Data protection policies and procedures

Why your company needs them, and what they should include

Whatever your business, it's essential that your company has some kind of formal data protection policies and procedures in place to guarantee you are sufficiently protecting your customers, partners, employees, and any other individual you keep data about.

Although the Data Protection Act (DPA) has protected individuals and consumers since 1998, the General Data Protection Regulation (GDPR), which came into force in May last year, takes this to a whole new level. This legislation applies to any company that has dealings with EU citizens - even if those companies are not headquartered in Europe.

The DPA has also undergone significant change and its latest update places it in line with many of the same policies of the GDPR. If your organisation does not comply with the law, it could face fines hefty enough to take any small or medium business into administration.

Both data laws exist to protect citizens from having their private data misused, which is an unfortunate part of modern life as so much information is digitised. If sticking to the GDPR and DPA isn't enough to convince you to develop data protection policies and procedures, our roundup of why you should have them and what they should contain should convince you otherwise.

Why a company needs a data protection policy and procedure

Not only is it vital that your company has data protection policies and procedures to meet the Data Protection Act guidelines, but it's imperative that you have such a document or documents available for everyone as part of the GDPR, which came into force for the entirety of the EU in May 2018.

If you aren't complying with the new regulations, your business can be charged 4% of its annual turnover, or up to 20 million.

What a data protection policy and procedure should contain

Your company's data protection policy and procedure should be created to suit your specific business. For example, you will need to state what your employee data policies and procedures are, but there's no point stating what you will do with customer data if you don't collect it.

Advertisement - Article continues below
Advertisement - Article continues below

Although the GDPR makes many changes to the DPA principles, they are in line with the original guidelines and so any policy addressing the original data legislation is a good place to start. These state data held by a company must:

  • Be obtained and processed fairly and lawfully.
  • Be obtained for a specified and lawful purpose and shall not be processed in any manner incompatible with that purpose.
  • Be adequate, relevant and not excessive for those purposes.
  • Be accurate and kept up to date.
  • Not be kept longer than is necessary for that purpose.
  • Be processed in accordance with the data subject rights.
  • Be kept safe from unauthorised access, accidental loss or destruction.
  • Not be transferred to a country outside the European Economic area, unless that country has equivalent levels of protection for personal data.

It's important your policy addresses each of these points, and explains how the organisation will guarantee each is respected.

Advertisement - Article continues below

That covers how you will ensure the data is lawfully obtained, how it's kept up to date if any changes are made, how your company plans on keeping the data safe from unauthorised access, how the data will be removed when it's no longer needed and how you will guarantee the data is removed from all systems.

The GDPR also adds a new principle in - that of accountability - so it's pivotal you highlight whose responsibility it is to enforce these policies upon your organisation as well. You'll also need to ensure the document explains how you will guarantee your whole staff complies with these policies, and any procedures your business has in place if staff fails to do so.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now


data management

EU-US data transfer tools used by Facebook ruled legal

19 Dec 2019

Arcserve UDP 9240DR review: Beef up your backups

4 Apr 2019

Most Popular

operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
data breaches

Misconfigured security command exposes 250 million Microsoft customer records

23 Jan 2020
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020

Windows 10 and the tools for agile working

20 Jan 2020