Does your business hold personal data about clients or customers? If so, then you need to start making preparations for the General Data Protection Regulation (GDPR) coming into force in May 2018. Noncompliance could result in your business being fined up to €10,000,000 (£8,7799,181) or 2% of your total worldwide annual turnover, whichever is higher.
What exactly is GDPR?
GDPR relates to data protection and many of the points contained in it are very similar to those in the current Data Protection Act (DPA). However, the three main issues highlighted by the GDPR are:- Data protection standards established
- Data breach notification requirements
- Security failures
What is Encryption?
Encryption encodes data and information so unauthorised parties cannot read it. This safeguards people’s personal information and protects it from unlawful processing and misuse. There are two types of encryption;- Encrypted storage which is used to protect disks, drives or devices.
- Encrypted content which applies to files or text, such as emails.
GDPR and Encryption
The GDPR expressly states that businesses must put in place processes to encrypt personal data and protect against data breaches. Under GDPR, if data is breached but this data was encrypted and rendered unusable then the business will not have to notify their clients of the breach. Encryption will not only protect your clients and customers data but it will also protect your business and ensure you comply with the GDPR regulations.GDPR Considerations
Whilst GDPR does not come into effect until May next year (2018), it is very important to start putting processes in place now to ensure compliance. The Information Commissioner’s Office has put together 12 steps you should be taking now to prepare for GDPR which look at:- Awareness
- Information you hold
- Communicating privacy information
- Individuals rights
- Subject access requests
- Lawful basis for processing personal data
- Consent
- Children
- Data breaches
- Data Protection by Design and Data Protection Impact Assessments
- Data Protection Officers
- International

