How will GDPR affect you and your business?

◴ 2 min

Firstly, what is GDPR?

GDPR is coming into force on 28th May 2018. But do you know how it will impact you and your business, and what you need to do in order to prepare?

GDPR stands for General Data Protection Regulation. It is a new law that has passed which changes the way businesses store and handle personal data.

This gives every individual the right of the control of their personal data and simplifies the regulations for international businesses by unifying regulations within the EU.

What does GDPR mean for individuals?

GDPR would mean that individuals have the right of:

  • Accessing their data whenever they want to
  • Be informed of any breaches
  • Have the ‘right to be forgotten’
  • Have the right to change any of their information
  • Reject having their data processed
  • Have the right to transfer their information from one place to another

Which businesses would GDPR apply to?

  • GDPR will apply to any company which processes the personal information of EU citizens
  • Even businesses with less than 250 employees will be affected

What do businesses have to do as a result?

The Information Commissioner’s Office has created a checklist guide to help businesses make sure they know what to do for GDPR.

This would mean that businesses have to comply with the following:

  • Businesses which process and deal with personal information on a large scale will need to employ a DPO (Data Protection Officer) who will ensure the business is complying by GDPR correctly.
  • Personal data cannot be kept longer than necessary.
  • It can only be used for a limited time for a specific purpose.
  • It has to be kept extremely secure.
  • It cannot be shared with others.
  • It has to be used lawfully.
  • If an individual no longer wants a contract with you, they have a ‘right to be forgotten’ – i.e. their personal information has to be erased.

If you need any assistance or guidance as to how to cope with GDPR on your business and need to talk to a qualified accountant, book a FREE meeting (schedule a meeting.)

Picture of Jahan Aslam
Jahan Aslam
With 20+ years of experience, supporting businesses at every stage of their journey, they offer practical advice on UK accounting, taxation, company formation, and financial planning, helping entrepreneurs build and grow successful businesses.

Table of Contents

Frequently Asked Questions

line
What is GDPR?

GDPR (General Data Protection Regulation) is a data protection law designed to give individuals greater control over their personal information. It sets rules for how businesses collect, store, process, and protect personal data.

Yes. GDPR applies to businesses of all sizes, including small businesses, if they collect or process the personal data of individuals in the UK or EU. There is no exemption based solely on the number of employees.

Individuals have several rights under GDPR, including the right to access their personal data, correct inaccurate information, request deletion of their data (the “right to be forgotten”), restrict or object to data processing, and request data portability.

Businesses must collect personal data lawfully, keep it secure, only use it for legitimate purposes, retain it only as long as necessary, and ensure they have appropriate processes in place to respond to individuals’ data requests and report certain data breaches.

Not every business needs a Data Protection Officer. A DPO is generally required for organisations that process large amounts of personal data, monitor individuals on a large scale, or handle special categories of sensitive personal data. Smaller businesses should assess whether they meet these requirements.

What clients say

We value your feedback

Share your thoughts and help us improve your experience.