Accountability and the GDPR

The GDPR (General Data Protection Regulation) outlines seven key principles relating to the processing of personal data.

The principles are:

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality
  7. Accountability

What does ‘accountability’ mean under the GDPR?

The GDPR states in Article 5(2) that data controllers must be able to demonstrate compliance with the other six principles. There isn’t a formal definition for ‘accountability’, its meaning is clear:

You must be able to prove you are compliant.

Accountability means being able to show your personal data processing activities are secure and GDPR compliant.

Are your measures effective?

Most organisations tend to implement measures and then forget about them.

But you implement a control to mitigate a risk and then bring it down to an acceptable level.

You can’t, however, stop there.

First, confirm that the control is effective:

  • Did you implement it correctly, or does it require fine-tuning to get the result you want? Check that your money (and time) were well spent.
  • Was the control the best risk treatment option you had? Don’t forget, as with many aspects in business, you make decisions based on your best guess only. There’s no shame in finding out you’re wrong, but that’s no excuse for staying wrong.

Second, risks aren’t static – especially in a world where digital information is prevalent. Cyber threats and vulnerabilities are constantly changing, and therefore risks change with them.

Your business will change, too. You will modify the way you do things. For example, you might introduce a new system or change the way you conduct a certain activity.

In short, a measure that’s effective today may not be effective tomorrow.

Why do we need accountability under the GDPR?

The above is why accountability under the GDPR is so important.

It transforms GDPR compliance from a box-ticking exercise into a catalyst to improve the way you operate as a business. It means you’re:

  • Managing your risks better – not just to your data subjects (customers, employees, etc.), but also to your organisation;
  • Keeping track of what data you’re collecting and why, and destroying data you’re not using or no longer need; and
  • Making your processes more efficient and have more confidence in your data.

It’s the difference between creating a ROPA (Record of Processing Activities) as a one-off exercise, and turning that ROPA into a type of asset register of true business value to your organisation.

The accountability principle entails these types of differences.

Help is at Hand

If you are concerned about your accountability then why not get in touch and let’s take a look at where you are currently. Your initial call is free, so why not book a slot here.

Or, you can call us on 03333 22 1011.