{"id":18708,"date":"2021-10-04T11:36:00","date_gmt":"2021-10-04T10:36:00","guid":{"rendered":"https:\/\/wilsonjames.co.uk\/?post_type=blog&p=18708"},"modified":"2022-12-13T14:28:11","modified_gmt":"2022-12-13T14:28:11","slug":"data-protection-how-to-build-a-culture-of-good-policy-and-practice","status":"publish","type":"post","link":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice","title":{"rendered":"Data protection \u2013 How to build a culture of good policy and practice"},"content":{"rendered":"

\"\"<\/p>\n

\n
\n

Barry Spriggs
\n<\/strong>Data Protection Officer at Wilson James<\/strong><\/h3>\n<\/div>\n<\/div>\n

 <\/p>\n

 <\/p>\n

Where to start?<\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

Data Protection Policy<\/strong><\/p>\n

 <\/p>\n

Building a great culture and awareness around data protection starts with getting the basics right; in this case an initial data protection policy. This provides guidance to all in the enterprise about what is expected from staff, what assurances are given from the business around how personal data will be treated.<\/p>\n

\u00a0<\/strong><\/p>\n

Publish and promote it<\/strong>. Don\u2019t forget to make your organisational colleagues aware of the policy by proper publication and signposting. Your policy should provide assurance, leaving no doubt that personal data will be treated with the utmost respect and confidentiality in line with the data protection principles.<\/p>\n

 <\/p>\n

Retention Policy<\/strong><\/p>\n

 <\/p>\n

So, you have made a start and the board has approved your data protection policy.\u00a0 What\u2019s next?\u00a0 You need to build a comprehensive data retention<\/strong> policy that allows all areas of the business to understand how long personal data items should be kept and crucially when they should be deleted. Moving forward this amounts to more than just the usual HR\/Finance items. Don\u2019t forget with the advent of O365 environment you can put in place great auto delete features on MS Teams chats and emails.\u00a0 As we all know, less emails around means less data breaches and less items to redact in the subject access request process. Ultimately good data control includes compliant deletion as much as retention.<\/p>\n

 <\/p>\n

Awareness raising and training<\/strong><\/p>\n

 <\/p>\n

Think of your staff.\u00a0 It is no good having great policies if you don\u2019t implement some simple awareness raising or training.\u00a0 Make the effort to ensure all<\/strong> employees receive appropriate training about your privacy programme, including what its goals are, what it requires people to do and what responsibilities they have. The training must be relevant, accurate and up to date. The regulator, Information Commissioners Office (ICO), state \u2018All<\/strong>\u2019 should receive training.<\/a><\/p>\n

 <\/p>\n

The truth is that every colleague is a link in the data protection chain and should know their role in protecting your organisation from breaches or improper retention.<\/p>\n

 <\/p>\n

Privacy by design and default<\/strong><\/p>\n

 <\/p>\n

You\u2019re doing great so far. But hang on, I.T in cahoots with HR have commissioned a new system that involves personal data and haven\u2019t told you. The worst thing is the go live date is next week!<\/p>\n

 <\/p>\n

The truth is that these days all improvement programmes should ensure that IT and Procurement are on board from the planning stages, with the whole privacy by design theme. They need to involve data protection at the outset so that your DPO can ensure that this new system can indeed service all the rights of a data subject.\u00a0 It really isn\u2019t going to be good having to tell the ICO that you didn\u2019t know about it when there\u2019s a data breach. No one wants to be the one to tell the board that there\u2019s a fine or other action on the way, as carrying out a Data Protection Impact Assessment (DPIA)<\/a> is mandatory in some cases.<\/p>\n

 <\/p>\n

 <\/p>\n

Rights of a Data Subject – that includes you!<\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

A business must ensure that it can service all the rights of a data subject. The most common one of these is the right of access. As everyone becomes more aware of how valuable personal data is this right is becoming widely used and will only become more popular as we move along the data journey. People want to know what personal data a business holds on them. Ensure you have an efficient process in place where this can be facilitated. All the personal data you collect on staff or customers must be able to be accessed by them. This can be very time consuming and resource intensive if good procedures are not in place.<\/p>\n

 <\/p>\n

Am I done? <\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

Not quite. Don\u2019t forget your Privacy Notices, Record of Processing Activity (ROPA), Data Breach procedures, International Data Transfers and Cookie Policy to name but a few.<\/p>\n

 <\/p>\n

 <\/p>\n

What\u2019s coming up in 2022?<\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

The Covid-19 aftermath<\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

All in all, 2021\/2 will hopefully turn devastation into much needed growth and prosperity, but the data protection challenges ahead will test the resilience that we have all learnt to practice in 2020. How do we manage our staff Covid data? Will Covid passports be brought in? Can we share our staff Covid status? How do we share securely?\u00a0 Data breach involving health data \u2013 far from becoming simple, organisations should be planning now for an increasingly complex set of requirements with more vigorous oversight from industry bodies. The growth of technology in all its forms has been key to withstanding the shock of the pandemic, but this means that individuals and organisations need to be more mindful than ever of what data they hold and why.<\/p>\n

 <\/p>\n

The growth of representative actions<\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

An added touch of drama for data protection professionals will result from often unexpected legal actions claiming damages derived from data protection infringements. Opportunist tactics will become more sophisticated as representative actions mature. So, privacy and data protection litigation will become a new and active field to explore. The new PPI is here\u2026 Just ask British Airways how defending a class action for a data breach.<\/p>\n

\u00a0<\/strong><\/p>\n

\u00a0<\/strong><\/p>\n

Who can help?<\/strong><\/p>\n

 <\/p>\n

Appointing a suitably qualified Data Protection Officer (DPO)<\/a> will help you and your business navigate all this work. This is mandatory in some circumstances. If you do not have the right member of staff for this work, you can always outsource your DPO requirements. This is an accepted procedure by the ICO and is particularly useful for small businesses that may not have the resource for a full time DPO. The outsourced DPO carries out all the requirements under Data Protection Act 2018 and UKGDPR.<\/p>\n

 <\/p>\n

 <\/p>\n","protected":false},"excerpt":{"rendered":"

An initial data protection policy provides guidance to all in the enterprise about what is expected from staff, what assurances are given from the business around how personal data will be treated.<\/p>\n","protected":false},"author":8,"featured_media":18710,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[64,67],"tags":[],"jetpack_publicize_connections":[],"aioseo_notices":[],"yoast_head":"\nData protection \u2013 How to build a culture of good policy and practice - Wilson James<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection \u2013 How to build a culture of good policy and practice - Wilson James\" \/>\n<meta property=\"og:description\" content=\"An initial data protection policy provides guidance to all in the enterprise about what is expected from staff, what assurances are given from the business around how personal data will be treated.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice\" \/>\n<meta property=\"og:site_name\" content=\"Wilson James\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-04T10:36:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-13T14:28:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"721\" \/>\n\t<meta property=\"og:image:height\" content=\"484\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Cadence Woodland\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@wj_ltd\" \/>\n<meta name=\"twitter:site\" content=\"@wj_ltd\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Cadence Woodland\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice\",\"url\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice\",\"name\":\"Data protection \u2013 How to build a culture of good policy and practice - Wilson James\",\"isPartOf\":{\"@id\":\"https:\/\/wilsonjames.co.uk\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#primaryimage\"},\"image\":{\"@id\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#primaryimage\"},\"thumbnailUrl\":\"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg\",\"datePublished\":\"2021-10-04T10:36:00+00:00\",\"dateModified\":\"2022-12-13T14:28:11+00:00\",\"author\":{\"@id\":\"https:\/\/wilsonjames.co.uk\/#\/schema\/person\/49941be4c3b9c7a0a3b21ede1658e2d9\"},\"breadcrumb\":{\"@id\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#primaryimage\",\"url\":\"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg\",\"contentUrl\":\"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg\",\"width\":721,\"height\":484,\"caption\":\"Computer security concept\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wilsonjames.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection \u2013 How to build a culture of good policy and practice\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wilsonjames.co.uk\/#website\",\"url\":\"https:\/\/wilsonjames.co.uk\/\",\"name\":\"Wilson James\",\"description\":\"Wilson James is a leading security, logistics and aviation services provider with over 5,000 employees operating across the UK.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wilsonjames.co.uk\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/wilsonjames.co.uk\/#\/schema\/person\/49941be4c3b9c7a0a3b21ede1658e2d9\",\"name\":\"Cadence Woodland\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/wilsonjames.co.uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b0376243dae4ae8704239a2d3e2a64c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b0376243dae4ae8704239a2d3e2a64c2?s=96&d=mm&r=g\",\"caption\":\"Cadence Woodland\"},\"description\":\"ok\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection \u2013 How to build a culture of good policy and practice - Wilson James","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice","og_locale":"en_GB","og_type":"article","og_title":"Data protection \u2013 How to build a culture of good policy and practice - Wilson James","og_description":"An initial data protection policy provides guidance to all in the enterprise about what is expected from staff, what assurances are given from the business around how personal data will be treated.","og_url":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice","og_site_name":"Wilson James","article_published_time":"2021-10-04T10:36:00+00:00","article_modified_time":"2022-12-13T14:28:11+00:00","og_image":[{"width":721,"height":484,"url":"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg","type":"image\/jpeg"}],"author":"Cadence Woodland","twitter_card":"summary_large_image","twitter_creator":"@wj_ltd","twitter_site":"@wj_ltd","twitter_misc":{"Written by":"Cadence Woodland","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice","url":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice","name":"Data protection \u2013 How to build a culture of good policy and practice - Wilson James","isPartOf":{"@id":"https:\/\/wilsonjames.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#primaryimage"},"image":{"@id":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#primaryimage"},"thumbnailUrl":"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg","datePublished":"2021-10-04T10:36:00+00:00","dateModified":"2022-12-13T14:28:11+00:00","author":{"@id":"https:\/\/wilsonjames.co.uk\/#\/schema\/person\/49941be4c3b9c7a0a3b21ede1658e2d9"},"breadcrumb":{"@id":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#primaryimage","url":"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg","contentUrl":"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg","width":721,"height":484,"caption":"Computer security concept"},{"@type":"BreadcrumbList","@id":"https:\/\/wilsonjames.co.uk\/blog\/data-protection-how-to-build-a-culture-of-good-policy-and-practice#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wilsonjames.co.uk\/"},{"@type":"ListItem","position":2,"name":"Data protection \u2013 How to build a culture of good policy and practice"}]},{"@type":"WebSite","@id":"https:\/\/wilsonjames.co.uk\/#website","url":"https:\/\/wilsonjames.co.uk\/","name":"Wilson James","description":"Wilson James is a leading security, logistics and aviation services provider with over 5,000 employees operating across the UK.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wilsonjames.co.uk\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/wilsonjames.co.uk\/#\/schema\/person\/49941be4c3b9c7a0a3b21ede1658e2d9","name":"Cadence Woodland","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/wilsonjames.co.uk\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b0376243dae4ae8704239a2d3e2a64c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b0376243dae4ae8704239a2d3e2a64c2?s=96&d=mm&r=g","caption":"Cadence Woodland"},"description":"ok"}]}},"jetpack_featured_media_url":"https:\/\/wilsonjames.co.uk\/wp-content\/uploads\/2021\/10\/iStock-155438989.jpg","jetpack_shortlink":"https:\/\/wp.me\/p9jZtb-4RK","jetpack_sharing_enabled":true,"publishpress_future_action":{"enabled":false,"date":"2026-04-24 22:42:36","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category"},"_links":{"self":[{"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/posts\/18708"}],"collection":[{"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/comments?post=18708"}],"version-history":[{"count":8,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/posts\/18708\/revisions"}],"predecessor-version":[{"id":21242,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/posts\/18708\/revisions\/21242"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/media\/18710"}],"wp:attachment":[{"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/media?parent=18708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/categories?post=18708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wilsonjames.co.uk\/wp-json\/wp\/v2\/tags?post=18708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}