Although the UK subsequently voted to leave the EU, the UK government has since confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect from 25th May 2018.
What is the General Data Protection Regulation (GDPR)?
The General Data Protection Regulation (GDPR) is a new legal framework to be applied within the EU. It is principally designed to cover all those businesses which have day-to-day responsibility for personal data. The aim is to achieve uniformity in data protection legislation across the EU thereby streamlining data exchange and security between member states.
Although GDPR is complex, its key stipulations are clear:
- Firms of a certain size (over 250 employees) must employ a Data Protection Officer (DPO). This person ensures that a business collects and secures personal data responsibly.
- Any breaches in data security must be reported to data protection authorities such as the Information Commissioner’s Office (ICO) in the UK. Breaches must be reported within 24 hours if possible but certainly within 72 hours.
- Individuals have more rights dictating how businesses use their personal data. In particular, they have the ‘right to be forgotten’ if they either withdraw their consent to the use of their personal data or if keeping that data is no longer required.
- Any failure to comply with the GDPR will lead to heavier punishments than before. Under current rules, the UK’s Information Commissioner’s Office (ICO) can fine up to £500,000 for malpractice but the GDPR will be able to fine up to €20 million or 4% of annual turnover (whichever is higher).
The criteria has been designed to ensure that businesses are doing enough to secure the personal data of their clients. It is possible that many companies already fulfil their obligations under the GDPR, especially if those companies already comply with the UK’s Data Protection Act (DPA) of 1998.
How the General Data Protection Regulation (GDPR) will affect small employers.
The General Data Protection Regulation (GDPR) will apply to organisations of all sizes. The reason for this is that, even where an organisation employs only a few people, it would still be processing a large amount of data in the course of business and the consequences of non-compliance with the GDPR could be significant.
The GDPR requires organisations to take measures, into account of the nature, scope, context and purposes of processing data, as well as the likely risks to the rights of individuals. Further, supervisory authorities will be required to ensure that any fines are effective, proportionate and dissuasive. Therefore, it is less likely that the supervisory authority will focus its attention on organisations that do not process a large amount of personal data and are not involved in higher risk processing. Further, those organisations would not be expected to commit as many resources to GDPR compliance as higher risk organisations would.
There is a limited exemption for organisations with fewer than 250 employees in relation to record-keeping requirements, but employers should be aware that this is only a narrow exemption and that the other requirements and principles of the GDPR apply regardless of the organisation’s size.
Organisations with less than 250 employees must retain a record of their processing activity if they are processing data which;
- Could result in a risk to the rights and freedoms of data subjects.
- Part of special categories of data (sensitive personal data).
- Any personal data relating to criminal convictions and offences.
The GDPR will come into effect on 25th May 2018.
For further guidance or information on GDPR and how this will affect your business. Please contact Sally Phillips 01932 830664 or sally.phillips@wardwilliams.co.uk.

