Podcast Summary:
Ed Simpson talks to Client Legal Director Amanda Mallender about General Data Protection Regulations (GDPR). From key concepts and principles through to likely changes incoming with the proposed Data Protection and Digital Information Bill, Amanda explains what businesses need to know to stay on top of their data protection responsibilities.
In this episode ...
Episode introduction:
In this episode of TLD Talks, Ed Simpson, CEO of The Legal Director talks with Amanda Mallender about what GDPR means for SMEs, as a new Data Protection and Digital Information Bill makes its way through Parliament.
Today’s guest:
Amanda Mallender is a solicitor with more than 20 years’ experience both in-house and in private practice. She is a practical and solutions-driven lawyer who puts in the time to understand each company’s systems and processes, allowing her to offer clear opinions and guidance to senior management. Amanda enjoys working with rapidly growing businesses helping them build and develop good governance.
Main topics and questions:
- What is GDPR? How does it relate to the data protection landscape in the UK? (1’23)
- What are some of the key concepts and principles of GDPR? For example, personal data, and the data subject. (2’26)
- What is processing in the context of data protection? (3’45)
- What is the difference between a data controller and a data processor and how would a business work out which one it is? (4’45)
- The eight key data protection principles, what businesses are supposed to do with the data they are holding. (6’07)
- What can go wrong? The key business risks if you don’t take your GDPR responsibilities seriously, for example cyber-hacks and accidental errors. (7’08)
- How to reduce the impact of accidental errors, for example having delays on emails, passwords being separately. (08’26)
- The importance of data protection training for staff, recognising issues and knowing what to do if something goes wrong. (09’36)
- Where does the regulator, the Information Commissioner’s Office, fit into the picture? (10’00)
- What are Subject Access Requests and what impact could it have on your business if you receive one? (11’35)
- What are the benefits of having a good GDPR compliance programme in place? (13’42)
- Where would a CEO or FD of a small business start with a compliance programme? What’s the first thing they should do? What is a data map? (14’56)
- Next steps after creating a data map. (15’53)
- Is the new Data Protection Bill being discussed in Parliament related to Brexit? What changes are being discussed? (16’27)
- When is the Bill expected to come into force? (19’05)
Listen via:
“It’s all about protecting individuals’ rights and making sure that they have control and access to the data that’s being held about them.”
Amanda Mallender
“If you wouldn’t want the individual you’re making a comment about to hear that comment, don’t write it down. Because if a Subject Access Request comes in you will have to disclose it and that can be really quite embarrassing for a company.”
Amanda Mallender
“You can’t eliminate those human errors, everybody’s going to suffer them, but it’s having processes and controls in place to reduce them as much as you sensibly can.”
Amanda Mallender
Click Here
Previous slide
Next slide
Related Posts
-
Meet Amanda Mallender - a responsive, flexible and principled lawyer with over 20 years experience as in-house counsel.
-
Originally introduced to Parliament in July 2022, the DPDI (Data Protection and Digital Information Bill 2022-23) has been refreshed and reintroduced for consideration. Amanda Mallender gives an overview of the key changes.
