Data protectionJun 24 2020

How coronavirus is changing data protection for firms

  • Explain the genesis of GDPR
  • Explain how firms have fared since GDPR was introduced
  • Identify implications of Covid-19 on application of GDPR
  • Explain the genesis of GDPR
  • Explain how firms have fared since GDPR was introduced
  • Identify implications of Covid-19 on application of GDPR
pfs-logo
cisi-logo
CPD
Approx.30min
pfs-logo
cisi-logo
CPD
Approx.30min
twitter-iconfacebook-iconlinkedin-iconmail-iconprint-icon
Search supported by
pfs-logo
cisi-logo
CPD
Approx.30min
How coronavirus is changing data protection for firms

In our experience, the fact that an organisation may get things wrong in relation to data protection has not been a reflection of failings of attitude or culture - but a reflection of the natural limits of their own staff’s ability to maintain high levels of competency in specialised legal fields that are not core to their businesses.  

Being right about your rights

The most frequent challenge we see for financial organisations in relation to data protection housekeeping is compliance with the new ‘right to be informed’.

This is one of many data rights that the GDPR and the DPA 2018 afford to individuals, whether clients or prospective clients. 

Essentially, an organisation needs to provide specific information about why data is collected, how it will be used and how long it will be kept for.

This is not a complex requirement to comply with, since information can be provided in a privacy policy.

The GDPR provides a checklist of the key elements of information to include in such a policy and the ICO has published helpful guidance on their website covering this topic in detail.

Why then are financial institutions finding this to be a challenge?

The simple reason is that the information needs to be specific and tailored to a firm’s own interactions with its clients and prospective clients.  

It is not enough to have a generic template privacy policy that is not specifically tailored to a firm’s (or a department’s) data handling practices.

Under the old law (the Data Protection Act of 1998), firms were often in the bad habit of re-using generic template privacy policies that did not reflect their businesses. 

This practice was not appropriate under the old law, but it seemed to become pervasive.

This bad practice seems to have continued despite the new law coming into force, which requires a higher level of specific transparency.

Even two years after the DPA 2018 and GDPR have come into force, we are still helping financial institutions to comply with this requirement.  

Data housekeeping while Covid-19 keeps us all indoors 

The global response to Covid-19 seems to have had two effects on this ‘housekeeping’ work for financial institutions.

Firms are now finding the time to get their data protection regime into good order; however, there has been a significant increase in price-sensitivity from firms who are naturally keen to use their internal resources as much as possible to assist with the delivery of the necessary legal work rather than, for instance, the drafting of data protection policies.

PAGE 2 OF 5