Does anyone have a clue about Data Protection?!

  • Post author:
  • Post category:Blog

As it’s “Data Protection Day”, I decided to write a blog about data protection (or data privacy if you’re in the U.S.). Data Protection Day started in 2007 in Europe, to “raise awareness and promote privacy and data protection best practices”, especially with such rapid technology changes all the time.

There’s hardly a person on the planet who won’t have heard of GDPR in the past year or so! It’s been everywhere! (I remember the week it came into play; I’ve never had so many emails asking me if I wanted to stay on mailing lists! It was almost comical!) Saying that, there are likely to be a lot less who actually understand it.

I’ll be honest. When it first came into the headlines I had very little interest. As a stay at home mum, it really didn’t seem to apply to me. Of course now, as a VA, I’ve had to make sure I not only understand it, but that my business is compliant. As a sole trader I’m just as responsible for making sure I have things in place, as someone who runs a huge company. Not just for myself, but for my clients too.

So, what is data protection, and how does it apply to you whether you own a business, are employed by a business, or just on a personal level?

Data protection is the protection of an individual’s personal data – i.e. name, address, email etc. and sensitive personal data like genetics, religion, political stance, sexual orientation etc. Basically, any information which can be used to identify a person.

GDPR came into play in May last year as a way to monitor how businesses process and handle this data. Although GDPR is a law brought in by the EU, if you are in the UK and concerned about how Brexit might change things, you are still covered by the new data protection act, which was brought in in the UK just before GDPR was and is largely the same, so still applies to you. (For in depth information about the UK data protection act, check out this link http://www.legislation.gov.uk/ukpga/2018/12/contents/enacted)

As a business, the basics you need to know for any personal data you hold for clients/customers etc. are reasonably simple. You need to be able to show the type of data you hold, how you got it, why you hold it, how long you have and will keep it for, if you share it with others, and (if you work in or with a medical organisation) if the information is in the special (sensitive personal data) category. Also, where it is stored and the security of the data is very important too. (Check out the ICO – Information Commissioners Office – website for an in-depth description of GDPR – https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/ – they also have a questionnaire that can tell you if your business needs to register with the ICO.)

If your business has a website, you must have a privacy policy on your website stating how you use data collected through your website, and also give people the option to opt in and out of using cookies.

On an individual level, GDPR or the UK equivalent has boosted your rights as an individual when it comes to how your personal data is used. You have the option of withdrawing consent at any time, you can ask to access your data held by specific organisations at any time for free (SAR – Subject Access Request) and it basically reminds you of the importance of protecting your privacy online.

When it comes to personal privacy, it amazes me how little some people seem to worry about their personal information, but I feel that subject may open a can of worms so may be for another blog at a later date!

I’m not professing to be an expert in this area, in fact in a lot of senses, being new to business, I am still learning*, but I wanted to share what information I do know, in case you are just starting out or just haven’t realised what’s applicable to you, and need a shove in the right direction.

Don’t put your head in the sand. It’s just not worth it!

As a VA, if you run a small business and feel overwhelmed by GDPR, I would be happy to come alongside you and support your business as you put things in place. Just get in touch using the contact links.

For other articles about GDPR and how it applies to you if you’re a VA check out the links below.

https://www.thevahandbook.com/va-data-protection/

https://www.vact.co.uk/guest-blog-lesley-cooley-ten-things-vas-need-know-general-data-protection-regulation-gdpr/

*All information in this blog is from my personal perspective, and is as correct to my knowledge as possible, at the time of writing. For official information about these laws and policies, please use the links within the article.