4 Years of GDPR

The GDPR has been part of UK law since 2108. What impact has it had, and where is there still work for UK based organisations to do? Overall there has been a significant step forward in the application of the GDPR principles. In the early says there was a lot of work done to comply with the GDPR. This was largely driven by the unfounded fears of large fines. However progress has slowed somewhat since 2018. Our experience is that there is more work do to to achieve compliance. Overall there are both positives and negatives in terms of how well personal data is being managed.

 

The GDPR

 

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Privacy by default and by design is not systematically applied

 

A key aim of the GDPR is to get organisations to factor personal data into planning and design activity. In sort, treat data much as they do money, people and other resources. Today still a lot of organisations think about GDPR compliance at the end of project, product or service design. For example when working with clients as Data Protection Officer we often got told about marketing activity a company had decided to do. But, we were asked to check if it was GDPR compliant after the decision had been made and the campaign designed. This can lead to a duplication of work if things need to be changed or processes redesigned.

 

In addition there is not as much thought as there should be, when starting any kind of data processing activity, about data security, limiting access, data deletion etc. and identifying learning / continuous improvement in terms of data privacy.

 

While this may read as a bit abstract, particularly as GDPR compliance is patchy and data breaches widespread, it is as if organisations were saying there is no point in designing and implementing financial controls as some level of fraud is inevitable. No successful organisation would dream of operating in that way.

 

Organisations are not fully abiding by the Principles of GDPR

 

What are the 7 principles of GDPR? They set out that data must be used:

 

  • lawfully, fairly and transparently
  • only for the purposes specified
  • only for a limited period
  • safely and securely
  • in the smallest amount possible
  • accurately

 

The GDPR also sets out that data processors are accountable for demonstrating compliance with these principles (the so-called accountability principle)

 

There are still major issues across all sectors for organisations in terms of:

 

  • disposing of personal data that they no longer need or use;
  • ensuring the personal data they have is accurate and up to date;
  • or only processing the minimum necessary data.

 

This will and does cause headaches for organisations.  when people exercise their data rights, or if there is a data breach. For example, in our experience, subject access requests are presenting a major problem for some organisations because of the sheer volume of information that they retain, unintentionally, in emails, archives and old electronic files. A viable programme of data audit and deletion based on a robust retention schedule would be enormously beneficial.

 

Organisations are (rightly) moving away from consent as a lawful basis

 

Many organisations defaulted in 2018 to consent as the lawful basis for data processing. Over time they have begun to understand that consent is just one of six lawful bases, and each of them are equal. There is now a greater appreciation that consent as a lawful basis has its limits and is only appropriate in limited circumstances. The GDPR meaning of lawful basis is much better understood, and organisations are getting more sophisticated in finding the right one.

 

Legitimate interests has in particular come to the fore as a lawful basis. This is partly because it is the most flexible lawful basis when others cannot be applied.

 

People are increasingly asserting their GDPR rights, but inconsistently

 

Many people know about the right of access – if you asked someone “what is a subject access request” they would probably be able to answer. We have a long-standing tradition of giving patient access to medical records, for example. More rarely people exercise their rights to data deletion (the “right to be forgotten”) or data rectification. We have seen limited evidence that people are exercising their other rights, such as in relation to profiling or automated decision making.

 

This may be in part because people are generally not aware of these rights. The right of access – what most will know as making a subject access request – is a long standing right. It has had much more time to embed in the pubic consciousness. However, without any kind of public information.

 

People and organisations are also not aware of how GDPR rights apply to or can be exercised by children.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

There is still a lack of awareness among both businesses or individuals

 

Under the GDPR people’s data processed for anything other that purely personal activity falls within the scope of the Data Protection Act 2018.

 

What is personal data? “Anything that by itself or in combination with other data could lead to a person being identified” is the GDPR definition. This is very broad. So, in short, who does GDPR apply to? Virtually all organisations in all sectors.

 

However, our own analysis suggests that there is a widespread lack of awareness about the need to abide by the rules. This is particularly true of new, small businesses founded over the last three years. To explore this we looked at 5,000 limited companies started in 2021. We found that less than 8% had paid the ICO (information commissioner) fee – despite not doing so if you need to being a criminal offence. Most had no, or fundamentally inadequate, privacy notices on their websites. Overall we estimate that c. 40% of organisations are significantly or wholly non-compliant with the GDPR,

 

In addition to comply organisations must take reasonable technical and organisational measures to ensure they meet the data privacy principles. Yes there are still basic mistakes that are easily avoided and lead to enforcement action by the ICO, such as this case involving an email sent CC instead of BCC, leading to a fine.

 

Even less attention payed to special categories of personal data, and the particular lawful bases and protections for processing data of this type. Special category data is sensitive. It relates to health, characteristics such as race or gender, or other data needing special care.

 

Lack of awareness is, we think, partly down to a failure to raise awareness of core tasks such as ICO registration, which most businesses need to have.

 

There are still references to the Data Protection Act 1998 around

 

The Data Protection Act 2018 replaced the 1998 Act. However even today there are still references to 1998 in documentation that we see, be it in the form of contracts, privacy statements on websites or marketing emails. For us this is a big red flag, as it shows that people are either unaware of the current legislation or haven’t made the effort to update their processes to take it into account.

 

Our advice is if you see a reference to the 1998 Act in any documentation you should challenge it. There is a big chance the organisation you are dealing with cannot be complaint with current rules. It won’t understand lawful basis, people rights and so on.

 

scales of justice

 

The ICO has had a huge burden to manage

 

For the ICO GDPR meant a step-change in their regulatory role. Our experience is that it has placed a major burden on the ICO’s resources. The ICO is also the regulator for the Privacy and Electronic Communications Regulations, and the Freedom of Information Act. GDPR is not the only thing they oversee. There is huge amount of enforcement action that the ICO undertakes. This is not limited to GDPR fines. They provide advice and support, reach out to businesses that aren’t on the ICO register, and so on.

 

This means that there is unlikely to be any new awareness campaigns or resources from the regulator. The ICO does an excellent job, with great resources on their website. Unless people and organisations become aware of the need to comply, or their rights they won’t do what they need to do.

 

GDPR at 4: Where We Are

 

Overall it looks as if the journey to GDPR compliance has slowed, if not stalled. This is for a number of reasons as set out above. This is unfortunate because the risks of not abiding by data protection legislation are real. Data being used improperly, or businesses seeing a competitive advantage in bending the rules are the risks people face in a regulatory environment that is reactive rather the proactive.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial