On 25 May 20218, the General Data Protection Regulation (GDPR) will replace the Data Protection Directive as the new global standard on data privacy for all government agencies and organizations that do business with European Union (EU) citizens. When it does, all organizations that control, maintain, or process information involving EU citizens will be required to comply with strict new rules regarding the protection of personal customer data.
Personal data can be anything that allows a natural person to be directly or indirectly identified. This may be a name, an address, or even an IP address. It includes automated personal data and can also encompass pseudonymised data if a person can be identified from it.
Both personal data and sensitive personal data are covered by GDPR.
The GDPR includes a number of requirements for organisations running consultation programs, including:
Read more about the implications for Consultors and Consultation Processes in our free e-book here.
This week we are moving our UK servers to the Microsoft Azure UK environment as it offers us some additional security measures and is GDPR compliant. With these additional measures in place, such as data encryption at rest, we meet the requirements of the GDPR as Data Processors.
There are a number of functions in Darzin that help you meet the GDPR requirements as Data Controllers. These include:
We've put together a guide to understanding and complying with the GDPR from a Public Consultation point of view. Please don't treat it as legal advice - it is our understanding of the GDPR combined with our expertise in Public Consultation and Stakeholder Management.
Included in the e-book are a couple of checklists which you might find helpful to test if you are ready for this new legislation before May 28.
If you have any comments or questions about the e-book, please do get in touch.