Simple Explanation of Data Protection, GDPR and Privacy Policy

UK Data Protection Act (DPA) has been updated by the European GDPR (General Data Protection Regulation) Law design to modernise and harmonise personal data privacy laws across Europe. Reading guidance on this legislation can be quite a challenge so basically:

Does Data Protection Apply to you?

If you have information about people for any business or other non-household purpose you need to comply. The law applies to any ‘processing of personal data’, and will catch most businesses and organisations, whatever their size.

If your business stores or uses personal information you must make sure the information is kept secure, accurate and up to date.

This could include:

  • keeping customers’ contact details and addresses on file
  • giving delivery information to a delivery company

Your Data Protection obligations:

Data protection is about the fair and proper use of information about people. It’s about treating people fairly and openly, recognising their right to have control over their own identity and their interactions with others.

When you collect someone’s personal data you must tell them who you are and how you’ll use their information, including if it’s being shared with other organisations.

You must also tell them that they have the right to:

  • see any information you hold about them and correct it if it’s wrong
  • request their data is deleted
  • request their data is not used for certain purposes

Register with ICO

Data Protection requires that you register with the Information Commissioners Office (ICO) if you are using personal data and pay an annual fee.

The ICO regulates data protection in the UK. They offer advice and guidance, promote good practice, monitor breach reports, conduct audits and advisory visits, consider complaints, monitor compliance and take enforcement action where appropriate.

You can get further help on Data Protection and GDPR:

Privacy Policy, Cookies and Consent

Out of this requirement comes the need for a website Privacy Policy and the requirement to handle Cookies transparently with the User’s Consent.

The main purpose of the Privacy Policy is to inform and reassure your website visitors that the information collected by your website (in forms and cookies) is going to be used appropriately.

  • Privacy Policy addresses the data you collect and store from users.
  • Cookie Policy specifically addresses how your website tracks users with cookies.
  • Consent refers to your obligation to obtain users consent to you collecting, storing and using personal data. The existence of a Privacy Policy does not give you consent to use personal data. As a general rule you should have specific User Consent (so Agreement) to have permission to collect and use personal data.
  • There is overlap between Privacy and Cookies but GDPR requires that your Privacy and Cookie Policies are separate documents.

Tools to assist you include

  • ICO’s Privacy Policy generator (particularly good as it generates a nice simple easy to understand privacy notice that isn’t full of legal jargon only solicitors can understand) – Generate a Privacy Policy for a small business.
  • TermsFeed have a selection of tools to generate legal compliance documents including Privacy Policy and Cookie Consent.

If you need expert help with your website contact Joseph Tirelli today.

Epsilis Web Design,
WordPress Specialists with over 25 years of experience.

PS. If you want to ring the best time to get me is between midday and 4 pm Monday to Friday. If you prefer email I aim to respond the next working day.