February 15, 2018
When the GDPR comes into force on 25 May, data protection laws in the UK will undergo their biggest overhaul since the Data Protection Act 1998. The changes will also apply throughout the rest of the EU, as the GDPR is an EU regulation. However, the UK has already announced that it will continue to comply with the GDPR after Brexit.
Some of the key changes to be introduced are:
In practice, in order to comply with the GDPR, businesses will need to assess all of the personal data they hold (including marketing databases and details of current and former employees) to see whether they still have a valid basis for holding and processing it. If not, the data will need to be deleted if fresh consent cannot be obtained from each individual. Businesses should also review and amend their commercial and employment contracts and policies, or bring in new policies, ensure their staff are trained on how to handle personal data, and put systems in place for recording all decisions that are taken.