General Data Protection Regulation (GDPR) Compliance

Solicitors within Franklins’ Corporate Regulatory Compliance division are able to advise and assist organisations should there be a breach under the 2018 General Data Protection Regulation (GDPR).

What is Data Protection Compliance?

Data Protection compliance basically means that organisations fall within the scope of the Data Protection legislation which regulates the proper handling of personal and sensitive data.

Why is Data Protection Compliance important?

Data Protection is important because it controls how personal information can be used, stored, accessed etc. It provides the individual with rights of access, including updating, correcting and deletion of data.

What legislation governs Data Protection in the UK?

Data Protection Act 2018.

Who does the Data Protection Act apply to?

According to the Information Commissioner’s Office (ICO) “personal data means any information relating to an identified or identifiable natural person (“data subject”), an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

The Data Protection Act does not apply to organisations or businesses.  

What constitutes ‘personal data’?

Types of personal data can be obvious such as a name, address, date of birth, email, telephone number but also includes credit card, account data, number plate, appearance and bank details. The ICO classifies data into categories according to their sensitivity: public, private, confidential and restricted.

What should an organisation do in the instance of a data breach?

Following the identification of a data breach, an organisation has 72 hours to report the breach to the ICO. Failing this, the business can incur a maximum fine of up to £8.7m or 4% of the business’s turnover, whichever is the higher. As soon as a breach is identified, an organisation needs to preserve all breach evidence, contain the breach and investigate the reason for the breach, Through a well-developed incident response plan, organisation can limit the damage caused by a breach an recover more quickly by restoring any systems they may have lost or which have been compromised.

How Franklins Solicitors support organisations with Protection Compliance

Franklins can provide risk mitigation by supporting preventative measures via a Data Protection audit and from this help to develop a robust incident response plan. In the event of a breach we can also support in any interactions with the ICO to put a recovery plan in place.

Breaching GDPR

The GDPR is regulated by the supervisory authority, The Information Commissioner’s Office (ICO).

There are strict time frames for notifying the ICO of any breach.

Data controllers must notify the ICO of a personal data breach in which there is a risk to the data subject’s rights no later than 72 hours after becoming aware of it. The notification must include:

  • The nature of the breach
  • The name and contact details of your Data Protection Officer (DPO)
  • The likely consequences of the breach
  • Measures taken or proposed to be taken to address and mitigate the breach.
Fines under the GDPR

A number of factors will be taken into account by the ICO when deciding the level of fine. Given that the fine can be 4% of the total worldwide annual turnover (note not profit), these could be critical to the survival of a business. These factors include:

  • Nature, duration and gravity of the breach
  • Whether it was intentional or negligence
  • What damage was caused
  • Mitigation steps taken
  • Existing safeguards implemented
  • The degree of co-operation with the ICO
  • Whether the matter was reported by the company
  • Any other similar breaches by the company
  • Any other mitigating factors

Seeking advice promptly and responding to the breach quickly with a clear plan of action is vital.

Contact Us

Frequently Asked Questions about Data Protection Compliance

What does Data Protection compliance entail?

Data Protection compliance involves adhering guidelines for the collection and processing of personal information from individuals within the UK and EU. The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation. It requires businesses to protect personal data and uphold the privacy rights of individuals.

    Why is Data Protection compliance important?

    Compliance with data protection is crucial for safeguarding personal data and maintaining trust with customers. It helps prevent data breaches and fines, ensuring that businesses respect the privacy of individuals and operate within legal frameworks.

      How does data protection affect businesses?

      Data protection affects businesses by imposing strict rules on data handling and storage and requiring transparency about how personal data is used. Businesses must implement robust data protection measures and may need to appoint Data Protection Officers (DPOs) depending on their business type and scale of data processing.

        What is the role of a Data Protection Officer (DPO)?

        A DPO is responsible for overseeing data protection strategy and implementation to ensure compliance with data protection requirements. They monitor data processing activities, conduct data protection impact assessments, and act as a point of contact for data subjects and supervisory authorities.

          What are the penalties for non-compliance with data protection laws?

          Non-compliance with data protection laws can result in significant penalties, including fines of up to €20 million or 4% of the annual global turnover of the preceding financial year, whichever is higher. Businesses may also face reputational damage and loss of customer trust.

            How can Franklins Solicitors assist with data protection compliance?

            Franklins Solicitors offers expert guidance on data protection legislative compliance, helping businesses develop and implement data protection policies. We provide services such as:

            • Conducting data protection audits
            • Assisting with the appointment and training of DPOs
            • Advising on data protection impact assessments
            • Reviewing and drafting privacy notices and consent forms
            • Ensuring compliance with data subject rights

            Contact the Franklins Business Services team

            If you have any questions about Data Protection Compliance, please don’t hesitate to contact our team of experts who are on hand and ready to help you.