data is.

The University of Birmingham includes a training clause in it's Data Protection Policy The University of Birmingham includes a training clause in it’s Data Protection Policy

In Conclusion

The main sections to include in your Data Protection Policy are: the purpose of the policy, definitions, scope of data protection, data protection methods, the principles, data subject rights, roles and responsibilities, accountability, legal requirements for data protection, reporting data breaches, and training.

A Data Protection Policy outlines how your company uses, manages, secures, and protects its data, and it’s different from a privacy policy. The Data Protection Policy is internal, for staff and your DPO; a privacy policy is external, outlining how customer and user data is collected, used, and stored.

If your company is required to hire a DPO, you also need a Data Protection Policy to help them demonstrate GDPR compliance.

For a comprehensive Data Protection Policy, we recommend using our privacy policy generator.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.