Three years after the General Data Protection Regulation (GDPR) came into play, thousands of companies aren’t abiding by the rules. With a maximum fine of £17.5 million or 4% of the company’s annual turnover (whichever is higher), doing what you can to avoid a breach is about as important of a task as it can get.
GDPR and where can it go wrong?
According to DLA Piper, GDPR fines rose by almost 40% in 2020 after a total of 121,165 data breaches, totaling around £130M in fines. So it doesn’t look like they’re taking their foot off the pedal anytime soon.
Now we know that the biggest fines come from the biggest companies. For example, Google was fined £43.2 million last year for not making it clear what user’s data would be used for, but that doesn’t mean they’re not coming after the little man too. You must ensure that you have shown them how you’re using it and have got their consent whenever you collect your customers’ data.
Have you been monitoring your employees without their knowledge or permission? Well, I hope not. Just like customers, your employees must know when you’re collecting data, what for and where it’s going. H&M was hit with a whopping £32.1M for the illegal surveillance of hundreds of employees – you can read more about that here.
Sometimes it doesn’t even have to be your own fault. As British Airways found out in 2018, you can be fined a very handsome fee simply for not having good enough cybersecurity. If hackers manage to compromise your systems, they have access to your customers and employees addresses, login details, banking details and more.
So, what can you do to protect yourself?
Firstly, sign up with the Information Commissioner’s Office (ICO) if you haven’t already. Technically, any entity that stores personal information needs to register with the ICO and pay its fee. There are a few exemptions, so always check on the self-assessment on their website first, but it is more than likely that your company should be paying fees to the ICO.
Next, invest in some genuine top-tier cyber security and disaster recovery solutions. Like insurance, it might be an annoying expense now, but it could save you millions in the long run. This is where we come in. As part of our services, we offer the best cybersecurity solutions for your business to ensure that you are protected if you do have a breach.
Finally, educate your employees. We offer a clear and honest consultancy service to help you and your staff best understand the risks of GDPR. The more they know, the less they’re likely to make a costly mistake.
For more information on GDPR, visit the GOV.UK website. To find out how we can help you with cyber security IT solutions, get in touch.