Posts

Showing posts with the label Information Commissioner

Small Business Cyber Security & Data Protection for UK SME

With the explosion of cloud computing and general internet online activity (think social media) small businesses need to assess their security from business and compliance perspectives. Small and medium sized organisations in the UK need to be extra vigilant about cyber security given the increased regulations applicable to personal data and data security. Check out The National Cyber Security Center SME site discussing cybersecurity together with links to numerous resources as well as Cyber security: what small businesses need to know . The UK government maintains a general cybersecurity site providing links to guidance, research, and news among other items of interest that discuss cyber risks and protection measures. The ICO site has information and guidance (general and detailed) on cybersecurity that briefly discusses data security and your obligations under statutory and regulatory regimes. Also, the ICO has a small business hub with links to guidance and information on da...

Dealing With UK Data Protection Act and The UK General Data Protection Regulation (UK GDPR)

Data protection in the UK consists of the UK GDPR (retained EU law version of the General Data Protection Regulation ((EU) 2016/679)) and the Data Protection Act 2018 (DPA 2018) together with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426) (PECR). Review the UK government's tutorial on the DPA 2018 and learn about its requirements . The Information Commissioner's Office (ICO) maintains a web guide to prepare for compliance with the UK GPDR.  The guide provides links to relevant UK GDPR provisions as well as discussion/analysis on applicable UK GDPR definitions, principles, processing structures, security, accountability, data breaches, exemptions, applications, and international transfers.  The guide is updated by the ICO so frequently check the site.  Part of the guide links to a guide for SMEs and companies generally to begin conforming processes and procedures to UK GDPR requirements . Daniel H. Erskine, an attorney and solicit...