GDPR overhauls the data protection rules across the EU in a manner designed to fit with the demands of the digital world. It strengthens individual rights and also places greater obligations on all those processing data of EU residents including researchers of all types and sizes.
The Regulation now applies directly without having to be implemented by statute and is enforced by the Information Commissioners Office.
1) Do you understand how your business uses data?
You need to conduct a data use and security. Can you map answers to the following questions:
2) How can you strengthen and design new policies and systems for GDPR compliance?
You need to make sure IT systems, staffing, policies and contracts are compliant with the new rights and responsibilities. Privacy policies need to be rewritten with additional information in Plain English. Some questions to think about are:
3) Can you prioritise and implement key remedial measures using a risk-based approach?
You need to identify issues that pose highest risk to business and take action to address these first. Use privacy impact assessments and think about:
4) Do you train your staff regularly on data protection?
Organisational culture needs to reflect the new approach in the GDPR and enshrine respect for privacy. Some things to think about are:
5) Has your organisation committed to best practice?
We have a simple way to help - Fair Data Accreditation. Contact us today and we can help guide you through the process.
The MRS Fair Data Accreditation is the only mark that allows companies to show best practice in data protection. It will take you most of the way towards GDPR compliance. Find out more.
Our newsletters cover the latest MRS events, policy updates and research news.