Is GDPR still a thing?

In 2017 the noise about GDPR was starting to circulate but it wasn't until the start of 2018 that people started to take notice and even start to panic a little. I personally trained literally hundreds of people about GDPR.

Fast forward to late 2021 and where are we at? Having spent the last few years doing GDPR consultancy I have seen it all.

The truth is the majority did somewhere between the bare minimum and nothing at all. To be fair there was a huge amount of scaremongering during 2018 but it still does not change the fact that every business of all sizes needed to ensure compliance.

Why?

Many simply believed and still think that it does not apply to them. The truth is it applies to every kind of one-man band, small business, charity, club, church and more.

I also believe many may think they are compliant because they have added a generic privacy policy to their website and registered with the ICO, which is a start but doesn't mean you are compliant.

What does being GDPR compliant look like?

There are two key elements to being compliant, documenting how you manage, protect, process and share personal data and more importantly doing what you say you do in practice. It is not good enough just having perfect documentation and not actually do those things.

Has GDPR changed in the last 3 years?

Not really no, however as of December 2020 the UK changed from having to comply with the EU version of GDPR to a new version called UK GDPR. This still has the same requirements as the EU version. Late in 2021, the UK government has proposed some minor changes since leaving the EU but the proposed changes still are still in review mode and actually very close to the current standards of GDPR and will need to remain so to ensure we retain our current status as a third country.

What does this mean for you?

Nothing right now and even if the proposed changes are made it will not be for a long time yet and it still requires exactly the same as it did before in terms of data protection.

Today you are still required to be compliant and that is not going to change anytime soon.

Why should I bother now?

If you feel that you have got this far and it has not impacted you or you have not been fined so why bother, then you are lucky. Thousands of companies of all sizes have been fined for either falling foul of GDPR or for doing nothing. Many of my clients came as a result of them receiving a letter from the ICO asking them why they have not registered with them confirming that they will protect their client's data and comply with the GDPR.

More importantly, it's the right thing to do. Protecting your clients, employees and suppliers data is what we should be doing anyway and most likely what you are already doing, you just have not documented it?

Is GDPR compliance hard?

Ensuring compliance in your organisation depends on many factors, a very small business or church all could potentially process very different amounts of personal data and potentially with more risk which would require more documentation.

The truth is you can get all the information you need from the ICO website and if you have the time you can learn all about the requirements. If time is something you don't have then that's where someone like me can help you with my GDPR documentation service.

Privacy Policy
Cookie Policy
Terms and Conditions
FOLLOW
ME