The GDPR and its Principles

The GDPR has six principles on which it is based. The Data Protection Act of 2018 added a seventh: accountability. Being GDPR compliant doesn’t necessarily mean your business complies with the Data Protection Act of 2018. Let’s talk about the principles. There will be a short quiz at the end.

The Data Protection Act of 2018 - the 7 Principles of the GDPR
The GDPR has six principles on which it is based. The Data Protection of 2018 added a seventh: accountability.

GDPR Principles

  • One of the key principles of the GDPR is that you process personal data securely by means of ‘appropriate technical and organisational measures’ – this is the ‘security principle’.
  • Doing this requires you to consider things like risk analysis, organisational policies, and physical and technical measures.
  • You also have to take into account additional requirements about the security of your processing. This also applies to your data processors.
  • You can consider the state of the art and costs of implementation when deciding what measures to take. However, they must be appropriate both to your circumstances and the risk your processing poses.
  • Where appropriate, you should look to use measures such as pseudonymisation and encryption.
  • Your measures must ensure the ‘confidentiality, integrity and availability’ of your systems and services and the personal data you process within them.
  • The measures must also enable you to restore access and availability to personal data in a timely manner in the event of a physical or technical incident.
  • You also need to ensure that you have appropriate processes in place to test the effectiveness of your measures. Then you must undertake any required improvements.

So, that sounds very simple doesn’t it? er….

Let’s check what you have done so far….how may boxes can you tick? Don’t worry, we are not asking you to tick them but food for thought?

Here’s a Checklist

Have you undertaken an analysis of the risks presented by your processing? Will you then use this to assess the appropriate level of security we need to put in place?

When deciding what measures to implement, we take account of the state of the art and costs of implementation.

We have an information security policy (or equivalent) and take steps to make sure the policy is implemented.

Where necessary, we have additional policies and ensure that controls are in place to enforce them.

The business makes sure that we regularly review our information security policies and measures and, where necessary, improve them.

Basic technical controls are in place such as those specified by established frameworks like Cyber Essentials.

We understand that we may also need to put other technical measures in place depending on our circumstances and the type of personal data we process.

Our business uses encryption and/or pseudonymisation where it is appropriate to do so.

The company understands the requirements of confidentiality, integrity and availability for the personal data we process.

We make sure that we can restore access to personal data in the event of any incidents. This includes establishing an appropriate backup process.

Regular testing and reviews of our measures are carried out to ensure they remain effective, and act on the results of those tests where they highlight areas for improvement.

Where appropriate, we implement measures that adhere to an approved code of conduct.

We ensure that any data processor we use also implements appropriate technical and organisational measures.

Help is at Hand

So, if your blood pressure has remained as it was and your heart rate is ok, you can leave now. However, if not, call us now on 03333 22 1011. We are here to help you.