What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union regulation that will replace the current Data Protection Act 1998 and comes into force on 25th May 2018.

GDPR has been in development since 2012 by the European Union Parliament and the Trust to harmonise and strengthen the rights of data subject across Europe, including when data is transferred to third party countries.

The Regulation enhances the rights of individuals whose personal data is processed by an entity and allows for new changes such as the right to be forgotten and right to erasure.

It also provides for increased accountability and processes to demonstrate compliance.  For example; we may be required to either appoint a Data Protection Officer (DPO) or designate individual to take proper responsibility for the important task of data protection compliance.  Also the requirements for consent are now much higher.

All breaches will have to be reported to the Information Commissioners Office within 72 hours and the potential fines for breaches are up to €20 million.

Subject Access - Request Form (193.5 KiB)

 

NameDate UploadedSize
Data Audit Schedule - May 201816th May 2018234.4 KiB
Social Media & Electronic Communication Policy 201816th May 2018179.7 KiB
Information Data Protection Policy 201816th May 2018201.7 KiB
The Management of Transferable Data Policy 201816th May 2018166.3 KiB
GDPR - Document Retention and Disposal Policy 201816th May 2018212.2 KiB
List of Documents for Retention or Disposal - Appendix A16th May 2018191.3 KiB

 

How can I find out more?

We will continue to ensure compliance with GDPR.  Should you wish to know more about the GDPR, please visit the dedicated webpage on the ICO website:

https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/