The Europe-wide General Data Protection Regulation (GDPR) came into effect in the UK on 25 May 2018. GDPR covers the capture, control and consent to use of personal information. It applies to any company operating in Europe, even if headquartered elsewhere. GDPR recognises how the internet has changed the quantity and security of personal data. It introduces new rights for consumers. Further, it sets new obligations for businesses in a more inter-connected age. We thought we’d remind you why GDPR is quite so important to your organisation. And, of course, how CAS can help you to stay GDPR-compliant.
Some key elements of GDPR include:
For more information about the GDPR, you can visit the website of the Information Commissioner’s Office (ICO) http://ico.org.uk, the UK’s data protection authority.
For many organisations in the UK, the GDPR might be simply seen as an expensive upgrade to previous legislation. It increases the onus for self-reporting, as it’s now an offence not to report a data breach which your organisation knows about. Indeed, in 2018, there were nearly 2,500 self-reported data breaches in the UK. But it’s not simply about increasing the cost of data protection compliance. For companies which manage and store data effectively, GDPR also represents an opportunity to understand their stakeholders’ needs better.
Even so, it’s vital that organisations protect personal data, or they will be pursued by the ICO. In 2018, the ICO imposed fines totalling £1.29 million to 11 UK firms for serious security failures of data protection. And they fined 11 charities over £130,000 for unlawfully processing data, mainly to do with consent over fundraising databases. But these fines were pursued under the older legislation, and the upper limit for fines has been raised under GDPR. Potential fines are now up to 4% of worldwide turnover or 20 million euros (whichever is higher).
Therefore cyber security more generally must be taken seriously across senior leadership in every organisation which collects personal information. The UK government’s National Cyber Security Centre (NCSC) has some useful advice in its ’10 Steps to Cyber Security’ https://www.ncsc.gov.uk/guidance/10-steps-cyber-security. And the NCSC’s Cyber Essentials scheme provides a benchmark for organisations to follow https://www.cyberessentials.ncsc.gov.uk.
Data protection is an area in which CAS prides itself, and we are fully compliant with the GDPR. We are registered with the Information Commissioner’s Office (ICO), registration number Z1281061. CAS identifies clients as data ‘owners’. We are a data ‘controller’ (according to the definitions outlined in the GDPR). CAS also acts as a data ‘processor’. However, this extends only to scanning documents and uploading scanned files to client-managed data banks on the secure and password protected CAS-Cloud.
CAS guarantees that data shall be processed lawfully, fairly and in a transparent manner. We will only process information in a manner that ensures appropriate security of the personal data. That includes protection against unauthorised or unlawful processing and accidental loss, destruction or damage. We use appropriate technical and organisational measures. The conditions for processing and the legal basis for scanning are defined by each client’s obligations around data retention and are covered in the contracts which we sign with our clients.
Our document shredding and IT equipment disposal services are also entirely compliant with the GDPR, as our clients remain data ‘controllers’ under the GDPR definitions. Again, we will always make this clear in any contract which we sign with clients who use these services.
If you’ve got questions about data security, give one of the CAS team a call today.
CAS provides a comprehensive and secure document digitisation, information storage and facilities management service. For more than 20 years CAS have worked with NHS Trusts, Financial Services providers, and corporate and private clients. Our head office is just four miles from the City of London. Supported by our advanced storage centres across the UK. CAS has an impressive array of International certifications (ISOs). These certifications prove our compliance with the strictest national, European and international laws. They also demonstrate our commitment to provide innovative systems on security, confidentiality and quality control. CAS offers archive storage solutions at its secure document storage facilities for companies of all sizes and across every sector.