As experts in data protection, privacy and the GDPR, we wanted to share our knowledge with you to ensure your compliance journey is as simple as possible. With a clear understanding, data protection best practice will become a natural part of your organisation’s way of working - a benefit to you and your business.
So take a look over our GDPR and data protection resources below.
How to map your data flows
“Data flows”. Sounds like a job for someone in IT right? Wrong! Creating accurate maps of your data flows is an essential building block of any data protection compliance programme. Don’t get this bit wrong. If you do, everything else will be wrong as well. Time spent on getting this right will save you time over and over again as you build out your programme. Let us give you some pointers.
The Privacy Guy – Privacy Promise 8 – Privacy by design & by default
As everyone that has read his thoughts and watched his videos knows, The Privacy Guy is one seriously cultured individual. Without culture he would be nothing. He’d be an empty shell of a man. A man in an ill fitting grey suit with a clipboard, ticking boxes and shouting, “Computer says no!”. In short, he would be an unsuccessful man.
For a long time organisations have been very generous with their cookies. Website and app owners have been setting cookies on our devices, often without us even realising. But most cookies require the device user’s prior consent otherwise they are unlawful. Read on to find out when you need consent to set cookies and when you don’t.
The Privacy Guy – Privacy Promise 7 – International
The rules in relation to personal data are different from country to country. This has the potential to make the lives of some companies complicated. Which rules apply? How can we make compliance easier? How can we make sure that personal information is protected, wherever it travels? What if the way we process personal information is right in one country, but wrong in another?
The age of consent
What is the biggest myth touted about the GDPR? It is, “If you want to use personal information you must have consent”. Why is this a myth? Because what you need is a lawful basis for processing personal information, not consent. Consent is just one of the six lawful bases available under the GDPR.
The Privacy Guy – Promise 6 – Security
You’ve got to keep personal information safe they say. What does that mean? How safe do you have to keep it? And how do I check whether it is safe enough? All good questions. But, you won’t find the answers in the GDPR, or any other data protection legislation. What you need is a little help from real data protection experts like The Privacy Guy.
Am I a controller, a processor, or both?
Controllers of personal information are the ones with all the liability under the GDPR, right? Wrong. Processors have obligations under the GDPR too. And then there’s joint controllers as well. They are jointly liable to people who have suffered damage because of a GDPR breach. To confuse matters further, an organisation can be both a controller and a processor at the same time (although not in relation to the same processing activity).
The Privacy Guy – Privacy Promise 5 – Rights of Individuals
You’ve got to fight……… for your right………to privacy. Well, not any more. The GDPR has given individuals plenty of rights which they can exercise quickly and easily. Satisfying those rights is the tricky, time consuming part.
How to send marketing emails under the GDPR
Do you remember where you were during the great avalanche of May 2018? Piles of emails swamped inboxes across a vast area covering the UK and the EU. In the run up to the GDPR, these emails requested consent to send further emails to their recipients after 25 May 2018. Some were necessary, but a large proportion of them were not. The avalanche was borne of confusion about the GDPR and fear of fines. Even now confusion remains. Read on to find out when you need consent to send marketing emails and when you don’t.