General Data Protection Regulations – Will apply from the 25th May 2018

General policy of General Data Protection Regulations

“…Under the GDPR a consumer has the right to work with us and then be forgotten, never to be hassled again where there is no legitimate reason to process their information…”[/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074220632{padding-top: 30px !important;}”][vc_column][vc_column_text]

Potential consequences for breach of the General Data Protection Regulation 2016

[/vc_column_text][vc_column_text]

Golden Rules

[/vc_column_text][vc_column_text]

Information Currently Held

[/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”When Does Data Protection Law Apply?” heading_sep=”no” css=”.vc_custom_1597074462546{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text]It applies when a business is processing personal information to an identified or identifiable living individuals

Consents

Personal Data can include:

Personal data is covered by a new definition “Biometric Data” which is any personal data relating to the physical, psychological, or behavioral characteristics of an individual which allows their unique identification.

It includes:

Name Address Bank Account details Credit card details Date of birth Email address* Correspondence from the client containing personal data Medical records Client notes Digital recordings Documents IP Address CCTV information Criminal Record Other info e.g. Supports Brexit *We are not authorised to disclose a client’s email address to a third party without their consent. Many email addresses do not provide an identity to a third party e.g. [email protected]. However if an individual is identifiable from the email address e.g. [email protected] then displaying it to third parties reveals that they have had dealing with this firm in the past. For some organisations (e.g. political parties, or organisations that deal with specifically sensitive issues) this may be a serious breach of privacy. The individuals can complain to the information commissioner who has power to issue enforcement notices, or they may seek compensation under s13 of the Data Protection Act 2018 for any contravention which causes them damage. A staff member of a company sent a blind carbon copy (‘’bcc”) email to 90 participants. The staff member then erroneously sent a correction by entering the participant’s email addresses into the “to” field instead of the “bcc”. As a result the recipients of the email could therefore see the email addresses of all the other recipients – a security breach. Many of the email addresses contained the full names of the participants. The company was reported to the ICO as the identity of the participant had been disclosed to third parties without consent. The company was fined £200,000 as details of possible victims of non-recent child sexual abuse were distributed. [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”How Can Data Be Processed?” heading_sep=”no” css=”.vc_custom_1597077156773{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text]By keeping on laptops/pc’s/iPad’s Paper in a filing system Intend to record in a filing system USB memory Sticks DRD- RW drives CD and DVD disks Media player hard drives Portable external hard drives

Methods of processing personal data

Marketing database Employee records Handwritten notes on job application if put on a file Information received from a client Jottings in your notebook are not processing unless you intend to put into a filing system Outlook contacts Info in your mobile phone if in connection with work Information displayed on a white board which can be viewed by third parties Files in view around the office which have the names of clients on the outside front cover Moral is “Any information stored about anyone is covered by data protection law”[/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”What if I am given a business card. What information can I process?” heading_sep=”no” css=”.vc_custom_1597077558052{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text]There is implicit consent to add the information in the card to Outlook. You should include a note to record the fact that the information was provided from a business card that was given to you. However, you cannot include information which you were also verbally told e.g. they support Manchester Unit and have 3 daughters, unless you have specific consent, or it is necessary for work. [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”Can you put names, job titles and contact details of a client on your firm’s marketing database?” heading_sep=”no” css=”.vc_custom_1597077740377{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text]This is not allowed unless you have specific consent to opt-in In 2017 Morrisons Supermarket deliberately sent 130,000 emails to customers who had previously opted out of receiving marketing relating to their Morrisons More Card. They were fined £10,500[/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”Can you send client legal bulletin information?” heading_sep=”no” css=”.vc_custom_1597078690036{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text] [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”What data can you process lawfully?” heading_sep=”no” css=”.vc_custom_1597078699265{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text]

Where express consent has been given, or it is necessary for:

[/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”If personal data is recorded in Outlook and it changes what should you do?” heading_sep=”no” css=”.vc_custom_1597078747561{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text]

Where express consent has been given, or it is necessary for:

Sensitive personal data which cannot be processed without specific consent

*Unless in connection with employment, social security, occupational health assessment or in connection with legal action. [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”What can you use information about a client for the purpose of a matter including date of birth, salary and contact details?” heading_sep=”no” css=”.vc_custom_1597079047624{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text] [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”What information can an employer reveal by way of disclosure that is necessary for example an employment dispute?” heading_sep=”no” css=”.vc_custom_1597079185671{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text] [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”You read in the press that a business has a certain problem. Can you call them to suggest that you can help resolve it?” heading_sep=”no” css=”.vc_custom_1597079496125{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text] [/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”You read in the press that an individual has a legal problem. Can you call them to suggest that you can help resolve it?” heading_sep=”no” css=”.vc_custom_1597079588598{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text] “you do not make unsolicited approaches in person or by telephone to members of the public in order to publicise your firm or in-house practice or another business;”

Data Minimisation

Data held about an individual must:

Security of Data

A data protection breach is defined as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise”. If the data is unavailable, for example when it has been encrypted by ransomware, or accidentally lost or destroyed – e.g whilst working on a client matter, data is stored on a desktop PC and it’s hard drive is corrupted and the data has not been backed up so is then unable to be backed up, so unable to be restored when the hard drive is replaced. It includes but is not limited to: (1) Hacking by a cyber attack (2) Loss of theft of devices or equipment on which personal data is stores (3) Deceit (4) Disasters at business premises e.g. fire or flood

Scenario – off to a meeting

Any documents (maybe in the case that there is no local internet access e.g. on a train) on the desktop should be password protected. All documents should stored with IT Farm so that they are not on the computer desktop, and have to be accessed with IT Farm by internet connection by inserting a name and password. We may introduce a second level of security by a password being sent to an individual’s mobile which then has to be used to access the IT Farm website.

Scenario – On a train and want a cup of tea

Scenario – Talking by mobile on a train

Scenario – Using a Laptop on a train

Scenario – Laptop taken home

Scenario – Files on Reception / In meeting rooms

Scenario – Accidentally sending confidential documents to a client

Encryption

Use of Mobiles – Security of Data

ICO Advice for Lawyers:

Password Protection

[/vc_column_text][vc_column_text]

Do not talk to somebody about a confidential matter until you are sure they are who they claim to be

Stolen Data

[/vc_column_text][/vc_column][/vc_row][vc_row el_class=”newz” css=”.vc_custom_1597074440115{margin-top: 30px !important;}”][vc_column][tm-heading h2=”What if there is a breach of Security?” heading_sep=”no” css=”.vc_custom_1597081558842{margin-top: 0px !important;padding-top: 0px !important;}”][vc_column_text] If there has been any breach of security notify the DPO and he will then decide a course of action notify the ICO, or e.g. simply request to a third party to delete the information, and confirmation that it has been done will be sufficient.

Subject Access Request

[/vc_column_text][vc_column_text]

Confidential job references

The right to be forgotten

The right to be forgotten is also known as Data Erasure. It entitles an employee, or client to have their personal data erased, for further dissemination of the data to be disseminated, and potentially have third parties ceasing to process the data. For example, it may be requested by a leaving employee to delete all personal data. However, the right is not absolute and:

The 6 Data Protection Principles

1 Processes lawfully, fairly and in a transparent manner 2 Collected for specific, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes 3 Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed 4 Accurate and, where necessary, kept up to date 5 Kept no longer than necessary 6 Appropriate security including protection against unauthorized, or unlawful processing and accidental loss, destruction or damage 7 Accountability for documenting policies, measures and controls, process procedures to demonstrate we are compliant.

Rights under GDPR

1 The right to be informed 2 The right of access 3 The right to rectification 4 The right to erasure 5 The right to restrict processing 6 The right to restrict data portability 7 The right to object 8 Rights in relation to automated decision making and profiling

Vicarious liability for data breaches

In October 2018 the Court of Appeal decided that Morrisons were vicariously liable for the malicious criminal conduct of its IT Auditor who deliberately accessed Morrison’s database and posted online the personal data of 100,000 employees names, addresses, gender, date of birth, phone numbers (home and mobile), national insurance numbers, bank sort codes and account numbers, and salary details. Morrisons now have to pay compensation to the employees. The case will now be taken to the Supreme Court.

Summary

1 A client’s identity, and personal data must be kept confidential 2 Electronic data must be kept confidential by the use of passwords for laptops, PC’s, Ipads etc…and mobiles, together with encryption where possible 3 Whilst the use of in the cloud storage such as IT Farm has encryption when using on a public network, ideally you should connect to your own 4G / 5G network rather than a public network. e.g. Starbucks it is still possible for a third party to “set up” their own network in a coffee bar by creating a false network with a name similar to the e.g. “starbucksnetwork” that you may log on to with no password required. Always check the identity of the network with the host and enquire whether a password is required. Hackers can eavesdrop, intercept and alter traffic between two devices. 4 Linda Kirk is the Data Protection Office – Any data breach must be immediately reported to him 5 If you have any client data on your mobile or you are unable to locate your phone, you must inform the Data Protection Officer immediately so that it can be deactivated remotely. Any online accounts accessed through the device must have their passwords changed immediately e.g. IT Farm, Ochresoft, etc…. 6 Never allow applications or files to be installed from unknown sources particularly smartphones/tablets[/vc_column_text][vc_empty_space][/vc_column][/vc_row][vc_row full_width=”stretch_row” css=”.vc_custom_1571309128939{margin-top: 18px !important;padding-top: 55px !important;padding-bottom: 30px !important;background-color: #1f2532 !important;}”][vc_column][tm-heading h2=”Testimonials” h2_font_container=”color:%23ffffff” h2_google_fonts=”font_family:Roboto%3A100%2C100italic%2C300%2C300italic%2Cregular%2Citalic%2C500%2C500italic%2C700%2C700italic%2C900%2C900italic|font_style:700%20bold%20regular%3A700%3Anormal” txt_align=”center” use_custom_fonts_h2=”true” el_class=”newheading”][vc_column_text][elfsight_testimonials_slider id=”1″][/vc_column_text][/vc_column][/vc_row][vc_row css=”.vc_custom_1557318457356{margin-bottom: -70px !important;padding-top: 50px !important;padding-bottom: 0px !important;}”][vc_column][vc_column_text][logoshowcase center_mode=”true” slides_column=”6″][/vc_column_text][/vc_column][/vc_row]]]>

Request a Call back

How Would You Prefer To Be Contacted?

We close for Christmas at 2pm on Monday 23rd December 2024 and reopen at 9am on Thursday 2nd January 2025.

Our last day for completions prior to Christmas is Friday 20th December 2024.

We wish you and your families all the very best over the Festive Period!

What Service Do You Require?
Conveyancing
Fraud, Regulation and Regulatory
Wills & Probate