This web site uses cookies. You are free to manage your cookie settings in your web browser at any time. For more about how we use cookies, please read our data privacy policy.

GDPR data protection regulation impact scope

GDPR data protection regulation impact on organisations

GDPR data protection regulation impact scope on organisations

by Jim Ashton | Oct 8, 2018

What is the impact of the GDPR data protection regulation on your organisation?

A friend and professional colleague of mine, Bruce Robertson, summed it up in one brief sentence.

"The impact is from post-room to board-room."

All of your business and support areas should be assessed to determine if the GDPR needs to be applied.

If you aren't sure whether you need to implement the GDPR, take our test. If it tells you that you do, come back to this article and read the rest of it.

GDPR impact scope highlights

All the personal data you receive, store, process and disclose to external entities must be governed by the GDPR.

Personal data entering and leaving your organisation on a regular and scheduled basis must be done under a GDPR compliant written agreement.

Personal data entering and leaving your organisation on an ad hoc basis must be recorded and actioned under separate GDPR requirements.

Personal data that is disclosed to any external entity outside the European Economic Area (EEA) can only be done if specific conditions are met.

You will also need to build a GDPR framework. The following list (in no particular order) shows some of the main policies, standards and procedures you will need to update or create.

  1. dealing with individuals' (data subjects) rights,
  2. maintaining records of processing activities,
  3. establishing GDPR roles, responsibilities, accountability and liability in agreements that involve the interchange of personal data between your organisation and external entities,
  4. keeping all agreements that involve the interchange of personal data GDPR compliant,
  5. auditing any companies you outsource to that process personal data you give them,
  6. ensuring that you respect the GDPR requirements if your organisation acts in the role of data processor,
  7. ensuring that all projects include data protection impact assessments (DPIAs) to make sure that they meet GDPR requirements,
  8. making sure that you respect the GDPR's transparency requirements when dealing with individuals,
  9. ensuring that you only collect the personal data you need and that you only keep it for as long as is necessary,
  10. fortifying both digital and physical security in line with risk,
  11. ensuring that all channels meet GDPR transparency requirements,
  12. analysing and reporting any suspected or real personal data breaches,
  13. establishing a data protection best practice,
  14. ensuring that all HR policies and contracts are GDPR compliant,
  15. preparing training material,
  16. training your staff on an ongoing basis and logging attendance and results,
  17. responding to requests from Supervisory Authorities,
  18. ensuring all parts of your organisation are properly registered with local data protection authorities,
  19. setting a risk appetite,
  20. risk recording,
  21. monitoring and reporting risk,
  22. building a GDPR audit and review capability,
  23. building a compliance review process to regularly check that everything is performing and if changes need to be made,
  24. creating GDPR framework governance and controls to embed all of the above in your organisation.

Whether you do these things yourself or get help is your choice but make no mistake, to provide the GDPR framework your organisations needs to protect everything from post-room to board-room is challenging and demanding.

GDPR SMEs has driven GDPR framework projects from the top down for small, medium and large organisations including multi-nationals. If you'd like to know more, give us a call!


 Share article

More articles: GDPR and personal data in the USA, Privacy Shield or Model Contract? | GDPR controller to processor contract considerations | Dealing with suspected personal data breaches under the GDPR | GDPR employee monitoring | Are you respecting your employees rights to privacy? | GDPR Human Resource consideration case study covering consent and rights | GDPR scaremongering | a few GDPR myths exposed | GDPR, what is personal data for European organisations? | Information security certifications and the GDPR | Am I OK with an ISO 27000? | How to set up a representative for the GDPR in the EU | When should you appoint a Data Protection Officer?