Data Protection Act 2018 enacts GDPR rules

Image

The government has passed the Data Protection Act 2018, which ushers in major changes in the way companies handle and process personal data, under the General Data Protection Regulation (GDPR) effective 25 May

The new act supersedes the UK Data Protection Act 1998 (DPA) and has a significantly wider scope, expanding the rights of individuals to control how their personal data is collected and processed.

The GDPR applies all businesses processing the data of individuals who reside in the EU, regardless of the location of the business. Any breach of the rules, where there is a risk that the rights and freedoms of an individual could become compromised, must be reported within 72 hours.

The new act gives individuals the right to request and receive confirmation of the data held on them, how it is being processed and for what purpose. Individual also have the right to receive personal data that has previously been provided, in a commonly used and readable format.

There is a new ‘right to be forgotten’, whereby individuals can ask the holder of their data to delete data from all IT systems, including from backups and remote servers, while newly designed IT systems must include data protection systems from the outset.

The GDPR requires positive consent to be given by an individual in relation to the processing of their personal data. In addition, the legal basis for holding and processing data must be known and recorded.

Penalties for non-compliance are up to €20m (£17.4m) or 4% of global annual turnover, whichever is higher.

Data Protection Act 2018 enacted 23 May 2018

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

4.5
Average: 4.5 (2 votes)

Rate this article

Related Articles
Subscribe