Data protection – a brief guide for SMEs
Any personal information that you hold as business must be used fairly and securely and in line with the data protection laws. The definition of personal information is very broad and could be anything that directly or indirectly identifies a living individual.
By keeping personal information secure, and using it fairly, you can protect your reputation. Your actions will also help prevent potential harm and distress to individuals. In addition, good information management engenders trust from customers, employees and suppliers.
If you fail to put appropriate measures in place to handle personal data, and a breach occurs, your business may be subject to large fines as well as reputational damage. While looking after personal data properly may not guarantee you will never have a breach, it may reduce the likelihood or size of fines if a breach does occur.
How should I begin the process of managing personal data for my business?
Start by making a list. List all the categories of personal information that you have or plan to collect. You will probably have personal information saved on your phone, tablet or computer relating to, and enabling you to run, your business. Your list should generalise the categories of personal information such as ‘customer phone numbers’, rather than listing actual numbers.
You will also need to register the fact that you handle personal information with the Information Commissioner’s Office. For SMEs, this will usually cost £40 per annum.
Do I need all the personal information that I have?
You are only allowed to collect and use (‘process’) personal information that you need. You must not process any personal information on a ‘just in case’ basis. Your processing of personal information must always be fair and lawful. This means that you should only use the personal information in ways that the individual would reasonably expect. There are 6 types of lawful basis and you should keep a record of the lawful basis that you are relying on
Is the personal information secure?
You must take steps to keep personal information safe and secure. It is up to you to decide what security measures to put in place, which should be appropriate and proportionate to the nature of your business and the personal information that you process. This means that the more sensitive the information (e.g. financial or medical information) the stronger the measures you must put in place. Examples of security measures include physically locking information away or using strong passwords on your devices or systems.
Be transparent about how you’re storing and processing personal data, and why
You must tell individuals why you need their information, what you will do with it, who you will share it with and how long you intend to keep it for. The best way to do this is to have a privacy notice. You must also review the personal information that you have periodically and keep it up to date and ensure that it is accurate.
Respond quickly to data subject access requests
People whose information you process (data subjects) have rights. They can:
- Ask you to delete it;
- Challenge the accuracy of it;
- Object to what you are doing with it, and
- Ask for a copy of it.
Ideally, you should have a process in place for handling a person’s rights. Having such a process can save time and effort in the long run, even if you haven’t had a rights request before.
Know what to do if you have a data breach
When personal information is lost, accidentally destroyed, changed without the individual’s consent, damaged or disclosed to someone to whom it shouldn’t have been, you will have a data breach on your hands. Sometimes, external events such as a cyber-attack, flood or fire may cause the breach. Even if it wasn’t your fault, this will still constitute a breach on your part.
Act quickly when a breach occurs. In some cases, you may have to make a report to the ICO, and you have to do so within 72 hours. When this happens, you will need to understand and assess the risk to the personal information and respond accordingly.
Is that it?
No. Data protection compliance is a journey. It’s a bit like managing an ongoing project, meaning that you should review where you are and how you are doing regularly. Set reminders for renewal of your registration, check for updates on the ICO’s website and make improvements to your processes when breaches happen to prevent recurrence.
Contact us for help on your data protection journey
We can help you understand your data protection obligations in more detail, so that you can comply with the law and put procedures in place to reduce the risk of breach or non-compliance. This will lead to building trust and boosting your reputation as a responsible business.
Other resources
We know that data protection is a big topic, and something that gives many business leaders and company owners major headaches. So we’ve put together a number of short guides, linked below, providing you with a quick overview of the major areas you need to be aware of. They include:
- A brief guide to data protection (this blog post)
- Does my business need a privacy notice?
- What to do if we experience a breach of personal data
- Handling Data Subject Access Requests
- Handling data protection complaints
- Transferring personal data out of the UK