GDPR: Is your website compliant with the new regulation?

(Image credit: Image Credit: Startupstockphotos / Pexels)

The General Data Protection Regulation (GDPR) is a new EU regulation designed to enable consumers to better control their personal data and many businesses are becoming more wary of where workplace data is held.

While employees are able to access work emails on their personal laptops and smartphones, many companies may choose to put in place more stringent measures to access it.

A survey of 2,000 UK office workers, conducted by tech retailer Ebuyer, shows that 66% of people log on outside of their normal business hours, with most of those (91%) using their personal devices to do so.

Whether you are operating a large online store or just a small personal blog, if you process any kind of data taken from the users who visit your site, then you will be subject to the new regulations and you must make your website GDPR compliant. 

In order to that, you must conduct a personal data audit in order to identify all of your data processes. You must consider all important aspects such as what are you using the data for, where is it being stored and, most importantly, do you still need it?

GDPR compliance checklist

 - Document the personal data your organisation holds, where it came from and who it is shared with. A systematic audit of your current processes is a good start to identifying what changes need to be made.

- Review your privacy notices. Under the GDPR, you will need to explain the lawful basis for processing customer data, as well as how long you retain it for and the customer’s right to complain about how you are using it. This must be communicated clearly and concisely.

- Have a robust process in place for locating and deleting individual customers’ data if and when requested. This is one of the key rights individuals will be made aware of under the GDPR.

- Be aware of the new right to “data portability”. This means individuals have the right to request their personal data in a commonly-used, machine-readable format, provided free of charge and within one month. Consider how your organisation will provide this.

- Review how you seek, record and manage consent for data collection. Remember consent must be explicitly provided: assumption of consent (for instance, via pre-ticked boxes on a web form) may land you in trouble.

Review how you will verify individuals’ ages, and how you will obtain parental consent to process the data of under-13s if required. This will also mean your privacy notices must be written in a way children can understand.

- Reinforce your existing data breach reporting procedures to ensure your organisation can meet the new timelines. Failure to comply may be a much more serious matter under the GDPR than it currently is.

- Take steps to appoint a Data Protection Officer if you are required to, and consider who should be responsible for GDPR compliance even if not.

For advice on what GDPR means and how it will affect both businesses and individuals, click here.

For advice on what GDPR means and how it will affect both businesses and individuals, click here !

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does