Data Privacy & Marketing
The General Data Protection Regulations (GDPR) were the most radical overhaul of data protection law in the UK for 20 years, and came into effect on 25 May 2018 alongside the Data Protection Act 2018.
Following Brexit, the UK is no longer a member of the European Union. Therefore, the UK GDPR was adopted to govern the processing of personal data within the UK and of UK residents; and the EU GDPR governs the processing of personal data within the EU or where a non-EU country processes the personal data of an EU resident. At the time of adoption the UK GDPR mirrors the EU GDPR, but the UK government has the ability to deviate in the future should it wish to do so.
The legislation places greater responsibility on the way businesses handle personal data and deals with issues such as consent, record keeping, data security & breach reporting and privacy notices.
It is comprehensive and applies to all organisations, regardless of size or the type of business they carry out. It is important to note that the scope of and general powers that data protection regulators have in ensuring organisations within their jurisdiction comply with the law (for the UK it is the Information Commissioners Office (ICO)), has increased substantially and that significant fines can be levied by the ICO. It is therefore vital for all organisations to be compliant.
However the legislation can be difficult to navigate, and involves looking at relationships with it’s employees, customers and suppliers (data mapping), the updating of Privacy Notices, and drafting Data Sharing/Data Processing Agreements. In addition, businesses that undertake marketing activities also need to be aware of their strict obligations under the Privacy and Electronic Communications Regulations which cover electronic marketing.
Data Protection Compliance
We regularly assist clients in relation to issues with compliance, information handling practices, and privacy matters (in the UK and internationally) including:
- Drafting and negotiating Data Processing/Data Sharing Agreements
- Data Protection Notices, compliance manuals and Privacy Policies (both internal and external)
- Data Breach Policies and relevant notification processes
- Opt-ins, opt-outs, cookies, marketing, targeted advertising and online profiling
- Data commercialisation within organisations – from the structuring of Commercial Agreements to domestic and global compliance procedures
- Compliance audits and implementation
- Responding to Data Subject Access Requests
- Freedom of Information Act (FOIA) issues
- Data breaches – including advising upon an organisation’s responsibilities and timescales for responding
- Bringing and defending claims under the GDPR and Data Protection Act 2018
Some sites which your organisation may find useful:
- The Information Commissioner’s Office
- The National Cyber Security Centre
- The responsibilities of a DPO
- Action we’ve taken | ICO
For more information about Blacks’ services, or for a free no obligation discussion, please email or call us today on 0113 207 0000.
