{"id":417,"date":"2017-07-21T19:54:24","date_gmt":"2017-07-21T18:54:24","guid":{"rendered":"https:\/\/newmillennia.creativespark.co.uk\/the-general-data-protection-regulation-what-you-need-to-know\/"},"modified":"2021-05-12T16:21:31","modified_gmt":"2021-05-12T15:21:31","slug":"the-general-data-protection-regulation-what-you-need-to-know","status":"publish","type":"post","link":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/","title":{"rendered":"The General Data Protection Regulation: what you need to know"},"content":{"rendered":"<p>The General Data Protection Regulation (GDPR) will come into effect across the EU on 25 May 2018. Post-Brexit the GDPR will continue to apply to any organisation based outside the EU that provides services within the EU.<\/p>\n<p>So what are the most important changes?<\/p>\n<p><strong>The definition of personal data<\/strong><\/p>\n<p>Personal data is any data which relates to or identifies a living person. The GDPR will expand the definition of personal data to include both location data and biometric data.<\/p>\n<p><strong>The rights for individuals<\/strong><\/p>\n<p>The GDPR will enhance the control an individual has over their personal data. Organisations will have to have the individual\u2019s express consent to process their data unless they can rely on an alternative legal basis (see below). Express consent means consent which is actively and freely given (no opt out boxes).<\/p>\n<p><strong>Additional rights for individuals include:<\/strong><\/p>\n<p>The right to withdraw consent\u00a0 The right to request that any incorrect personal data is corrected (rectification)\u00a0 The right to request that their personal data is erased (the right \u2018to be forgotten\u2019) The right to data portability<\/p>\n<p><strong>The obligations on organisations<\/strong><\/p>\n<p>The GDPR will also impose new obligations on organisations:<\/p>\n<p>Organisations will need express consent to be able to process data. They will no longer be able to rely on pre-ticked or opt-out boxes. However organisations may also be able to rely on \u2018legitimate interests\u2019 and \u2018necessary for the performance of a contract\u2019 to process data, but these must be used only where appropriate. For recruiters, legitimate interest could be used to provide work-finding services generally but express consent would be required to transfer personal data to another party, such as an umbrella company. Some organisations will have to appoint a data protection officer (DPO) because of the nature and volume of personal data that they collect, eg significant amounts of sensitive personal data or because they are a public authority. Under the existing Data Protection Act individuals have the right to make a subject access request (SAR) to find out what data an organisation holds on them. Organisations can currently charge up to \u00a310 per SAR and must respond within 40 days. However under the GDPR, organisations will no longer be able to charge for a SAR except where the individual makes repeated or unfounded SARs. They will also have to respond within one month, though this can be extended to two months where the request is particularly complex.\u00a0 Organisations will have to adhere to the accountability principle which means they will have to show how they are complying with the GDPR, ie that they have appropriate processes in place to inform individuals of their rights, manage requests to withdraw consent, or rectify or delete data when requested.\u00a0 The GDPR allows member states to apply appropriate sanctions for non-compliance including fines of up to 20 million Euros or four per cent of annual worldwide turnover (whichever is the highest) for the most serious breaches.<\/p>\n<p><strong>How the REC can help<\/strong><\/p>\n<p>The REC legal team have created a GDPR FAQ section and factsheet\u00a0for members on our legal guide. The REC have also engaged with the Information Commissioner\u2019s Office to develop recruitment specific guidance. We will continue to support members so that they are well prepared for the changes ahead.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The General Data Protection Regulation (GDPR) will come into effect across the EU on 25 May 2018. Post-Brexit the GDPR will continue to apply to any organisation based outside the EU that provides services within the EU. So what are the most important changes? The definition of personal data Personal data is any data which &#8230;<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-417","post","type-post","status-publish","format-standard","hentry","category-news"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The General Data Protection Regulation: what you need to know - New Millennia<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The General Data Protection Regulation: what you need to know - New Millennia\" \/>\n<meta property=\"og:description\" content=\"The General Data Protection Regulation (GDPR) will come into effect across the EU on 25 May 2018. Post-Brexit the GDPR will continue to apply to any organisation based outside the EU that provides services within the EU. So what are the most important changes? The definition of personal data Personal data is any data which ...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\" \/>\n<meta property=\"og:site_name\" content=\"New Millennia\" \/>\n<meta property=\"article:published_time\" content=\"2017-07-21T18:54:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-12T15:21:31+00:00\" \/>\n<meta name=\"author\" content=\"Paul O&#039;Rourke\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Paul O&#039;Rourke\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\"},\"author\":{\"name\":\"Paul O'Rourke\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/0a5e64690211f8222b3e3e0f0a3f8f64\"},\"headline\":\"The General Data Protection Regulation: what you need to know\",\"datePublished\":\"2017-07-21T18:54:24+00:00\",\"dateModified\":\"2021-05-12T15:21:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\"},\"wordCount\":545,\"articleSection\":[\"News\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\",\"url\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\",\"name\":\"The General Data Protection Regulation: what you need to know - New Millennia\",\"isPartOf\":{\"@id\":\"https:\/\/www.newmillennia.co.uk\/#website\"},\"datePublished\":\"2017-07-21T18:54:24+00:00\",\"dateModified\":\"2021-05-12T15:21:31+00:00\",\"author\":{\"@id\":\"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/0a5e64690211f8222b3e3e0f0a3f8f64\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.newmillennia.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The General Data Protection Regulation: what you need to know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/#website\",\"url\":\"https:\/\/www.newmillennia.co.uk\/\",\"name\":\"New Millennia\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.newmillennia.co.uk\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/0a5e64690211f8222b3e3e0f0a3f8f64\",\"name\":\"Paul O'Rourke\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a556eebffd51d44e67a797c9d9b1f93f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a556eebffd51d44e67a797c9d9b1f93f?s=96&d=mm&r=g\",\"caption\":\"Paul O'Rourke\"},\"url\":\"https:\/\/www.newmillennia.co.uk\/blog\/author\/paul\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The General Data Protection Regulation: what you need to know - New Millennia","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/","og_locale":"en_GB","og_type":"article","og_title":"The General Data Protection Regulation: what you need to know - New Millennia","og_description":"The General Data Protection Regulation (GDPR) will come into effect across the EU on 25 May 2018. Post-Brexit the GDPR will continue to apply to any organisation based outside the EU that provides services within the EU. So what are the most important changes? The definition of personal data Personal data is any data which ...","og_url":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/","og_site_name":"New Millennia","article_published_time":"2017-07-21T18:54:24+00:00","article_modified_time":"2021-05-12T15:21:31+00:00","author":"Paul O'Rourke","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Paul O'Rourke","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/#article","isPartOf":{"@id":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/"},"author":{"name":"Paul O'Rourke","@id":"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/0a5e64690211f8222b3e3e0f0a3f8f64"},"headline":"The General Data Protection Regulation: what you need to know","datePublished":"2017-07-21T18:54:24+00:00","dateModified":"2021-05-12T15:21:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/"},"wordCount":545,"articleSection":["News"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/","url":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/","name":"The General Data Protection Regulation: what you need to know - New Millennia","isPartOf":{"@id":"https:\/\/www.newmillennia.co.uk\/#website"},"datePublished":"2017-07-21T18:54:24+00:00","dateModified":"2021-05-12T15:21:31+00:00","author":{"@id":"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/0a5e64690211f8222b3e3e0f0a3f8f64"},"breadcrumb":{"@id":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.newmillennia.co.uk\/blog\/the-general-data-protection-regulation-what-you-need-to-know\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.newmillennia.co.uk\/"},{"@type":"ListItem","position":2,"name":"The General Data Protection Regulation: what you need to know"}]},{"@type":"WebSite","@id":"https:\/\/www.newmillennia.co.uk\/#website","url":"https:\/\/www.newmillennia.co.uk\/","name":"New Millennia","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.newmillennia.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/0a5e64690211f8222b3e3e0f0a3f8f64","name":"Paul O'Rourke","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.newmillennia.co.uk\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a556eebffd51d44e67a797c9d9b1f93f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a556eebffd51d44e67a797c9d9b1f93f?s=96&d=mm&r=g","caption":"Paul O'Rourke"},"url":"https:\/\/www.newmillennia.co.uk\/blog\/author\/paul\/"}]}},"_links":{"self":[{"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/posts\/417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/comments?post=417"}],"version-history":[{"count":3,"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/posts\/417\/revisions"}],"predecessor-version":[{"id":1280,"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/posts\/417\/revisions\/1280"}],"wp:attachment":[{"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/media?parent=417"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/categories?post=417"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newmillennia.co.uk\/wp-json\/wp\/v2\/tags?post=417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}