Skip to main content

The New EU Data Protection Directive

With the coming into force of EU data protection legislation and the rising reputational and regulatory risks from data breaches, please see below a data compliance checklist, which we hope your organisation or business will find useful.
  1.  NOTIFICATION
    • Business registered with the Information Commissioner’s Office?
    • If registered, is entry up to date/relevant/wide enough to cover future uses?
  1. COMPLIANCE WITH DATA PROTECTION PRINCIPLES
    • What personal information is held and why
    • Is the information collected necessary for the purposes for which it is held?
    • How is accuracy of personal information checked?
    • How is information kept up to date?
    • How long is information held?
    • Where is information held?
      1. If on servers, where are servers based?
      2. Is the information secure?
    • What staff have access to the information and why?
    • Is the information disclosed to any third parties?
    • What details are provided when information is collected?
  1. POLICIES
    • Have staff been trained in data protection?
    • Data Retention Policy
    • Data Security Policy
    • Access to Information Policy
    • Subject Access Request Policy
  1. DATA PROTECTION OFFICER
  • Is there a named person/job title with responsibility for data protection?  (Not currently required, but likely to be a requirement when new EU legislation comes into force).
  1. RIGHTS OF DATA SUBJECTS
    • Procedures/guidance in place for dealing with a Subject Access Request?
    • Procedures/guidance in place for dealing with a section 10 Notice (request to delete data that may cause damage/distress)?
© Stone King LLP, October 2014
If you would like further information about the Regulations or if you have any concerns or queries in relation to them, please contact Vicki Bowles, Senior Associate or Brian Miller, solicitor and partner, IP/IT & Commercial.
Vicki Bowles is a barrister specialising in data protection and information management law and Brian Miller is a solicitor at Stone King LLP, providing specialist advice in the fields of intellectual property, IT, data protection and commercial law.
Disclaimer: This article may not be reproduced without the prior written permission of the author. This article reflects the current law and practice. It is general in nature, and does not purport in any way to be comprehensive or a substitute for specialist legal advice in individual circumstances.

Comments

Popular posts from this blog

Ten Questions to Ask Your Cloud Provider

The use of cloud computing is on an exponential rise, as it offers users almost unlimited storage of data, reduces the need for organisations to have physical servers and allows easy access to information from anywhere in the world. As such, many UK based organisations are now turning to cloud computing to satisfy their data storage needs. But there is one issue which seeks to bring grey clouds over an otherwise silver lining and that is data security . By using the cloud instead of a physical storage device, organisations are obliged to hand over data to a third party cloud provider, some or all of which might be personal data within the meaning of the Data Protection Act. An organisation must therefore be sure, before it enters into a contract with a cloud provider, that its information will be kept securely and the provider’s handling of data will be compliant with the Act and any other applicable laws. Before you embark upon acquiring a business which uses cloud computing o...

Jail Sentences for Data Protection Offenders

The House of Commons' Home Affairs Select Committee are encouraging the Home Secretary to introduce jail sentences as a possible punishment for data protection offenders. This is to act as a stronger deterrent than the current, quite ineffective fines.  It is generally unlawful for a person to "knowingly or recklessly without the consent of the data controller obtain or disclose personal data or the information contained in personal data, or procure the disclosure to another person of the information contained in personal data", under Section 55 of the Data Protection Act (DPA). But now, personal data has never been easier to access and the risks of information being leaked are an increasing concern. There are many new suppliers of information who are unlikely to understand or take notice of the rules to which they must comply. While the maximum fine for committing a section 55 offence is £5,000 when the case is heard in a Magistrates Court, and unlimited when ...

Data Leaks Prevalent Amongst Staff and Contractors

A twenty-five page report by security outfit Symantec has concluded that contractors and employees are the main cause for person data breaches in the UK. According to the report, thirty-six  firms in the UK covering eleven different industries has experienced data breaches during 2011 which resulted in a notification to the Information Commissioner. Apparently the data breaches were caused over a third of the time by " a negligent employee or contractor " whilst " system glitches " were responsible for another third of the instances. The glitches account for " a combination of both IT and business process failures ," the report said. Malicious or criminal attacks were the cause of the remaining one third of cases. Symantec expressed the view that the amount of information breached on average had fallen and that a larger number of customers were remaining loyal to companies that had lost data. " The average abnormal churn decreased from 3....