GDPR: Insights for small and medium organisations
The General Data Protection Regulation (GDPR) is one of the most complex and urgent issues that every organisation faces today it not just apply to large companies but also small and medium-sized enterprises (SMEs). It was created to bring data protection legislation in line with the modern-day usage of personal data on the internet.
According to Techtarget (2018), the collection of any data from citizens in the European Union (EU) needs to comply with strict rules protecting customer data. In other words, GDPR is all about protecting the personal of EU citizens and ensuring that their information is securely protected across Europe, regardless of the data processing takes place in the EU or outside. (Super Office, 2021 )
To comprehend where companies' responsibility for complying with GDPR standards begins and ends, it is necessary to understand the concepts of Data Controllers and Data Processors. Data Controllers are the companies that have the responsibility for the leads generated directly by it. In other words, they are the ones who control and promote the strategies for obtaining new contacts. Data processors, on the other hand, are like software that processes private data, must adopt technical and organizational measures so that the processing of information is done safely, respecting the privacy of the data holders. (Data Protection Commission, 2019)
To gain a better understanding of the obligations that small and medium business should know to comply with GDPR the Data Protection Commission (2019) says, that the GDPR principles is concerned with the following topics:
- Lawfulness, fairness and transparency: the three regulations preserve transparency according to the use of data to provide clear information about the purpose of processing data.
- Purpose limitation: the collection of personal data must have specific, explicit and legitimate purposes.
- Data minimisation: the collection of personal data should be limited only to what is necessary for what it is intended to be used for.
- Accuracy: accurate data and only used when necessary.
- Storage limitation: the format of personal data should allow identification of only what is necessary to be used.
- Integrity and confidentiality (security): the processing of personal data must guarantee their security.
- Accountability: the person responsible for using the data must strictly comply with the principles.
Companies that fail to comply with the GDPR provisions can face substantial fines. Mild violation of the rules can only result in notifications, however, large infractions can result in penalties of up to € 20 million or 4% of annual worldwide global annual revenue whichever is greater. (GDPR.EU, no date)
To conclude, GDPR aims to protect consumers' data privacy rights, leading organisations to higher standards of transparency, security and accountability when it comes to collecting and storing data. From a business perspective, GDPR can be seen as an opportunity to better serve its consumers, putting more creative and thoughtful marketing tactics into practice. Starting a transparent marketing strategy that adds value to consumer journeys will ultimately earn consumer confidence and generate more success for any business.
Author: Natassya Coelho
#gdrp #dataprotection #gdprrules #gdprcompliance #datacontroller
References
Data Protection Commission.2019. Legal basis for processing personal data [ONLINE] Available at: https://www.dataprotection.ie/sites/default/files/uploads/2019-12/Guidance%20on%20Legal%20Bases_Dec19_1.pdf [Accessed 02 March 2021].
GDPR.EU. 2021. Everything you need to know about GDPR compliance [ONLINE] Available at: https://gdpr.eu/compliance/ [Accessed 02 March 2021].
Super Office. 2021. What is GDPR and how does it impact your business [ONLINE] Available at: https://www.superoffice.com/blog/gdpr/ [Accessed 02 March 2021]
TechTarget. 2018. GDPR backup and data protection: Five steps to implement now. [ONLINE] Available at: https://searchdatabackup.techtarget.com/tip/GDPR-backup-and-data-protection-Five-steps-to-implement-now[Accessed 24 February 2021]

Thanks for your post Natassya. It was really informative and explained the complicated topic of GDPR very well. The legal ramifications for non-compliance with GDPR legislation need to be taken seriously by business using online platforms. Given the fact that GDPR compliance benefits the customer and protects them it is also an essential tool for business’ CRM strategy. With regards to SME’s, while they aren’t collecting as much data as large companies, they still need to adhere to the seven principles you outlined above to both comply with GDPR and create a safe and trustworthy environment for their customers. This should create a good relationship between the two parties. Thanks again and looking forward to you next post.
ReplyDeleteJames
👏👏👏👏
ReplyDeleteIt just complements the post I read earlier from this same blog about cookies, by Udit. I believe it is so important for independent businesses to understand the importance of protecting the consumers data! Thankfully, there are these new rules, frameworks and checklists proposed by GDPR. There are loads of things to look after but I think ensuring compliance with data protection helps not only your consumers but the company too, right? It is so important to have an internal security, reducing the risk of digital threats that are arousing recently.
ReplyDeleteOnce we received the big digital push to small and medium businesses, due to the recent pandemic episodes, there are some requirements to step into the digital world. However, once we go through material like the ones we find in this blog, it is possible to understand some basics.
This comment has been removed by the author.
ReplyDeleteSuch an insightful post Natassya, it’s good to hear laws that protect the user's data in today's age where every activity done by users can be tracked online. The post very well outlined the whole idea behind GDPR laws and what they mean for organisations. It’s essential for organizations to comply with GDPR rules to respect the privacy of their users and use data in an efficient manner. SMEs often struggle to recognize legal bases and, as a result, underestimate the value of understanding one when it comes to data processing. Both data-driven SMEs should spend time looking over the legal bases.
ReplyDelete