Your Guide to GDPR
Explore the TSC eBook on GDPR, covering data protection principles, individual rights, breach reporting and the role of the DPO.
Understanding GDPR: What every employee in your organisation needs to know
The ICO receives an average of 1,276 data breach reports every month. Since its introduction in May 2018, GDPR has resulted in enforcement action against organisations including British Airways and Marriott International. The financial and reputational consequences of non-compliance are severe.
This eBook cuts through the legal complexity and explains data protection law in plain language. From subject access requests to breach reporting timelines, it covers everything your employees need to understand their responsibilities and protect personal data every day.
In this free eBook, you'll discover:
Strengthen GDPR compliance across your organisation
Build a culture of data protection with TSC's GDPR awareness training, eLearning and human risk solutions. Help every employee understand their responsibilities, reduce compliance risk and protect personal data.
GDPR - FAQ
What is GDPR and who does it apply to?
GDPR (General Data Protection Regulation) is EU legislation that governs how organisations collect, store and process personal data. It applies to any organisation handling the data of EU citizens, regardless of where that organisation is based, and in the UK sits alongside the Data Protection Act 2018. Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is greater.
How long do you have to report a data breach under GDPR?
Breaches involving personal or special category data that pose a risk to people's rights and freedoms must be reported to the ICO within 72 hours of discovery. The ICO receives an average of 1,276 data breach reports every month, so employees need to recognise and escalate a suspected breach immediately rather than waiting to be sure.
What is a Subject Access Request (SAR)?
A subject access request lets an individual ask an organisation for a free copy of the personal data it holds about them. Under GDPR, organisations must respond within 30 days, and individuals also have the right to have inaccurate data corrected or erased entirely - often called the "right to be forgotten".