Skip to content
Digital Inclusion Toolkit
  • Toolkit
  • News

Home > Delivering a digital inclusion programme > Digital equipment and software > Businesses > General Data Protection Regulation (GDPR) compliance tips

  • About this page
  • Good GDPR resources
  • What’s worked for us

General Data Protection Regulation (GDPR) compliance tips

December 3, 2020 by Liz Crew

The General Data Protection Regulation (or GDPR for short) can feel a bit intimidating, especially if you’re a new or very small organisation.

GDPR is important as it safeguards the privacy of your customers and users. It encourages you to think about the personal data you ask for, how you use it, and how it’s stored.

By personal data we mean anything that could be used to identify an individual, and there’s more detail on the Information Commissioner’s Office website.

There’s no choice about implementing GDPR. Every organisation that collects personal data in the UK has to do this.

About this page

We’re not currently planning to write a step by step guide to implementing GDPR in an organisation. If we see the need to write something, or you’d like us to do this, please let us know.

There’s so much information out there already, so we’re pointing to the best guides we find – see below for a list.

In the meantime, we’ll use this page to collect tips that TechResort has found useful, either in implementing GDPR for ourselves or in our work with other organisations.

We’ll keep adding tips here. If you’ve anything to share, please let us know in the comments.

Good GDPR resources

It’s worth bookmarking the Information Commissioner’s Office (ICO) website. Every aspect of the law is there, and it’s relatively easy to follow.

Which? has a great guide written from a customer’s perspective. It’s worth a read when you have time.

GDPR was established by the European Union, so Brexit may ultimately affect what you need to do. The UK has currently included GDPR in our own laws.

What’s worked for us

Understanding what you have to do – Controllers and Processors

If you’ve read anything about GDPR, you’re sure to have come across strange sounding terms called ‘Controllers’ and ‘Processors’. Organisations need to work out which one they are, because it makes a big difference to what they need to do.

Controller

You’re a Controller if:

  • you decide what data is collected
  • what it’s used for
  • how it’s processed or used

There’s also such a thing as a ‘Joint Controller’ where you share responsibilities with another organisation.

Processor

You’re a Processor if:

  • someone else collects the data, and you’re following instructions from them

The ICO has some straightforward advice about Controllers and Processors which will help you identify which one you are.

Think carefully about the data you want to collect

It’s really tempting to ask people for all sorts of personal data. If you know more about customers you’ll be able to market to them better, and so on.

In our conversations with small businesses though, few have had the time to use the data they’ve collected over the long term. It’s hard work doing marketing well and consistently.

If you factor in GDPR’s need to spell out how this data will be used and stored, then this becomes a big and complicated task. It’s far better to ask for only what you absolutely need.

At TechResort, we hardly need any data from our users, and so don’t ask for it. It means we keep our privacy policy really short, and don’t have much sensitive data to worry about.

Even huge organisations like GOV.UK keeps the data it collects to an absolute minimum.

We’ve always liked GOV.UK’s privacy policy, so ours is modelled on it. You can’t go far wrong using the same template, asking yourself the same questions they did.

Here’s a couple of examples to think about:

You might need to know where your users are based, so it makes sense to ask for a postal address. But do you need the full address? Would postcode or electoral ward suffice? It’s less to collect, and doesn’t personally identify a user.

If you’re grant funded for a project, check with the funder whether they’ll require any individual details of beneficiaries of the project. If they’re happy with anonymised data then reduce the data you hold to anonymous information as soon as possible.

Be clear about how you’re using personal data

Your website needs to explain what you need customer data for, and how you intend to use it. If you’re using paper forms to collect data, you need to add the same explanation there too.

We’ve found that this feeds back to the point above, about only asking for data you really need. If you can’t explain why you’re asking for data, odds on you probably don’t need it. If this is the case, don’t ask for it in the first place.

Appoint a Data Protection Officer

Someone in your organisation (maybe you?) needs to have a good grasp of the personal data that’s being asked for, how it’s used and how it’s stored.

Make someone on your committee, board or senior team responsible for understanding the GDPR basics, for drawing up the policy and for training staff and volunteers.

Keep records of policy reviews and staff training to be able to demonstrate how you comply.

Store the data safely

Make sure the people with access to the data really need it, and choose your data storage method carefully.

Here’s some things that have worked for us:

  • invest in a sturdy locked cabinet for paper records
  • put digital personal data on designated computers only and ensure the computers are password protected so that no casual users can see the information
  • don’t share log-in details for shared cloud storage if there’s personal data involved. Give people who need it access via their own account so you can withdraw access later
  • be careful with portable storage like laptops and USB sticks. It’s easy to forget what data’s on there
  • when you don’t need paper records any more – shred the paper, don’t just bin it
  • if you pass computers onto other organisations make sure the data has been removed with a tool like DBAN – just deleting files isn’t completely secure

Email no-nos

We see the same big problem time and again – mass emails to people using software like Outlook, with tens of email addresses in the “To” or “CC” fields. Instantly everyone’s email address has been made public.

Many people might be OK with that, but that’s not really the point. GDPR is all about asking users for permission to share their data, before you share it.

The easiest way to fix this is to send the email to yourself, and put your list of email addresses in the BCC box. Sometimes the BCC box isn’t switched on by default, so you might need to hunt for it.

The other big no-no is sending personal info by email – avoid it if at all possible!

Marketing emails

There’s two good rules of thumb here. If you’re going to use people’s details for marketing (this includes newsletters) you must not automatically opt them into a mailing list – they have to make a positive choice. Have a sign up form on your website explaining what information you’ll be sending and how often, with a checkbox for them to tick to opt in.

It also must be really easy for people to opt out of marketing. Using dedicated email sending software like Mailchimp takes care of sign up forms and unsubscribe requests in one package.

Some organisations we’ve worked with find Mailchimp complicated to use, so we’re planning a post about alternatives – if you have any suggestions please let us know.

Other pointers

There are special rules for passing data on – make sure your Data Protection Officer learns the essentials before passing on any client data.

If you really need to collect information that would be considered sensitive then it’s essential to double check the safeguards you need to put in place. Sensitive information includes:

  • medical details
  • ethnicity
  • sexual orientation
  • gender identity
  • disability information
  • household income

You should also be especially vigilant about how you store the information and who can see it.

When you no longer have need of the data delete it, shred it or anonymise it. If the data is on a computer, use a tool like DBAN – just deleting files isn’t completely secure.

Let clients know how they can contact you to share with them the data you hold on them. If you learn of any inaccuracies in your data, make sure you correct them.

If at any point you believe that personal data you hold has fallen into inappropriate hands, you must let the people who’s data it is (called the “subjects”) know.

Author: Liz CrewOperations Director at TechResort CIC.

@Lillput

Share this

More

Join the digital inclusion conversation on Twitter

@diginclusionkit

Email updates

Subscribe today and get regular email updates on what's happening in the world of digital inclusion.

Subscribe

Digital Inclusion Toolkit
Funded by Local Digital
@diginclusionkit Digital-Inclusion-Toolkit

Find out more

  • About the Toolkit
  • Contact us
  • Resources
  • Contribute
  • Accessibility
  • Privacy
  • Cookies

Email updates

Subscribe today and get regular email updates on what's happening in the world of digital inclusion.

Thanks for subscribing. We've sent you a verification email from updates@digitalinclusion.org. Simply click the link in the email so we can make sure it's the right email address.

How we use cookies
We would like to use cookies to help give the best online experience. Please let us know if you agree to this.
Cookie settingsAccept and close
Manage consent

Cookies

This website uses cookies to assist in core services to support your use of our website.
Necessary cookies
Always Enabled
Cookies are files saved on your phone, tablet or computer when you visit a website. We use this information to make the website work as well as possible and improve digitalinclusionkit.org. To find out more about controlling and deleting cookies usage on your browser, visit www.aboutcookies.org.
Non-necessary cookies
This site uses Google Analytics to track how the website is used by recording clicks on links and information about the device used to browse the site. This site uses HotJar to record how the website is used and to collect information from users in polls or surveys.
SAVE & ACCEPT