25th May 2018 and the new EU General Data Protection Regulation (“GDPR”) will be directly applicable in all EU member states.
Two years away, will Britain even be a member of the EU by then … does it really matter now?
Although there is no immediate urgency, the GDPR rules will have wide-ranging implications for all businesses irrespective of where they are located if they have data subjects (eg customers, employees, individuals they monitor) in the EU. In terms of data protection, the outcome of the Brexit vote will be irrelevant for many UK based businesses: EU data protection rules are more than likely to be the gold standard with which any business with an international element will have to comply. In many respects this is already the case as a number of US businesses, Facebook to name one, are finding.
So why consider the GDPR now?
Compliance with the GDPR will take time and careful planning will ease the burden of compliance and ensure a smooth adoption of new practises. In fact, much of what will be required for the GDPR is good practise under current data protection legislation.
And to focus the mind, the current maximum penalty in the UK of £500,000 for data protection breaches is paltry in comparison with the GDPR penalties for non-compliance: EUR20 million or, if higher, 4% of worldwide turnover.
The GDPR has individuals and the protection of their data at its heart. The legislation wishes to put individuals in control of their data and to enhance individuals’ rights to control their data whether by way of consent, the right of access, or right to rectification or erasure or portability plus a right not to be subject to a decision based solely on automated processing. In addition, the legislation contains various provisions to make businesses more accountable for their data practises.
This Regulation will apply to you in some measure or other: all businesses that employ people or have customers handle personal data. Businesses that provide their services via the cloud may process or hold significant amounts of personal data on behalf of their customers. Processors will now also be subject to direct compliance obligations under the GDPR aswell as increased contractual obligations imposed by controllers in satisfying their own compliance obligations.
Where to start?
A good place to start is with the advice published by the Information Commissioners Office: Preparing for the GDPR: 12 Steps to take now.
Here are a few initial points to consider:
1. The law is changing and data protection must be at the heart of all that your business does.
2. Think about the types of personal information that you hold, why you hold it and on what basis you process that personal data ie do you need explicit, informed consent to process that data or can you rely on another ground or legitimate interest?
3. New products, services or technologies will be required to take data protection requirements into account from their inception and consideration should be given as to whether a Privacy Impact Assessment is required (See ICO Guidance on PIAs). This all takes time.
4. Policies, privacy notices and procedures will need updating and controls will have to be put in place to ensure and document compliance with the GDPR and to deal with a potential data breach.
5. Keep an eye on the ICO website for further useful articles and tips on how to prepare for the new data protection laws.
This note picks out a few aspects only of a significant and complex piece of new legislation. Being aware of it is a very good start!
Summerfield Browne Solicitors have offices in London, Birmingham, Cambridge, Oxford, Northampton and Market Harborough, Leicester.






