How to avoid death by data protection!

They are the letters that concern anyone whose work, rest or play involves computers and information. Let's face it, that's most of us these days, especially in the field of accountancy (and I'm not talking about MTD!)  They are G.D.P.R.  And they are the general data protection regulations that come in play on 25 May 2018.

This area's anything but as dry and boring as it sounds. Controversy and confusion abound. So here's part one of Accounting Insight News's no-nonsense, hype-free guide through the GDPR maze: (But first a word of warning.... it's a guide, not legal gospel!)

The amount of digital info has increased rapidly and massively over the past 20 years. Existing rules governing how businesses and public organisations handle, process and generally look after this information were not up to the task in our new, more tech-drenched landscape.

Europe's new framework for data protection

So something had to give, rather like the guy who used to walk in front of the motorised vehicle waving a red flag to warn fellow road users. In a nutshell, the 1995 data protection directive (man with red flag) is being replaced by GDPR, Europe's new framework for data protection. We're entering the age of data brakes and traffic lights!

Oh, and, before we go down the Brexit road, the UK is introducing the data protection bill, which basically takes on board GDPR regardless of EU matters.

The regulations will be enforced in the UK by the Information Commissioner's Office, which is based in Cheshire and headed by Elizabeth Denham, who was appointed for a five-year term in 2016. Her job is to "increase the UK public's trust and confidence in what happens to their personal data".

Elizabeth Denham

 

Included in the GDPR legal package are:

  • Fines for non-compliance with the regulations.
  • Improved measures for data handling.
  • Better rights for people wanting to get hold of the info that groups hold about them.
  • Clear responsibility for organisations to obtain the consent of the people whose info they are using.

The nitty-gritty of GDPR

The ICO says that if you're presently subject to data protection laws then you'll also be subject to GDPR.

How you're affected by the law depends on whether you're a processor or controller of information. A "controller" decides how data is used, such as, say, for a marketing campaign or a sales pitch. The term "processor " covers everything else. That is you obtain, adapt and hold data on file or in the cloud but you don't call the shots.

Next up is personal and sensitive data. Personal means any info that can be used to ID a person, such as name or IP address. Sensitive means data that reveal things like sexual orientation, political views, medical history and the like.

As you would expect, most big data-driven companies are up to speed with GDPR. They've probably already complied with the requirement to employ a data protection officer, for instance.

But there are lots of smaller companies out there - accountants among them -  that control and process a lot of personal and sensitive data. And they need to be smart. Simply, they need to make sure they know what data they have... on clients, for instance. They need to make sure they've got permission to use it in the way that they are. And they need to make sure its secure.

More GDPR legal stuff to be aware of...

Data breaches - destruction, loss, unauthorised disclosure - have to be reported to the ICO within three days of a hack. The breach has to be likely to affect people's rights or freedoms. So the conditions for reporting involve areas such as financial loss and confidentiality

Groups with 250-plus workers must set out why people's personal and sensitive info is being collected and processed.

And, in certain situations, firms must get consent to use a person's details. This process has to be explained clearly and there has to be a "positive opt-in" from the person being asked to do something.

GDPR gives people more power to get hold of information about themselves. And they won't have to pay for the privilege, as they do now. The business will also have to provide the details within a month. In most cases, people will have the right to an explanation of a decision that is made about them based on use of their data. They will also be able demand the deletion of personal info that is no longer required for the purpose it was collected.

Now for the really controversial bits of GDPR

In a word. Fines. If you don't process someone's data as per GDPR (and you get shopped or found out), then you could be fined. Heftily. The same goes for a data security breach going unreported.

The ICO has the power to dish out financial penalties of up to €10m or 2% of a firm's global turnover (whichever's bigger) for smaller offences. That figure goes up to €20m or 4% for more serious matters. That figure used to be £500,000.

Some words of wisdom and reassurance from the ICO

GDPR has resulted in a lot of scaremongering and the profiteers of doom have been out in good number. Denham has responded to some of the critics thus:

On fines:  "This law is not about fines. It’s about putting the consumer and citizen first. We can’t lose sight of that. Focusing on big fines makes for great headlines, but thinking that GDPR is about crippling financial punishment misses the point. The ICO’s commitment to guiding, advising and educating organisations about how to comply with the law will not change under the GDPR. We have always preferred the carrot to the stick."

On consent: "For processing to be lawful under the GDPR, you need to identify a lawful basis before you start. Local authorities processing council tax information, banks sharing data for fraud protection purposes, insurance companies processing claims information. Each one of these examples uses a different lawful basis for processing personal information that isn’t consent. The new law provides five other ways of processing data that may be more appropriate than consent."

On GDPR in general: "GDPR is an evolutionary process for organisations – 25 May is the date the legislation takes effect but no business stands still. You will be expected to continue to identify and address emerging privacy and security risks in the weeks, months and years beyond May 2018. That said, there will be no ‘grace’ period – there has been two years to prepare and we will be regulating from this date."

Another thing is certain. We will be returning to this topic.