As everyone must now surely be aware, the new regulation on data protection known as General Data Protection Regulation (GDPR) came into force on the 25th May 2018.
This led all companies to review their data protection processes and we’re no different. We worked hard to ensure we are compliant.
In light of the UK leaving the EU we again reviewed our entire data protection process to ensure we are meeting current legislation. Below is a list of all the things we have done to make sure the data we process is protected adequately.
Undertaken data protection training
To enable us to fully understand our responsibilities in regards to data protection, our staff have undertaken training for a level 2 Certificate in Data Protection and Data Security. This has been delivered online throughout the pandemic by the Learning Curve Group.
Audited businesses data storage and streamlined internal storage processes
We began this process by doing an audit of all the tools we use in our business that were a place for our clients details to be stored. Over the years we have tried and tested many online tools to try and help streamline our businesses processes. Some of which have been successful and others not.
We revisited all of them, closing and deleting accounts that didn’t work for us, tidying up the ones we did use to make sure they only held relevant data and found new ones that better suited our purpose. A list of the software that we use to deliver our services to our clients can be found on our privacy notice under the section ‘where we store and transfer your data’.
Discontinued the use of any third party plugins which were no longer required
We use Google Apps for our emails, contacts, calendar and data storage. We use plugins to help make the tools we use work more effectively for us. Over the years this has meant an accumulation of plugins, some of which are useful and some are not. We reviewed them all and removed many of them so now only have a select few that link with with our Google Apps account.
Where possible, we only data processors who are GDPR compliant
GDPR is a regulation in EU law so as such, any data processors that we use within the EU are also subject to the new legislation. We have tried to ensure that where possible, the data processors we use are GDPR compliant. We only use data processors which we feel really benefit our business and allow us to offer a better service to our clients.
Housekeeping on the data we hold removing old or dormant contacts
We use Capsule CRM to help us manage our clients details. We’ve made sure to delete our old accounts in the previous CRM systems we have trialled in the past and have integrated our emails, contacts and financial information together to provide a better solution for us and our clients. As part of our ongoing commitment to the protection of data, we review the details we hold in our CRM every 6 months, deleting unnecessary contacts where applicable meaning the data we now hold for every contact is relevant and as accurate as we can obtain.
We have ensured our processing is lawful
We have re-evaluated our Legitimate Interest Assessment to ensure our processing is lawful. By completing the assessment and going through the relevant questions we can confidently communicate with our clients, suppliers and potential clients. See our privacy notice for more details.
Updated our privacy notice
Based on the adjustments we have made to our process, we have updated our privacy notice on our website to ensure it is accurate and reflects all the changes that new changes bring into force. You can see the updated notice here.
So yes, we’ve been busy. Although GDPR has at times felt like an uphill struggle, now we are ready we can really see the benefits for us and our clients. For all those of you who have also undergone this process we can appreciate the time and effort that’s gone into becoming compliant and we salute you!