4 ms·
Unfortunately, most organisations need professional guidance on GDPR, and that's not necessarily cheap or accessible to the budget-constrained. A few points on
by donogh 8y ago
Unfortunately, most organisations need professional guidance on GDPR, and that's not necessarily cheap or accessible to the budget-constrained. A few points on their issues (IANAL):
1. Most organisations do NOT need a Data Protection Officer (DPO). There are a set of criteria for determining if you do. Here is guidance on it from the Irish DPC: http://gdprandyou.ie/data-protection-officer/ http://gdprandyou.ie/data-protection-officer/
If they are processing health data, then technically, yes, you might need one. You can consider outsourcing the DPO role to a privacy consultant; it may be the most sensible option.
2. If your data processors have not put agreements in place, then you are legally obliged to do so yourselves. This can actually be an advantage because you set the terms. Unfortunately, again it's best to seek professional advice, preferably legal advice when it comes to drafting contracts. I would go so far as to ask your solicitor to send a "threatening" letter with the agreement they need to sign.
3. Why does the visitor book need to be publicly visible? Is there a secretary or receptionist who could handle the book? Switching it to an electronic system is not necessarily going to meet the requirement. (GDPR is intentionally technologically neutral by the way -- there is no inherent advantage of one medium over another, so long as you're collecting and using data in a justifiable way, and meeting the other data controller requirements.)
4. Again, regarding display of health data, which is considered sensitive personal data, I would say it depends. GDPR is not a series of absolute dictums. Use of data does have to be explained and documented, and I believe you could seek parental consent for display of that information under certain circumstances. (Presumably to teachers who will be overseeing children?)
5. The vagueness of the legislation is definitely a problem. The GDPR does allow for an official certification[i], which will be a huge improvement (whenever we see it!).
All the scaremongering aside, the reality is that the legislation is still largely untested. We can fully expect to see a series of test cases appear over the coming months, which will provide clarity.
However, it's important to note and realise that no data protection authorities are going to start doling out extreme fines come Friday morning.
Even if an organisation is reported to the authority, there will undoubtedly be opportunities for remediation first and, unless it's a serious data breach, I seriously doubt anyone will receive a significant fine any time soon.
Facebook, on the other hand...
6. When it comes to training and certification, I'd recommend the IAPP: https://iapp.org/ https://iapp.org/
They are one of the thought leaders in the space, and have a solid track record, with affiliations with lots of reputable privacy consultants.
[i] http://www.privacy-regulation.eu/en/article-42-certification-GDPR.htm http://www.privacy-regulation.eu/en/article-42-certification...
- s73v3r_ 8y ago"Unfortunately, most organisations need professional guidance on GDPR, and that's not necessarily cheap or accessible to the budget-constrained." Professional guidance is needed for many things, and usually it's not cheap for any of it.