{"id":387,"date":"2018-05-14T00:00:00","date_gmt":"2018-05-14T00:00:00","guid":{"rendered":"http:\/\/www.interventure.info\/practical-steps-to-get-ready-for-gdpr\/"},"modified":"2020-05-14T14:32:56","modified_gmt":"2020-05-14T14:32:56","slug":"practical-steps-to-get-ready-for-gdpr","status":"publish","type":"post","link":"https:\/\/www.interventure.info\/blog\/practical-steps-to-get-ready-for-gdpr\/","title":{"rendered":"Practical steps to get ready for GDPR"},"content":{"rendered":"<p>The way in which businesses and governments store and make use of your <strong>personal information<\/strong> is about to change. At present, this is regulated by the <strong>Data Protection Act 1998<\/strong>, but it is clear to all that a piece of legislation implemented 20 years ago will no longer be fit-for-purpose, considering the vast developments in how we communicate and interact as a society.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-1603\" src=\"https:\/\/www.interventure.info\/wp-content\/uploads\/2018\/05\/gdpr-misstrauischer-blick-1200x800px.jpg\" alt=\"Mann schaut misstrauisch \u00fcber silbernen Laptop\" width=\"1200\" height=\"800\"><\/p>\n<p>On the <strong>25 May <\/strong>2018 this Act will be replaced by a new piece of legislation called the <strong>General Data Protection Regulation (GDPR)<\/strong>. This Europe wide data protection instrument will bring about a&nbsp;<a href=\"https:\/\/www.eugdpr.org\/key-changes.html\" target=\"_blank\" rel=\"noopener noreferrer\">number of changes<\/a> in how personal data is handled and will require many businesses to make changes to their processes and procedures to ensure compliance with the new law. Key practical steps for your business will include the following:<\/p>\n<h3>Assign a Data Protection Officer (DPO)<\/h3>\n<p style=\"padding-left: 30px;\">Depending on the size of your business \/ organisation, a designated DPO will need to be appointed, to be responsible for monitoring compliance (and liability) for GDPR<\/p>\n<h3>Educate<\/h3>\n<p style=\"padding-left: 30px;\">Any member of your team who handles personal data will need specific GDPR training. Within the software sector, for example, this might be someone who manages communications with new users, performs data entry or looks after the company CRM system. Customer communications and social media teams will also be heavily involved in this process<\/p>\n<h3>Data breaches<\/h3>\n<p style=\"padding-left: 30px;\">Companies will have to report breaches within 72 hours to the supervisory authority and describe in detail the possible consequences of the breach and how they will mitigate its negative effects<\/p>\n<h3>Audit<\/h3>\n<p style=\"padding-left: 30px;\">You must audit and maintain where personal data is stored within your organisation and with whom it is shared. For large businesses operating across multiple sectors, this is obviously a huge undertaking, with many companies now investing in Security Information and Event Management (SIEM) tools to make this process more efficient<\/p>\n<h3>Update<\/h3>\n<p style=\"padding-left: 30px;\">Companies must update policies and privacy notices to reflect the newly revised rights of individuals and to comply with GDPR\u2019s requirement for simple and concise privacy language across the board<\/p>\n<h3>Consent<\/h3>\n<p style=\"padding-left: 30px;\">For those organisations who need to seek customer \/ user consent for processing personal data, the ways in which your company seeks, records and manages consent may no longer be legally compliant and must be reviewed for GDPR implementation<\/p>\n<h3>Children<\/h3>\n<p style=\"padding-left: 30px;\">GDPR brings in special protection for children aged under 16 and requires companies to have robust strategies and systems for verifying age and \/ or ensuring guardian consent<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The way in which businesses and governments store and make use of your personal information is about to change. At present, this is regulated by the Data Protection Act 1998, but it is clear to all that a piece of legislation implemented 20 years ago will no longer be fit-for-purpose, considering the vast developments in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":388,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6],"tags":[],"class_list":["post-387","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nearshoring"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/posts\/387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/comments?post=387"}],"version-history":[{"count":0,"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/posts\/387\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/media\/388"}],"wp:attachment":[{"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/media?parent=387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/categories?post=387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.interventure.info\/de\/wp-json\/wp\/v2\/tags?post=387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}