When the EU’s GDPR was announced, it was due to be enforced in the UK on 25 May 2018. Following last year’s ‘Brexit’ referendum the UK Government has confirmed that the UK will implement GDPR before the UK leaves the EU.

Furthermore, the GDPR will continue to be relevant for many organisations in the UK – most obviously those operating internationally.  So, as we will have to comply with the GDPR, it remains important to understand the implications of the GDPR.

According to the Information Commissioner’s Office :

“If you are currently subject to the DPA, it is likely that you will also be subject to the GDPR.”

This means that UK business will need to comply with various new features of the regulations, including breach notification and data portability.  Failing to comply with these provisions, could preclude you from dealing with EU-based customers and partners.

Another important change from the current Data Protection Act  is the new principle of Accountability. This requires you to demonstrate that you:

“comply with the (GDPR) principles and state explicitly that this is your responsibility.  This may include internal data protection policies such as staff training, internal audits of processing activities, and reviews of internal HR policies.”

Our Information Governance Compliance review service is an ideal place to assess your GDPR-readiness, and crucially, ensure that you can demonstrate compliance.

Contact us for a no-obligation assessment of your risk and readiness.