Data Protection Part 2: What You Need To Do
Topic Menu
Topic Menu
Quick Links
Welcome.
This is the second short training video produced by Support Cambridgeshire in a series on data protection. In this one, we’ll be looking in particular at the key steps you should take to comply with data protection law.
But first, here is a very short recap on what we covered in video one.
Video one highlighted the seven principles of data protection that underpin the law. One of these is that you must have a lawful reason to carry out your processing. There are six lawful reasons, including consent, entering into a contract and legitimate interest. We ended the first video explaining that individuals have a range of legal rights, including the right to be informed and to have access to the data you hold on them.
With these things in mind, what are we going to cover in this video? Firstly, we’ll begin with what you’re allowed to do with other people’s personal data. Then we’ll look at what steps you must take to comply with the law and so meet your legal duties. This will include looking at data audits, privacy notices, data protection policies, and staying accountable. Finally, we’ll finish with a look at the vital subject of data security.
Other people’s personal data
Let’s look at what you’re allowed to do with personal data. The answer may surprise you. If you stick to certain requirements, in other words, the data protection principles and respecting an individual’s data protection rights, you can do almost anything with someone’s personal data.
This includes processing their data without consent, because consent is just one of six legal reasons for processing data. Profile someone and target specific individuals. Share data, including that of a personal nature such as to do with health, criminal records or a protected characteristic. Sell data, refuse someone a job or even prescribe someone (in other words, bar or prohibit someone from something).
Remember, though, the data protection principles are strict, and they include having a legal reason for processing data and only processing data for the purpose it is collected.
Complying with the law
This looks at what you must do as an organisation to comply with the law.
The place to start is with a data audit. To make sure you comply with the law, you first need to understand all the different types of data you are collecting. So carry out a data audit to find out what is collected, how, why and when you do this. Also, look at what you actually do with the data, including who, if anyone, it is shared with and how it is stored.
The importance of auditing your processing operations cannot be understated because it will inform your future data processing arrangements. For example, the audit allows you to decide the legal reason for each of your processing operations and to identify any associated privacy risks.
Once the audit is complete, you can also use it to produce a privacy notice. This is used to tell people whose data you are processing, why you need their data, and what you’re doing with it. In this way, you’ll be meeting an individual’s right to be informed.
Your privacy notice must include certain required information as set out by the Information Commissioner’s Office, the Data Protection Regulator. One of these is the lawful reasons by which you are processing data, but others include how your data is stored and who has overall responsibility for data protection in the organisation. Privacy information must also be made available at the time data is collected. You will need to think about your data collection methods and how your privacy notice can be made available to individuals. Again, your data audit should help with this.
Given the importance of privacy notices, we have devoted the third video of our data protection series to this topic. Please view the video to find out how you write a privacy notice for the data you process.
General data protection policy
Alongside your privacy notice, you also need to have a general data protection policy.
This will explain how you meet other aspects of data protection law and good practice. It’s all about showing that you are accountable, trustworthy, and transparent.
So what does a data protection policy look like? It should start by setting out your commitment to protecting privacy and the levels of responsibility for data protection within your organisation. This includes stating who is in overall charge of data processing. It should then go on to cover all your arrangements for compliance with the law. The arrangements should cover things like your data processing audit, your data security, your data sharing arrangements, and clear procedures for dealing with data breaches, requests, or complaints connected to individual rights.
To help you develop a suitable policy, a template is available from Support Cambridgeshire. In addition, the NCVO have produced some guidelines for writing a data protection policy, and the link to the relevant page on their website cab be found in the guidance links below.
You need to account for your actions when you process personal data and show that you are complying with the law. Indeed, this is one of the seven principles of data protection. Keep good records, make sure your data protection policy is fit for purpose, and that the arrangements it describes are working properly. Make sure your team is fully trained on how to process data securely and that they know how to recognise cyber attacks like phishing.
As I explained in the first video of this series, consent, when used as a lawful reason for processing, must be given freely and it must be possible to withdraw the consent at any time, something that must be made clear when consent is given. When it comes to email marketing circulars and e-newsletters, obtaining consent is the only legal route you have.
Indeed, an individual must consent to be placed on the marketing mailing list, and they must be able to withdraw that consent at any time. This means including an “unsubscribe” notice, or preferably an “unsubscribe” button on every email or newsletter.
However, an upcoming change in the law will allow charities and voluntary groups to apply what is called the soft opt-in in certain circumstances. This means that direct consent will not necessarily be required. More information can be found in the guidance links below.
Data security
Keeping your data safe, both physically and electronically, is absolutely essential, so you must train your staff and/or volunteers in data security. In fact, you can be fined quite heavily if you fail to protect your data from hackers and thieves, even though you, as an organisation, will have been the victim of a crime.
So make sure that you: one, control access to data who and where with robust passwords and two-factor authentication of users. Two, regularly back up your data. Three, ensure physical security… The doors, locks, lighting, CCTV, etc. Four, ensure safe disposal of data waste. Five, control the use of laptops and other mobile devices with encryption, passwords, antivirus software, etc. Six, keep software and operating systems up to date. And seven, develop a cyber incident plan so you are ready to deal with any problems if they arise.
Summary
Okay, we’re almost at the end of this video, so let me sum up.
As long as you have a lawful reason for your processing and can meet all the other data processing principles, then you can process data for all sorts of reasons. But to stay within these principles, you must comply with the law. To do this, you need to know what data you are processing and why, and what exactly you will do with it.
This is where a data audit helps. You should also have policies and procedures setting out who is responsible for what aspects of data protection and the different arrangements you have in place for legal compliance. Key among these is the need to provide privacy information at the time data is collected.
So use the videos and other resources from Support Cambridgeshire and then complete a data audit. Do this and you’ll find that data protection compliance becomes straightforward.
For further information, please refer to the Information Commission’s website and see guidance links below for information on: key data protection terms, who needs to register with the Information Commission’s office, dealing with freedom of information and subject access requests, and the soft opt-in for sending out marketing emails.
That is the end of this video, so thank you for watching..
Guidance Links:
Who needs to register with the ICO
Guidance on direct marketing using electronic mail
Writing a data protection policy and procedures
Guidance on AI and data protection