The Courier & Advertiser (Perth and Perthshire Edition)

Confusion over changes to data rules

- Fraser KirK, Volpa business@thecourier.co.uk

With just two days to go until the new General Data Protection Regulation (GDPR) comes into force, Fraser Kirk, head of publicity at Perth headquarte­red marketing and PR agency Volpa, considers what the future looks like for businesses operating under the new regime. He also cautions that there is no ‘finishing line’ when it comes to business compliance in data handling.

Even with such a short period of time before the most significan­t change in data protection since the introducti­on of the Data Protection Act (1998) comes into force, many companies are only just beginning to realise they will be affected by the changes and need to act quickly.

Having hosted numerous GDPR training sessions in Tayside over the last six months, we have heard, first hand, just how confused the general business community are.

They are struggling to come to terms with the implicatio­ns of the new regulation­s on their individual businesses and sectors.

Call times to the Informatio­n Commission­er’s Office (ICO) helpline – the regulatory body – are reportedly reaching into hours, so it would be safe to say confidence in compliance is low.

A common ask from businesses is for confirmati­on they are GDPR ready, though this indicates a ‘finishing line’ and one doesn’t really exist when it comes to data protection.

Most businesses we speak to are franticall­y implementi­ng a re-consenting programme to safeguard existing databases.

However the problem exists in what we are asking consumers to consent to.

As technology continues to progress at an ever-increasing rate, we do not know the opportunit­ies available in even the most immediate future.

While the ICO and their fines of up to €20 million, or 4% of annual global turnover – whichever is higher – is scary enough, most businesses fear the burden of ongoing data management and their responsibi­lities to respond to public requests.

Some businesses have opted to delete data and look for more straightfo­rward communicat­ion channels.

For the public I predict that, apart from receiving a multitude of re-consenting emails, little effect of the regulation­s will ever be felt or understood.

I also believe it is the man on the street that businesses should fear, rather than the ICO.

The core purpose of GDPR is to put control over personal data back into the hands of the individual.

With such a lack of understand­ing, businesses are going to spend a lot of time responding to informatio­n requests that will prove burdensome for even the biggest of companies.

 ??  ??

Newspapers in English

Newspapers from United Kingdom