
People are working hard to protect your personal information.
Is your website GDPR compliant 2018? The EU General Data Protection Regulation (GDPR) came into force on 25th May 2018 and replaces the current Data Protection Act (1998). It aims to give individuals more control over their personal data and peace of mind that companies are taking better care of it.
With the many recent high-profile security breaches and data abuse stories in the media, it’s not surprising that 60 percent of consumers give false information when submitting data on the web (according to research agency Verve).

GDPR need not be as complex as it sounds.
Gone are the Wild West days of the world wide web where companies can harvest emails and personal information for marketing and profitable gains. There will now be stiff penalties for those that break the rules. So where do you stand with your website?
Who does GDPR apply to?
GDPR apples to any business of any kind within the European Union that handles personal data. This data includes information as basic as names, addresses, telephone numbers and IP addresses belonging to anyone including suppliers.
Where to start with GDPR and your website.
GDPR apples to any business of any kind within the European Union that handles personal data. This data includes information as basic as names, addresses, telephone numbers and IP addresses belonging to anyone including suppliers.
Website security – do you have an SSL certificate?
How you handle data that comes into your website via online forms needs to be secure to stop the personal information collected getting into the wrong hands. An SSL Certificate is a way to make information sent between your website and your server unreadable to anyone except the to which server you are sending it.
Privacy policies – every website should have one.
Any business that handles personal information should have a Privacy Policy. Yes, writing it is a big headache and will take a lot of research. However, it will serve you in the long term. Firstly, it lets customers know that you have concern and respect for their personal information. It is also a great way to make you focus on the various privacy aspects of your company and tighten up your security levels. Visit the Information Commissioner’s Office (ICO) for a full list of recommendations.
Permissions
When it comes to online forms and any method of getting personal information from people, it’s essential that you have their consent to do so. Gone are the days of getting a pile of business cards from a networking event, then adding the details to your marketing database.
People now have to know transparently what data you have, what you intend to use it for and how long you want to keep it. Hidden tick boxes are no longer allowed, and privacy notices need to be clear, not hidden in the small print.
It’s important to file any permissions that you have because you must be able to provide proof that you have consent to use any personal information, should you be asked to provide it. So, make sure your paperwork is up to date. If it isn’t, it’s time to ask your clients to sign new consent forms.

Do you know what personal data you have on file?
Lastly, people have a right to know at any time what information you have about them, so you need to know how and where to access that information.
They also have ‘a right to be forgotten’- in other words, you should be able to, and are legally required to, remove all information about them from your files at any time, should they ask you to do so.
Good housekeeping is essential; dusty old forgotten databases are a thing of the past. Files need to be regularly reviewed so that only relevant information is stored.
Is your data storage secure?
You have your SSL certificate to keep any data you have secure online, but you also need to make sure that the information is stored securely on your computer and within your paper filing system. Encryption, complex passwords and lock and key are all good ways to keep data secure. Also, the information should be restricted, so that only the people that need to see it have access.
There have been many cases in the news of lost or stolen devices that have contained databases full of personal information. Special care should be taken to protect personal information should the worst happen. If your laptop or mobile phone is stolen, is the information suitably encrypted or password protected?

Are your data security practises watertight?
Lastly, any business that handles data of a personal nature should register with ICO via their website. Click here to check whether you need to register.
Prices start at around £35 per year. Any data security breaches that do happen must be reported to the ICO within 72 hours.







