{"id":1946,"date":"2017-11-22T15:00:40","date_gmt":"2017-11-22T15:00:40","guid":{"rendered":"http:\/\/tiger-recruitment.com\/?p=1946"},"modified":"2021-04-20T16:37:38","modified_gmt":"2021-04-20T15:37:38","slug":"preparing-gdpr-need-know","status":"publish","type":"post","link":"https:\/\/tiger-recruitment.com\/workplace-insights\/preparing-gdpr-need-know\/","title":{"rendered":"GDPR law: what you need to know"},"content":{"rendered":"<p>The General Data Protection Regulation (GDPR) has revolutionised the collection and storage of personal data in the EU since it&#8217;s introduction in May 2018. When it was introduced, it had major repercussions for many small and medium enterprises.<\/p>\n<p>The regulation\u2019s main aim is to give individuals control of their data once more; giving them the right to know how any company is handling personal data. For the purposes of the legislation, personal data is classified as information held about a living individual, which can identify who they are.<\/p>\n<h2>The regulation<\/h2>\n<p>The regulation can be broken up into seven key principles:<\/p>\n<p>\u2022 The right to be informed<br \/>\n\u2022 The right of access<br \/>\n\u2022 The right of rectification<br \/>\n\u2022 The right to erasure<br \/>\n\u2022 The right to restrict processing<br \/>\n\u2022 The right to data portability<br \/>\n\u2022 The right to object<\/p>\n<p>These principles apply to three main areas: consent, data privacy, and data protection officers. Failure to comply can result in fines of up to \u20ac20 million or up to four per cent of total global revenue of the preceding year, whichever is greater.<\/p>\n<h3>Consent<\/h3>\n<p>Since the introduction of GDPR, businesses have had to ensure that consent is freely given with an affirmative and clear action. Instead of asking consumers to tick the box if they don\u2019t want to hear from a company, SMEs must now ask consumers to tick the box if they do want to receive marketing material.<\/p>\n<p>On the other side of the coin, withdrawal of consent is now required to be as simple as possible. Consumers must be informed that they have the right to withdraw consent at the time of signing up, and businesses must make this process as easy as possible. Furthermore, when withdrawn, an individual\u2019s details must be permanently erased, not just removed from the relevant databases. Essentially, individuals now have the right to be forgotten, so data records must be as up to date as possible, with inaccurate entries corrected without delay.<\/p>\n<p>In collecting and storing data, companies must also provide a clear trail of consent in case of audit, with screen grabs or saved consent forms.<\/p>\n<h3>Data Privacy<\/h3>\n<p>One of the most striking changes found in the GDPR in comparison to older laws is the requirement of businesses to prove they have a legal basis to store and use any gathered data, and provide details of where their data is stored. Reasons for processing data must be specific, explicit and have a legitimate purpose.<\/p>\n<p>The regulation recognises four lawful bases for processing:<\/p>\n<p>1. Explicit consent \u2013 individual must proactively supply consent through a positive opt-in<br \/>\n2. Compliance with a legal obligation \u2013 for example, to process right to work checks<br \/>\n3. Entering into a contract with an individual to supply goods and services or fulfil an obligation \u2013 for example, an employment contract<br \/>\n4. Legitimate interests, unless outweighed by the individual\u2019s rights and interests. Businesses must prove they have genuine reasons to process personal data without consent by satisfying the following criteria:<br \/>\na. Organisations must need to process information for its own legitimate interests or for those of a third party to whom it may disclose the data.<br \/>\nb. The legitimate interests must be balanced against the individual\u2019s \u2013 processing must not prejudice the rights and freedoms, or legitimate interests, of the individual. If in conflict, the individual\u2019s interests will take priority.<br \/>\nc. Any processing must be fair, transparent, accountable and must comply with all the data protection principles.<\/p>\n<p>Companies can now only hold data that is necessary for the purpose of processing, keeping retention periods to a minimum. SMEs must also know exactly where their data is located.<\/p>\n<h3><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1948\" src=\"https:\/\/tiger-recruitment.com\/wp-content\/uploads\/2018\/03\/GDPR-2.jpg\" alt=\"\" width=\"600\" height=\"337\" srcset=\"https:\/\/tiger-recruitment.com\/wp-content\/uploads\/2018\/03\/GDPR-2.jpg 600w, https:\/\/tiger-recruitment.com\/wp-content\/uploads\/2018\/03\/GDPR-2-300x169.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><br \/>\nData Protection Officers and Breaches<\/h3>\n<p>One of the most effective ways to ensure full compliance to the GDPR is to hire a data protection officer (DPO). In fact, the regulation states that a DPO must be appointed for all public authorities or any businesses whose core activities involve the systematic monitoring of large amounts of personal data.<\/p>\n<p>A DPO is responsible for implementing any data protection strategies and is accountable for maintaining all documentation that proves full compliance with the GDPR. The regulation doesn\u2019t specify any necessary credentials, but suggests that anyone employed as a DPO have expert knowledge of data protection law and practices. They can be employed on a permanent basis or under a service contract, and can be shared by a group of businesses, proving equal accessibility. A DPO should report to the highest management level and be located in the EU.<\/p>\n<p>In the event of a data breach, companies must inform the relevant authorities within 72 hours, providing extensive details of the problem and proposing mitigation strategies.<\/p>\n<p>Tiger Recruitment can help source temps with a data background to cleanse and tidy databases and delete records, or contracted data protection officers to help companies remain GDPR compliant.<\/p>\n<p><a href=\"\/?page_id=7\">Get in touch<\/a> today to find out how we can help.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The General Data Protection Regulation (GDPR) has revolutionised the collection and storage of personal data in the EU since it&#8217;s introduction in May 2018. When it was introduced, it had major repercussions for many small and medium enterprises. The regulation\u2019s main aim is to give individuals control of their data once more; giving them the<\/p>\n<p><a class=\"read-more\" href=\"https:\/\/tiger-recruitment.com\/workplace-insights\/preparing-gdpr-need-know\/\">Read more<\/a><\/p>\n","protected":false},"author":1761,"featured_media":1949,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[8],"insight-type":[13],"class_list":["post-1946","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-workplace-insights","insight-type-article"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>GDPR law: what you need to know<\/title>\n<meta name=\"description\" content=\"We\u2019ve put together a comprehensive guide on GDPR laws, how they affect you and your data and what to do if you have a data breach.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/tiger-recruitment.com\/workplace-insights\/preparing-gdpr-need-know\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR law: what you need to know\" \/>\n<meta property=\"og:description\" content=\"We\u2019ve put together a comprehensive guide on GDPR laws, how they affect you and your data and what to do if you have a data breach.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tiger-recruitment.com\/workplace-insights\/preparing-gdpr-need-know\/\" \/>\n<meta property=\"og:site_name\" content=\"Tiger Recruitment\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/tigerrecruitment.ltd\/\" \/>\n<meta property=\"article:published_time\" content=\"2017-11-22T15:00:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-20T15:37:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/tiger-recruitment.com\/wp-content\/uploads\/2018\/03\/GDPR-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tiger Contributor\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@tigerrecruit\" \/>\n<meta name=\"twitter:site\" content=\"@tigerrecruit\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tiger Contributor\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR law: what you need to know","description":"We\u2019ve put together a comprehensive guide on GDPR laws, how they affect you and your data and what to do if you have a data breach.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/tiger-recruitment.com\/workplace-insights\/preparing-gdpr-need-know\/","og_locale":"en_GB","og_type":"article","og_title":"GDPR law: what you need to know","og_description":"We\u2019ve put together a comprehensive guide on GDPR laws, how they affect you and your data and what to do if you have a data breach.","og_url":"https:\/\/tiger-recruitment.com\/workplace-insights\/preparing-gdpr-need-know\/","og_site_name":"Tiger Recruitment","article_publisher":"https:\/\/www.facebook.com\/tigerrecruitment.ltd\/","article_published_time":"2017-11-22T15:00:40+00:00","article_modified_time":"2021-04-20T15:37:38+00:00","og_image":[{"width":600,"height":400,"url":"https:\/\/tiger-recruitment.com\/wp-content\/uploads\/2018\/03\/GDPR-1.jpg","type":"image\/jpeg"}],"author":"Tiger Contributor","twitter_card":"summary_large_image","twitter_creator":"@tigerrecruit","twitter_site":"@tigerrecruit","twitter_misc":{"Written by":"Tiger Contributor","Estimated reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[]}},"_links":{"self":[{"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/posts\/1946","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/users\/1761"}],"replies":[{"embeddable":true,"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/comments?post=1946"}],"version-history":[{"count":0,"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/posts\/1946\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/media\/1949"}],"wp:attachment":[{"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/media?parent=1946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/categories?post=1946"},{"taxonomy":"insight-type","embeddable":true,"href":"https:\/\/tiger-recruitment.com\/wp-json\/wp\/v2\/insight-type?post=1946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}