No doubt by now you’ve heard of the GDPR, but what does it actually mean to be GDPR compliant?

To be GDPR compliant, a company or organisation that collects, uses, and stores personal data from its users must adhere to a set of rules that keep that data safe and secure, while giving users more control over accessing their data and understanding how it’s used.

What does GDPR stand for?

GDPR stands for General Data Protection Regulation.

What is the GDPR?

The GDPR is a set of regulations designed to protect the rights of EU residents and citizens over their personal data. It came into effect on 25th May 2018.

With so many aspects of our lives online, these laws exist to help protect the personal data collected when we use most websites, including banking, retail, and social media sites, to name a few.

So what is personal data?

Personal data is any information related to an identifiable natural person, also known as the “data subject.” An identifiable natural person is someone who can be identified, directly or indirectly, by reference to an identifier, such as a name, identification number, or an online identifier reflecting their physical, genetic, cultural, economic, or social identity.

If my business is outside the EU, do I need to be GDPR compliant?

In short, yes. If your company offers goods or services to people in the EU, you’ll be collecting some form of personal data from them, and are therefore required to be GDPR compliant.

What does it mean to be GDPR compliant?

Any company or organisation that collects, maintains, and uses people’s personal data has a set of rules it must follow to comply with the GDPR. Here’s a checklist to help:

  • Complete an audit to determine what personal information you collect, and how you use and maintain it.
  • Ensure you satisfy the requirements for “lawfulness of processing” of personal data.
  • Have a privacy policy that clearly outlines how and why you collect and use personal data, and how you keep it safe and where it’s stored.
  • Encrypt or anonymise personal data wherever possible.
  • Create a data protection policy for your company, and make sure staff understand their role in keeping personal data secure.
  • Have a process in place for handling a data breach: this can be part of your data protection policy.
  • Appoint a Data Protection Officer, if required.
  • Make sure your customers and users are aware of their data privacy rights.

Personal Information Audit

Determine what personal information your company collects, and whether any of it comes from EU residents or citizens. If it does, check the relevant GDPR guidance to determine whether you’re subject to the regulation.

Lawfulness of Processing

Under the GDPR, personal data processing is lawful if one or more of the following applies:

  1. Your user has consented to their personal data being processed for a specific purpose.
  2. Processing is required to fulfil a contract with the user.
  3. Processing is necessary for a legal obligation.
  4. Processing is needed to protect your users’ interests, or those of another person.
  5. Processing is necessary to carry out a task in the public interest, or under the official authority of the controller.
  6. Processing is necessary for the legitimate purposes of the data controller or a third party, unless overridden by the interests of the data subject, especially important where the data subject is a child.

A GDPR-Compliant Privacy Policy

Under the GDPR, your company must have a privacy policy that’s written in clear terms, is concise, is provided free of charge, and is available to users in a timely manner. It should include:

  • Your purpose for processing personal data
  • How long personal data is retained
  • Who personal data is shared with, if anyone
  • Contact details for your company, and your data protection officer if you have one
  • A list of data protection rights
  • The right for users to withdraw consent at any time
  • The right for users to lodge a complaint with a supervisory authority
  • Details of any automated decision-making system, including its consequences, if you have one implemented

Encrypting Personal Data

Wherever possible, encrypting personal data helps keep it safe and private. Encryption scrambles data so it can only be read by someone who knows the code or encryption key.

There are several types of encryption; one of the most common is SSL (“secure sockets layer”), used by most legitimate websites. You can tell a website uses it by looking for the lock symbol in the URL bar and the “s” in “https://”. Other common forms include AES (Advanced Encryption Standard), RSA, and Triple DES.

Data Protection Policy

Create a data protection policy for your company, outlining how you use, manage, store, and secure data. This is an internal policy for handling personal data, so employees understand and can implement best practices.

Data Breach Process

In the event of a data breach, the relevant authorities must be notified within 72 hours, unless the breach is unlikely to cause harm to an individual’s rights. Make sure you have a data breach protocol in place; your data protection policy is a good place to document it.

Appoint a Data Protection Officer

A Data Protection Officer isn’t always required, but your company will need to appoint one if it meets any of the following:

  • Public authority: the processing of personal data is done by a public body or authority (with exemptions for courts and other independent judicial authorities).
  • Large-scale, regular monitoring: processing personal data is a core activity of an organisation that regularly and systematically monitors data subjects on a large scale.
  • Large-scale special data categories: processing of specific “special” data categories is part of the organisation’s core activity, done on a large scale.

Even if your company doesn’t require a Data Protection Officer, someone still needs to be responsible for ensuring GDPR compliance.

Ensure Users Are Aware of Their Data Privacy Rights

One of the key aspects of the GDPR is protecting the privacy of personal data and empowering data subjects with knowledge of their rights:

  1. The right to information: to find out whether your company is processing their personal data, what type, and why.
  2. The right of access: to access the personal data your company holds, including requesting copies.
  3. The right to rectification: to have inaccurate or outdated personal data corrected.
  4. The right to withdraw consent: at any time, for the processing of their personal data.
  5. The right to object: to request that processing of their personal data stop, unless there are overriding legitimate grounds to continue; where processing is for direct marketing, it must stop immediately.
  6. The right to be forgotten (erasure): to request that all their personal information be erased, under certain grounds.
  7. The right to data portability: to receive their personal data in a structured, commonly used, machine-readable format, and transfer it to another data controller.

In Summary

Being GDPR compliant is complex. A well-structured data protection policy for your staff, and a clearly written privacy policy for your users, will go a long way toward implementing what the GDPR requires.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.