Data Protection Policies & Procedures
Any well-oiled business is likely to have a good set of robust data protection policies and procedures. Whilst not necessarily the most exciting thing to consider, an appropriate set of tailored data protection policies and procedures can really help ensure UK data protection compliance.
As a business grows, data protection policies and procedures can help ensure that staff and management understand at a basic level their obligations in respect of data protection and to ensure that data protection is as uniform as possible across the business. Having written policies and procedures can also provide a benchmark against which processes, action and inaction can measured to ensure ongoing data protection compliance.
What data protection policies & procedures do I need?
The specific policies and procedures which a business needs will depend on the business – what personal data it collects, stores and otherwise processes. The policies and procedures will likely to some extent also be shaped by the businesses’ values and objectives. Having said that, businesses typically has one or more of the following policies and procedures in place: data protection policy; data retention policy; data breach policy; and data subject access request policy.
Businesses may have different data protection policies and procedures or one encompassing ‘data protection policy’. It also sounds obvious but the policy itself needs to actually be a policy, that is a set of written principles and rules relevant to the business which can actually be achieved in practice. A policy shouldn’t just contain statements of a businesses’ commitment to ensuring compliance with UK data protection law or a summary of UK data protection law, however many policies and procedures do contain one or both of these items for context.
It’s also important to ensure that policies and procedures have a clear point of contact for staff and management (as relevant) to seek further guidance, as well as which function of the business is responsible for review and maintenance of the policies and procedures.
How often should I review my data protection policies and procedures?
This will depend on time and budget available to the business together with developments and changes in UK data protection law. However, many businesses review their policies and procedures annually, with accelerated review if something really serious happens, for example a personal data breach.
Are policies and procedures all that I need?
Whilst a robust set of data protection policies and procedures is certainly a great start, the business needs commitment and buy in from staff and management at all levels to help drive UK data protection compliance. In addition, a business’s relevant contracts (e.g. data processing/sharing agreements) and other data protection documents (e.g. external privacy notices) should reconcile with its data protection policies and procedures, to mitigate against the risk of a business saying that it does or can do something which it doesn’t or can’t do in practice.
How can we help?
We can help with reviewing and preparing a range of data protection policies and procedures to help ensure businesses are compliant with UK data protection law.
Want to speak with one of our experienced data protection lawyers? Get in touch with the team.