FREE GDPR Helpline
Call +44 (0) 208 133 2545
Companies must ensure that data is adequately protected to prevent loss or theft. Where a breach has taken place, companies may need to notify individuals as well as face negative impact on the company’s brand and customer loyalty. Under the General Data Protection Regulation, companies may face fines of up to €20 million or 4% of annual turnover.
It is possible to minimise the risk of data breaches by following a number of best practices:
Ensure software is updated and patched regularly to avoid weak spots for hackers to exploit.
Carry out vulnerability assessments to review and address any changes or new risks in data protection. Consider all aspects, such as data storage and remote access for employees, and ensure that policies and procedures are adequate.
Personal data should at least be encrypted, including on work laptops issued to staff. Instead of using backup tapes that can be lost or stolen, data can be backed up to remote services using the Internet.
Train staff to follow best practices, be aware of the importance of data security and how to avoid mistakes that could lead to breaches. Awareness of sensitive data and security should be a part of the company’s culture.
When working with other companies that may be handling your customers’ data, make sure they also have adequate systems in place to protect data.
Having a third party carry out a risk evaluation allows an objective and outside view of the current breach risks. A Data Security expert can advise on the best solutions specific to each company to reduce the risk of breach. This also demonstrates a serious intention to ensure data protection.
When the pub chain JD Wetherspoons recently announced that it had fixed its GDPR problem by deleting their customer data base, it caused a collective sigh of desperation amongst the
Updated ICO statement in response to Equifax cyber attack. Source: ICO.org.uk
One of the biggest points to note about the General Data Protection Regulation is the potential of massive fines. It is certainly an eye-opener. But how much will the first
Hot on the heels of the warning that TalkTalk would have faced a £70m fine had its 2015 data breach
The European Parliament’s official publication of the General Data Protection Regulation means it will become enforceable on 25 May 2018
We all know it’s coming, we just don’t know precisely what “it” is yet. The General Data Protection Regulation (“GDPR”)
Today the European Council approved its version of the General Data Protection Regulation (GDPR). The next stage is for the