GDPR – It’s All Going To Be Okay…

GDPR – It’s All Going To Be Okay…

Take a look at the most recent ICO blog stating that GDPR is not ‘a burdensome revolution’ - we can now all stop worrying, Well not exactly – this blog seems to ignore the complexity of GDPR, the amount of work required to implement the GDPR changes, and the costs involved.

The blog also ignores the fact that there is little in the way of guidance around GDPR and an awful lot about the consequences of none compliance. This combination of incomplete regulations; vagueness of implementation requirements; and threats of ginormous fines makes me nervous and should be a huge concern to everyone.

The ICO 12 step approach might be okay if you are a blue-chip organisation with an IT team and large IT budget but is meaningless for most small companies. How many SMEs will even know what an information audit is or how to document a risk assessment? The 12 step model might work well for large companies but ignores the thousands of UK SMEs that might not even be aware of GDPR.

Not forgetting the enormous power of ICO to decide that they just don’t like your security approach, data minimisation strategy or operational processes and you have a pretty scary situation.

At some point the ICO has to accept that this is a huge issue for all UK companies and stop pretending that GDPR is just an evolution of DPA and take some action to support UK business. Either that or at least stop threatening everyone with enforcement action and punitive fines.  Take the HMRC approach and adopt a light-touch on enforcement at least for a short time. Give us all a chance!

Thanks

To view or add a comment, sign in

More articles by Adam Brogden

  • Is your GDPR failing?

    Is your GDPR failing?

    So, you worked hard to complete your GDPR policies, updated your privacy policy and emailed all your clients to confirm…

    4 Comments
  • GDPR ONGOING DUE DILIGENCE

    GDPR ONGOING DUE DILIGENCE

    GDPR is not just about compliance today. It is more about making data security part of everything you do in the future.

    2 Comments
  • Cyber Security 101

    Cyber Security 101

    Here at Optindigo.com we take data security seriously.

    4 Comments
  • PROTECT YOUR MAC!

    PROTECT YOUR MAC!

    Whether GDPR is on your mind or not, encryption certainly should be. With data security constantly in the spotlight…

  • GDPR URGENT ACTION

    GDPR URGENT ACTION

    If you have just started your GDPR preparations, you have little chance of being ready for the 25th of May. However…

    1 Comment
  • HOW CAN YOU FINISH GDPR FAST?

    HOW CAN YOU FINISH GDPR FAST?

    With less than a month to go some companies are starting to panic and most are wishing that they had started their GDPR…

    5 Comments
  • GDPR AND USING SOCIAL MEDIA TO SAVE YOUR DATA.

    GDPR AND USING SOCIAL MEDIA TO SAVE YOUR DATA.

    Want to know how Facebook could help save your database? Here is a trick that might just save your customer list. Click…

    5 Comments
  • NOT READY FOR GDPR?

    NOT READY FOR GDPR?

    Although the ICO has clearly stated that GDPR enforcement starts of 25th May, it seems to be generally accepted that…

  • GDPR ADVICE. GAINING CONSENT AND CONFIRMING CAPACITY

    GDPR ADVICE. GAINING CONSENT AND CONFIRMING CAPACITY

    In some cases explicit consent is the most appropriate lawful basis under which you can process a person’s data…

    3 Comments
  • GDPR SUBJECT ACCESS REQUEST. THE KEY TO GDPR PLANS?

    GDPR SUBJECT ACCESS REQUEST. THE KEY TO GDPR PLANS?

    On the face of it the Subject Access Request process is a pretty innocuous document, pretty simple process and probably…

    2 Comments

Insights from the community

Others also viewed

Explore topics