The dangers of a GDPR breach
Businesses must issue notifications of valid data breaches to the "local supervisory authority" within 72 hours of becoming aware of them.
Failing to report a breach can result in an investigation and/or penalty. Individuals also have the option to file a class action lawsuit if a business does not comply with GDPR.
The legislation applies to every business large and small in the UK - there will be no exceptions for small businesses.
Data breach plan of action
There is a mandatory breach reporting requirement, where employers must report certain types of breaches to the data protection authority. A personal breach occurs where a business’s security systems have been compromised leading to the "accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data".
A business must determine the level of the breach’s severity and the risk it could present to an individual’s rights and freedoms. If it is considered a risk then you must notify the Information Commissioner's Office (ICO). If there is no risk then you do not have to report it.
However, businesses who do not report a breach should keep a record and be able to justify their reasoning behind their decision not to report it and document those reasons.
Make sure you have suitable procedures in place to notify the regulator where breaches have been reported and identified. Inform all staff of the correct procedure to follow should a breach occur.
Check with your IT team or staff to ensure your computer systems allow for your employees to securely delete and manage personal data in line with the GDPR legislation.
Non-compliance and penalties
The ICO will take non-compliance very seriously with significant fines and penalties in place for businesses who breach the GDPR legislation. Fines will be incurred of €20 million or 4 per cent of a business’s turnover, whichever is the greater amount.
The level of fine being imposed will depend on the type of breach that a business has committed. The fines are designed to punish any business that wilfully ignores their GDPR obligations after the May deadline.
However, fines can be mitigated against if there is evidence that shows that a business has prepared and worked towards GDPR compliance.
GDPR Free Guide
What you need to know about consent, emailing payslips, and your legal obligation
Businesses are legally obliged to protect payroll information on behalf of their clients/employees. The guide will uncover the ins and outs of the impact of GDPR on your payroll processing, highlighting the biggest areas of concern including emailing payslips, employee consent and your legal obligation.
Brightpay will be exhibiting at Accountex on May 23-24 at ExCel in London, on Stand 430.

