GDPR – Are you ready for the changes?

Here are some key steps that organisations should be preparing for;
1. Managing your data
2. Data breach notification
3. User Access
Organisations need to ensure that their Privacy Policy is clear and that processes are in place to respond to requests from individuals, such as, “What information is held” and “Remove all information about me.” Another key change will be that users have a right to access their own personal data and can make access requests to check the data held on them at any time. This means organisations should plan in advance as to how they will handle requests.
4. Opt in v Opt Out
The changes coming into effect with GDPR means that those areas that have pre-ticked boxes giving consent won’t be acceptable. The new regulation will state that pre-ticked boxes and ‘silence’ will not mean consent has been given to use their data and consent will still be required by law to send an SMS or marketing email to an individual.
5. Accountability and Governance
Although most organisations will already have good governance in place, GDPR will increase the requirements for transparency and accountability. Organisations are expected to have the necessary governance in place for privacy which ultimately, should reduce the risk of data breaches and protect the use of personal data. This is something that should have all been reviewed by now as part of the GDPR compliance work that needed to be carried out by all organisations so they are ready for the change by the 25th May 2018.