Share this article
In a year where the world appears to have been turned upside down, businesses can be forgiven for temporarily pushing thoughts of Brexit lower down the to-do list. When immediate survival is at stake, it’s not always possible to prepare for life a year down the road. As we prepare to wave goodbye (and perhaps good riddance) to 2020, companies have no choice but to turn their attention back to the UK’s transition as we complete our divorce from the EU.
As cyber security consultants, one of the most common questions we’re being asked right now is how leaving the EU affects the General Data Protection Regulation (GDPR) as we head rapidly towards a post-Brexit relationship with Europe.
In short, despite the UK leaving the EU on 31st January 2020, GDPR is here to stay and will continue to be enshrined in UK law after the end of the transition period on 31st December 2020 – under the title of UK GDPR (to sit alongside the EU GDPR). This is despite any uncertainties about the terms of the final Withdrawal Agreement. Although the UK will have the independence to review the framework over time, it is important to note that data protection will stay largely in line with European law in the immediate future.
In addition, those who receive or share any type of personal data from contacts within the EEA will most likely need to take some extra steps for this to continue after the end of the transition period. Again, this will depend on whether the UK is deemed to have appropriate safeguards in place. Importantly, though, it has already been established that data going from the UK to EEA will not require further safeguards – this is because the EU has deemed there to be sufficient measures in place already.
Nevertheless, organisations with offices, branches or any type of established presence within the EEA will most likely be required to have a designated European representative within the EEA over the coming years, depending on the nature of the business, frequency of data transfer and the fulfilment of relevant criteria. Some will also find Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) a useful way of ensuring safeguards are in place. Guidance associated with these can be found on the ICO’s website here.
If you have already brought your processes in line with GDPR, ensuring that data privacy and security are rigorously protected, and if you have no contacts or customers in the European Economic Area (EEA) then you may simply continue to focus on maintaining those high standards.
If it has been some time since you first considered your approach to GDPR, it would certainly be worth checking whether your organisation could be making improvements to your data protection policies right now but, broadly speaking, very little will change in January in this area.
If, however, you have not done so already, you need to address GDPR as a matter of urgency to ensure it is embedded into all aspects of your organisation. If you aren’t sure how to approach information security, a good starting point would be looking to achieve compliance with the ISO 27001 standard or Payment Card Industry Data Security Standard (PCI DSS) – either in an official capacity, or simply by following the frameworks laid out by these certifications.
Unlike GDPR itself, which does not have an actual compliance process, ISO 27001 provides very clear direction. It concentrates on policies and processes, including all legal, physical and technical controls involved in an organisation’s information risk management processes. Its value is that it creates a robust environment to protect both staff and customer information assets and even if you do not choose to adopt the standard itself, these guidelines provide a sound foundation for your GDPR approach.
Similarly, the PCI DSS provides a clear route map for data security best practice and will assist in developing a robust GDPR strategy. The only caveat is that both these standards are audited on an annual basis so if any changes have been made to policies or operational procedures since that date, you will need to update your GDPR approach accordingly.
SRM’s team of experienced GDPR consultants can help you to take all the necessary steps to ensure that your organisation adheres to the law. Providing valuable specialist support in these uncertain times, we are here to help organisations of all sectors and sizes. Our approach is collaborative and we work with resident CISOs and DPOs to achieve their goals in a cost-effective manner.
Want to find out more about how we can assist your organisation? Get in touch.