By Client Legal Director, Amanda Mallender

The Data Protection and Digital Information Bill has been refreshed and version number two is currently poised to move to the House of Lords, so, here at TLD, we thought it would be an appropriate time to focus on GDPR.
In this blog, we will clarify some terms and basic principles of data protection and discuss the risks involved in handling and processing data. We will also let you know some key details about the imminent changes and what you can do to get prepared.
We will give you further commentary on this legislation once it has been passed into law. If you’d like more information about the incoming bill now, you can read my article, published recently in SME Today: Demystifying Data Protection: how do businesses prepare for new GDPR legislation?
Key concepts and terms
Personal data
In essence, this refers to data which identifies a living individual. This can include the obvious – your name, date of birth, bank account details – but also some more obscure online identifiers like your IP address, biometric or genetic data, health data, or details of your online activities. If two pieces of collated information can identify someone, this becomes personal data, and the identified person is the “data subject.”
Data processing
This term refers to anything you can possibly do with data – collating, sorting, editing, even opening an email and reading it. This definition is deliberately broad to ensure that people can’t easily get around the data protection laws.
The key takeaway from this, therefore, is that every business is impacted by these laws. Even if your operational business doesn’t involve processing personal data, you will undoubtedly be processing the personal data of your employees, which makes you a data controller and subject to data protection legislation.
Data processor v data controller
It’s important for you to ascertain whether you are a data processor or a data controller as there are different rights and obligations associated with each role. The UK’s regulator, the Information Commissioner’s Office (ICO), has some detailed information about this which is well worth a read: What are ‘controllers’ and ‘processors’?
Put briefly, a data controller is the party that decides what to do with the data. For example, a typical business with employees will be the data controller of its employees’ data because it decides what data to collect, how to process it, where to store it and how long to keep it.
A data processor, on the other hand, processes data on behalf of the controller. Consider the context of online services. A business such as Amazon Web Service that gives you the facility to store data is a data processor. They can only process that data in accordance with the instructions of the data controller and are not entitled to do anything other than that.
The data protection principles
There are seven principles in the data protection legislation that form the basis of the UK GDPR. Compliance with these fundamental principles should underly your data protection regime. They are fairly broad concepts that most people would readily agree with. For example, you must store data safely; only use data for the purpose for which you collect it (and for which you’ve told individuals you’re collecting it) and not keep personal data any longer than is necessary.
Adherence to these principles will give you the building blocks you need for good data protection practice. Again, the ICO has some good guidance on these key concepts.
Data breaches
One of the biggest data risks that most businesses face is that of a data breach. These can be broadly divided into two categories: external attack and internal error.
Cyber hacking
Cyber hackers deliberately exploit weaknesses in an organisation’s computer systems to steal or compromise data, to disrupt communications or procedures, or to fulfil some other harmful intention. Though you can never guarantee that you’re safe from such an attack, you can reduce the risk by ensuring that you’ve got appropriate and robust technical and operational measures in place to keep your data safe.
Human error
Save for the odd catastrophic case, this type of error is less likely to hit the headlines but is far more likely to occur. Often, this is simply due to an employee sending an email to the wrong person. And this usually has only minor consequences. However, there are occasions when significant amounts of personal data are shared, like an attachment containing bank details or payroll data for example.
You can never eliminate these kinds of human errors, but you can reduce their likelihood and mitigate their risk. Introduce processes and controls such as putting delays on the sending of emails or ensuring that if sensitive attachments are included, they’re password protected and the password is sent separately. Train employees in these processes and encourage best practice, like double checking email addresses and attachments before pressing send.
Your processes should set down clear instructions about what to do if a data breach does happen so individuals in your business know what to do and how to tackle it. And you should be regularly training staff who process or control personal data to recognise when there’s an issue. We regularly help businesses put in place policies and procedures and conduct best practice training for employees, so do get in touch if you would like our help with this.
New legislation
We will give you more details of the new data protection bill once it has passed into law. Its main aim is to reduce some of the red tape that the UK government feels has been put in place by the EU whilst ensuring that the protections are still deemed good enough to allow the free transfer of data between the UK and the EU.
If your current data protection programme is already up to date it is unlikely that these changes will be overly onerous for you. Some of the proposed changes, like the removal of first party cookies, which have proven problematic for many smaller businesses, will be welcome, and you may find opportunities to relax some of your procedures and gain a few operational efficiencies out of it.
It is worth keeping abreast of the changes and incorporating them into your programme.
How can we help?
We can help you establish a GDPR compliance programme that reassures both internal and external stakeholders and satisfies the regulator.
We would usually begin with a data protection audit so that we fully understand what data you hold, where it is and how it is used. Once we have this base understanding, we can produce a report identifying any gaps and recommending next steps.
We can update your policies and procedures and liaise with your team from the board down so everyone who handles data is aware of best practice and familiar with what to do if things go wrong. If you would like more information, please call us on 020 3056 8538 or send us an email.