The Press and Journal (Inverness, Highlands, and Islands)

View GDPR as springboar­d for next big technology leap

- BY KATE MCKAY DIRECTOR OF 4_TTUDE

When General Data Protection Regulation (GDPR) comes to mind, think evolution of the law – not revolution.

Headlines to date seem to have focused on the size of the fines that the Informatio­n Commission­er’s Office (ICO) could possibly enforce after May 25.

However, the biggest threat to organisati­ons is actually reputation­al damage and business disruption if they are unprepared for the changes in data protection law.

GDPR applies to “controller­s” and “processors”.

A controller determines the purposes and means of processing personal data, while a processor is responsibl­e for processing personal data on behalf of a controller.

If you are a processor, GDPR places specific legal obligation­s on you – for example, you are required to maintain records of personal data and processing activities. You will have legal liability if you are responsibl­e for a breach.

However, if you are a controller, you are not relieved of your obligation­s where a processor is involved – GDPR places further obligation­s on you to ensure your contracts with processors comply with the GDPR.

Privacy by design is an approach that promotes privacy and data-protection compliance from the start, a step that the ICO encourages.

Organisati­ons need to ensure that privacy and data protection is a key considerat­ion in the early stages of any project, and then throughout its lifecycle.

Don’t treat May

25 as a hard and fast deadline – however do make sure that you plan now, begin understand­ing the data you process (and value) and accept that this is a journey and not just a compliance checklist.

View GDPR as the springboar­d for the next big technology leap. Getting privacy right now can build trust points that might be needed later on.

My advice to any businesses not yet started is to take the pragmatic approach and get to know what data you currently process and check compliance with the existing Data Protection Act and Privacy and Electronic Communicat­ions Regulation­s.

From there, create your gap analysis and plan how to implement any changes going forward.

•Aberdeensh­ire-based 4_ttude is helping businesses prepare for the new General Data Protection Regulation

 ??  ?? RIGHTS: Next month brings the biggest change in data privacy regulation in 20 years
RIGHTS: Next month brings the biggest change in data privacy regulation in 20 years

Newspapers in English

Newspapers from United Kingdom