Get in Touch Menu

GDPR: Useful insights from the ICO

01 March 2018

Much has been written about GDPR, but one of the more useful recent documents is entitled “Preparing for the General Data Protection Regulation – 12 steps to take now”, published by the Information Commissioner’s Office (ICO) and available at Some of its more useful insights are as follows.

You don’t always need to have a person’s consent in order to process (i.e. hold or use) their data. There are other legal justifications for doing so, and in some cases it’s actually preferable to rely upon these rather than upon ‘consent’. Processing is justified if it’s necessary for the performance of a contract with that person – e.g. if they’re a customer and you need that data to provide goods or services to them. Processing is also justified if it’s in your legitimate business interests, provided that it doesn’t outweigh their privacy rights. This can be more difficult to judge, but would probably not extend to marketing to non-customers.

You’ll need to provide people with more information about the legal basis for processing their data, what data may be processed and for what purpose, how long it will be stored for, and their legal rights. These are known as privacy notices. Current privacy notices won’t be adequate, but we can help you draft new ones.

Unlike now, you’ll be legally required to report data security breaches to the authorities, without undue delay, and, where feasible, within 72 hours of becoming aware of the breach. However, a breach will only need to be reported if it is likely to result in a risk to ‘the rights and freedoms of individuals’. This can be difficult to assess, but we have helped clients with this process in the past.

Any contracts you have with a ‘data processor’ such as a payroll bureau or marketing agency will need to be reviewed, as the GDPR requires you to include certain contractual terms guaranteeing data privacy. We can help you put appropriate terms in place.

Our multi-disciplinary legal teams spend all day, every day helping companies large and small with complex business decisions. Download a handy fact sheet on GDPR compliance here or view key stats in this infographic.

Resources to help

Related articles

Do I really need to bother with a shareholders’ agreement?...


When starting out, many businesses naturally want to keep costs to a minimum. This often results in them regarding a shareholders’ agreement as something optional or something to consider at…

Helen Howes LLM
Trainee solicitor

Protecting your brand on an international scale

Intellectual property & protection

Despite the significant resources which a company will allocate to international brand protection, it is surprising how often trade mark protection programmes are launched without a clear strategy. An international…

Kym Fletcher LLB (Hons) Euro
Consultant, solicitor

Brexit Q&A: How can my business manage post-Brexit risks?


The key to navigating Brexit for any business is planning. Right now, despite the uncertainty around what Brexit may or may not look like, all businesses (whether they trade directly…

Chris Wills LLB (Hons)
Contact us