{"id":1764,"date":"2018-04-23T14:17:13","date_gmt":"2018-04-23T13:17:13","guid":{"rendered":"http:\/\/teamkinetic.co.uk\/blog\/?p=1764"},"modified":"2018-04-24T14:36:39","modified_gmt":"2018-04-24T13:36:39","slug":"are-you-ready-for-gdpr","status":"publish","type":"post","link":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/","title":{"rendered":"Are you ready for GDPR?"},"content":{"rendered":"<h4>A whitepaper to help you get ready for GDPR and find out what it means for your data.<\/h4>\n<p><a href=\"http:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2018\/04\/Whitepaper-Are-you-ready-for-GDPR.pdf\">Whitepaper &#8211; Are you ready for GDPR<\/a>\u00a0&#8211; Download the paper here.<\/p>\n<h4>What should you be doing now?<\/h4>\n<p>If you haven\u2019t started preparing your organisation for compliance then the next 3 months are crucial. If you have started getting ready for the GDPR deadline, \u00a0keep going.<\/p>\n<p>Make sure your board is bought in to the importance of the project. Having the support you need from the top is vital to the GDPR compliance process.<\/p>\n<p>ONCE THE GDPR COMES INTO FORCE, YOUR BUSINESS MUST:*<\/p>\n<ol>\n<li>Keep a record of data operations and activities and consider if you have the required data processing agreements in place<\/li>\n<li>\u00a0Carry out privacy impact assessments (PIAs) on products and systems<\/li>\n<li>\u00a0If applicable to your organisation, designate a data protection officer (DPO)<\/li>\n<li>\u00a0Review processes for the collection of personal data<\/li>\n<li>\u00a0Be aware of your duty to notify the relevant supervisory authority of a \u00a0\u00a0data breach<\/li>\n<li>Implement \u201cprivacy by design\u201d and \u201cprivacy by default\u201d in the design \u00a0\u00a0of new products and assess whether existing products meet GDPR standards<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h4>What are TeamKinetic doing right now<\/h4>\n<p>See what we have already put in place, to be ready for 25th May 2018.<\/p>\n<p><a href=\"https:\/\/teamkinetic.co.uk\/blog\/2018\/02\/07\/teamkinetic-updates-new-eula-and-data-policy\/\">https:\/\/teamkinetic.co.uk\/blog\/2018\/02\/07\/teamkinetic-updates-new-eula-and-data-policy\/<\/a><\/p>\n<h1>We continue to work with our customers to ensure compliance and understanding.<\/h1>\n<h1>Are you ready for GDPR?<\/h1>\n<h4>Deadline &#8211; 25th May 2018<\/h4>\n<p>Information sourced from <a href=\"about:blank\">UKFast<\/a>, <a href=\"http:\/\/www.blplaw.com\/expert-legal-insights\/articles\/gdpr-and-brexit-uk-government-unveils-data-protection-plans\">Berwin,Leighton,Paisner<\/a> and <a href=\"http:\/\/www.onsidelaw.co.uk\/\">Onside Law<\/a><\/p>\n<h4>Contents<\/h4>\n<p>Let\u2019s refresh<\/p>\n<p>Why has the GDPR come about?<\/p>\n<p>What about Brexit?<\/p>\n<p>What should you be doing now?<\/p>\n<p>Data security is EVERY business\u2019s business<\/p>\n<p>Key changes to consent<\/p>\n<p>Key changes to breach notifications<\/p>\n<p>Are the rules different for electronic communications?<\/p>\n<p>What is TeamKinetic doing right now?<\/p>\n<p>Disclaimer: The information in this whitepaper is for your general guidance only and is not and shall not constitute legal advice. If you need advice on your rights or responsibilities or any legal advice around data protection matters, please obtain specific legal advice and contact an adviser or solicitor.<\/p>\n<h4>Let\u2019s refresh\u2026<\/h4>\n<p>What is the GDPR? The General Data Protection Regulation (GDPR) is a binding legislative act from the European Union for the protection of personal data. The Regulation tackles the inconsistent data protection laws currently existing throughout the EU\u2019s member states and facilitates the secure, free-flow of data.<\/p>\n<p>Why do you need to know about it?<\/p>\n<p>As of April 2016, businesses have been preparing for the legislation coming into effect on 25th May 2018. Although we are in the process of leaving the EU, working towards GDPR compliance remains crucial.<\/p>\n<p>If you fail to comply with the Regulation you could find yourself being fined up to 4% of your company\u2019s global annual turnover and your reputation damaged beyond repair.<\/p>\n<p>That is 4500% increase on current fines that can be issued by the ICO!!<\/p>\n<p>Now that the deadline is just 3 months away, is your organisation ready?<\/p>\n<h4>Why has the GDPR come about?<\/h4>\n<p>There is a need in Europe and beyond for a standardised data protection framework that addresses the rapid technological advancements that have taken place in recent years, putting the personal data of the masses at risk.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2018\/04\/GDPR-why-now-info--300x296.png\" alt=\"\" width=\"359\" height=\"354\" \/><\/p>\n<h4>Where do vulnerabilities lie?<\/h4>\n<p>Everywhere. All organisations are at risk of a cyber-attack, despite common misconceptions that some industries are more secure than others.<\/p>\n<p>The results of a survey carried out by the Information Commissioner\u2019s Office (ICO) of 173 councils at the end of 2016 reveals that more than 15% of councils do not have data protection training for employees processing personal data and a third do not carry out privacy impact assessments (PIAs) as required by the GDPR.<\/p>\n<p>The survey\u2019s release coincided with the news that the ICO had fined Norfolk Council \u00a360,000 for a data breach in which social work files were discovered in a cabinet bought in a second-hand shop by a member of the public.<\/p>\n<p>Capgemini: The Currency of Trust, February 2017<\/p>\n<p>74% of UK SMEs had a security breach in 2016.<\/p>\n<p>While leaving vulnerable information in a cabinet or on a train may seem like a problem from 1997 rather than 2017 &#8211; when cloud technology means physical files never need to leave the office &#8211; the overarching security challenge remains.<\/p>\n<p>Professionals across the public and private sectors must be aware of the nature of the data they are accessing from their home networks and ensure they are doing so securely.<\/p>\n<p>Computer Weekly: Many Councils Still Unprepared for GDPR, March 2017<\/p>\n<h4><\/h4>\n<h4>What about Brexit?<\/h4>\n<p>Despite the vote to leave the EU, UK businesses must continue to work towards GDPR compliance. Not only has the UK government stated that it is good business practice to do so, but the legislation applies to all businesses working within the EU and with EU data. A failure to comply can lead to significant fines and irreparable damage to a company\u2019s reputation.<\/p>\n<p>The latest thinking is that the UK could replace the 1998 Data Protection Act (DPA) with legislation that mirrors the GDPR, enabling the UK to achieve free data flow with the EU post-Brexit. The government has warned that it may take two to three years for the European Council (EC) to decide that the UK has an adequate data protection regime.<\/p>\n<p>While the impact of the Investigatory Powers Act on the UK\u2019s GDPR compliance has yet to be fully understood, it is possible that the mass surveillance and data retention practices carried out under the Act could cause issues when the EC comes to decide whether the UK\u2019s practices are adequate. The existence of these two extraordinarily contradictory legislations could result in a UK equivalent of the Privacy Shield agreement held between the US and the EU to facilitate secure transatlantic data flow.<\/p>\n<p>If your business activities are contained within the UK or elsewhere within Europe, you will have to observe the protections afforded by the GDPR for citizens.<\/p>\n<h4>What happens if my business is not complaint?<\/h4>\n<p>The GDPR introduces a two-tier fine system that emphasises just how small a financial deterrent existed under the Data Protection Act (DPA).<\/p>\n<p>As of the 2018 deadline, any data controller or processor that fails to comply with the Regulation will face the following fines:<\/p>\n<p>&nbsp;<\/p>\n<p>Tier 1<\/p>\n<p>If a data breach occurs that puts highly important data at risj, the data controller\/processor will be fined upto \u20ac20M (\u00a317.25M) or 4% of the previous year\u2019s global annual turnover, whichever is greater.<\/p>\n<p>Tier 2<\/p>\n<p>Any other data breach could lead to fines of up to \u20ac10M (\u00a38.6M) or 2% of the previous year\u2019s global annual turnover, whichever is greater.<\/p>\n<p>&nbsp;<\/p>\n<p>It is estimated that if breaches remain at the same level as in 2015, the fines given will raise 90 fold from \u20ac1.4 billion to \u20ac122 billion<\/p>\n<p>Key changes to consent<\/p>\n<p>Do you ask your customers for permission before you use their data? Do you go a step further and tell them what it will be used for? If the answer to either \u2013 or both \u2013 of these questions is no, you could be in trouble if you don\u2019t start changing your ways before the GDPR deadline.<\/p>\n<p>&nbsp;<\/p>\n<p>Why is consent important?<\/p>\n<p>Consent enables your business to lawfully process data.<\/p>\n<p>Organisations applying the GDPR\u2019s standards are giving individuals greater control over their information and, in turn, building trusting relationships that ultimately keep customers coming back for more.<\/p>\n<p>Any business found to be misusing personal data will be fined according to the highest level of the two-tier system and \u2013 most poignantly \u2013 is at serious risk of damaging its own reputation. When is consent required? You must have the data subject\u2019s consent to lawfully process their data. However, just to confuse things, there are instances that will call for consent to be acquired via alternative methods; we\u2019ll clarify this shortly. Consent is also needed under ePrivacy laws if you\u2019re in the business of tracking communications and installing software and apps on devices.<\/p>\n<p>If you want to use someone\u2019s personal data they must give you explicit consent to do so. This means in practise no pre-ticked boxes, a user must always choose to tick the box.<\/p>\n<p>If you want to use an individual\u2019s personal data for multiple purposes, they must give consent for each purpose, separately<\/p>\n<p>&nbsp;<\/p>\n<p>Who might need an alternative method of gaining consent?<\/p>\n<p>Most commonly, data controllers in a position of power such as public authorities and employers who are likely to find getting valid consent challenging and so must consider the alternative options.<\/p>\n<p>For example, if you are a highly successful eCommerce business is bringing on board a new supplier of garden furniture, you will need a contract with them that clarifies the role of each party and enables you to lawfully process their data.<\/p>\n<p>Whether you are the data controller or processor, you must always record how consent was given, who from, when, how, and what the interested parties were told.<\/p>\n<p>You must not bundle your consent request with your standard terms and conditions.<\/p>\n<p>&nbsp;<\/p>\n<p>Does your consent process meet GDPR standards?<\/p>\n<p>Carry out a thorough review of existing consent processes and asses whether they meet the Regulation\u2019s requirements. if they do, there is no need to request consent from the subject again.<\/p>\n<h4>Key changes to breach notifications<\/h4>\n<p>Europe had a phenomenally inconsistent data protection landscape. It meant that when a Switzerland-based business suffered a data breach affecting people in Greece, Italy and Spain, the organisation would need to comply with the breach notification standards of each of the three member states.<\/p>\n<p>This lack of uniformity throughout Europe means that while some member states, such as Spain and Germany, are recognised for their rigorous data breach privacy laws, there are also member states with minimal to no regulations in place.<\/p>\n<p>In this environment, organisations in lax member states have not needed to notify an authority of a breach.<\/p>\n<p>The GDPR smooths all this out with the introduction of a single breach notification requirement.<\/p>\n<p>&nbsp;<\/p>\n<h4>What is a personal data breach?<\/h4>\n<p>A personal data breach is not simply the loss of data but a breach of security, resulting in the destruction, loss, alteration, unauthorised disclosure of or access to personal data.<\/p>\n<p>When must the relevant supervisory authority be notified?<\/p>\n<p>The relevant supervisory authority must be informed of any data breach that puts an individual\u2019s rights and freedoms at risk. This includes a loss of confidentiality and financial loss.<\/p>\n<p>Data controllers must inform the supervisory authority without undue delay and within 72 hours of learning of a personal data breach. They must state:<\/p>\n<ol>\n<li>Its nature<\/li>\n<li>The approximate number of people affected<\/li>\n<li>The contact information for the organisation\u2019s DPO (if one has been appointed)<\/li>\n<\/ol>\n<p>The controller must also pin-point the likely consequences of the breach and the measures taken to reduce further risk to those affected.<\/p>\n<p>Data processors must tell the data controller about a data breach without undue delay after having become aware of it.<\/p>\n<p>If a breach is significant enough that it is in the public interest, those responsible \u2013 be that the controller or processor \u2013 must do so without undue delay.<\/p>\n<p>The impact of data breaches If we hark back to our real world TalkTalk and Yahoo examples, we can see that the severe consequences each company experienced following their respective breaches were related to how they handled the aftermath of the breach and not simply because the breach happened in the first place.<\/p>\n<p>What should you be doing now?<\/p>\n<p>A personal data breach is not just the loss of that data but a breach of security, resulting in the destruction, loss, alteration, unauthorised disclosure of or access to personal data.<\/p>\n<ul>\n<li>Educate your employees about \u00a0\u00a0\u00a0personal data breaches and how to \u00a0\u00a0spot when one has occurred.<\/li>\n<li>Set-up an internal process for reporting \u00a0\u00a0a personal data breach.<\/li>\n<li>Make sure you have the internal resources and processes in place to \u00a0\u00a0detect and investigate breaches. Speak to any third-party data processers if they are storing your data.<\/li>\n<li>Put an incident response plan in place.<\/li>\n<\/ul>\n<h4>Are the rules different for electronic communications?<\/h4>\n<p>No, not really. The EU has introduced a complementary legal framework to the GDPR to clarify exactly what data controllers and processors must be doing to protect individuals\u2019 communications; electronic or otherwise.<\/p>\n<ol>\n<li>New cookies responsibilities \u00a0\u00a0for browser providers Users must be given the choice to consent to cookies as part of the browser software set-up. This should reduce or eliminate cookie banners on websites entirely.<\/li>\n<li>Extra-territoriality and 4% fines The Regulation no longer applies solely to the EU. It applies to anyone in the world that provides publicly-available \u201celectronic communications services\u201d to acquire data from the devices of EU citizens. Any organisation that breaches the Regulation will be subject to the GDPR\u2019s two-tier fine system. That means you should be paying attention even if your business is contained within the UK.<\/li>\n<li>The Regulation application is expanded Unlike its predecessor, the ePrivacy Directive, the ePrivacy Regulation goes beyond the traditional telecommunications organisations and internet service providers. It incorporates messaging apps like WhatsApp, and email providers, amongst other communications suppliers such as Facebook and Snapchat.<\/li>\n<li>New rules for processing communications data The Regulation introduces new rules for handling: what was said, who said it, where and when. This data is confidential; interfering with it could result in a Tier 1 fine.<\/li>\n<li>Exemption analytics cookies Businesses are exempt from the cookie consent requirement when using firstparty analytics. However, using third-party analytics platforms such as Google Analytics requires user consent.<\/li>\n<\/ol>\n<p>For the non-techy amongst you, \u2018party\u2019 refers to the website that places the cookie. So when you visit www.ukfast.co.uk, and you find the domain of the cookie placed on your computer is www.ukfast.co.uk, this is a first-party cookie. If you visit www.ukfast. co.uk and a cookie by a suspiciously dissimilar name appears, this cookie has been placed by a third party.<\/p>\n<p>Like the GDPR, the ePrivacy Regulation will come in to effect on the 25th May 2018.<\/p>\n<p>Source: <a href=\"http:\/\/privacylawblog.fieldfisher.com\/2017\/the-new-e-privacy-regulation-what-you-need-to-know\/%20\">http:\/\/privacylawblog.fieldfisher.com\/2017\/the-new-e-privacy-regulation-what-you-need-to-know\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A whitepaper to help you get ready for GDPR and find out what it means for your data. Whitepaper &#8211; Are you ready for GDPR\u00a0&#8211; Download the paper here. What should you be doing now? If you haven\u2019t started preparing your organisation for compliance then the next 3 months are crucial. If you have started [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[2,4,5,132],"tags":[135,134,133,92,96],"class_list":["post-1764","post","type-post","status-publish","format-standard","hentry","category-application-features-and-tutorials","category-policy-and-operations","category-technical-updates","category-whitepaper","tag-best-practice","tag-data","tag-gdpr","tag-volunteer","tag-volunteer-management"],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.10 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\r\n<title>Are you ready for GDPR? - TeamKinetic<\/title>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_GB\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"Are you ready for GDPR? - TeamKinetic\" \/>\r\n<meta property=\"og:description\" content=\"A whitepaper to help you get ready for GDPR and find out what it means for your data. Whitepaper &#8211; Are you ready for GDPR\u00a0&#8211; Download the paper here. What should you be doing now? If you haven\u2019t started preparing your organisation for compliance then the next 3 months are crucial. If you have started [&hellip;]\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\" \/>\r\n<meta property=\"og:site_name\" content=\"TeamKinetic\" \/>\r\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/TeamKineticUK\" \/>\r\n<meta property=\"article:published_time\" content=\"2018-04-23T13:17:13+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2018-04-24T13:36:39+00:00\" \/>\r\n<meta property=\"og:image\" content=\"http:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2018\/04\/GDPR-why-now-info--300x296.png\" \/>\r\n<meta name=\"author\" content=\"Chris Martin\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:creator\" content=\"@TeamKineticUK\" \/>\r\n<meta name=\"twitter:site\" content=\"@TeamKineticUK\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Chris Martin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\"},\"author\":{\"name\":\"Chris Martin\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/person\/faa34760f4a3d387850388450ba51cb6\"},\"headline\":\"Are you ready for GDPR?\",\"datePublished\":\"2018-04-23T13:17:13+00:00\",\"dateModified\":\"2018-04-24T13:36:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\"},\"wordCount\":2321,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#organization\"},\"keywords\":[\"best practice\",\"data\",\"GDPR\",\"volunteer\",\"volunteer management\"],\"articleSection\":[\"Application Features and Tutorials\",\"Policy and Operations\",\"Technical Updates\",\"Whitepaper\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\",\"url\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\",\"name\":\"Are you ready for GDPR? - TeamKinetic\",\"isPartOf\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#website\"},\"datePublished\":\"2018-04-23T13:17:13+00:00\",\"dateModified\":\"2018-04-24T13:36:39+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/teamkinetic.co.uk\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Are you ready for GDPR?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#website\",\"url\":\"https:\/\/teamkinetic.co.uk\/blog\/\",\"name\":\"TeamKinetic\",\"description\":\"Connect, with great value volunteer management software\",\"publisher\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/teamkinetic.co.uk\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#organization\",\"name\":\"TeamKinetic\",\"url\":\"https:\/\/teamkinetic.co.uk\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2023\/06\/logo-TeamK.png\",\"contentUrl\":\"https:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2023\/06\/logo-TeamK.png\",\"width\":1850,\"height\":498,\"caption\":\"TeamKinetic\"},\"image\":{\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/TeamKineticUK\",\"https:\/\/twitter.com\/TeamKineticUK\",\"https:\/\/www.instagram.com\/teamkineticuk\/\",\"https:\/\/www.linkedin.com\/company\/teamkinetic\/\",\"https:\/\/www.youtube.com\/c\/TeamKinetic\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/person\/faa34760f4a3d387850388450ba51cb6\",\"name\":\"Chris Martin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/18fdb09a46964a776472ea0edea8ee9b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/18fdb09a46964a776472ea0edea8ee9b?s=96&d=mm&r=g\",\"caption\":\"Chris Martin\"},\"url\":\"https:\/\/teamkinetic.co.uk\/blog\/author\/christeamkinetic-co-uk\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Are you ready for GDPR? - TeamKinetic","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/","og_locale":"en_GB","og_type":"article","og_title":"Are you ready for GDPR? - TeamKinetic","og_description":"A whitepaper to help you get ready for GDPR and find out what it means for your data. Whitepaper &#8211; Are you ready for GDPR\u00a0&#8211; Download the paper here. What should you be doing now? If you haven\u2019t started preparing your organisation for compliance then the next 3 months are crucial. If you have started [&hellip;]","og_url":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/","og_site_name":"TeamKinetic","article_publisher":"https:\/\/www.facebook.com\/TeamKineticUK","article_published_time":"2018-04-23T13:17:13+00:00","article_modified_time":"2018-04-24T13:36:39+00:00","og_image":[{"url":"http:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2018\/04\/GDPR-why-now-info--300x296.png"}],"author":"Chris Martin","twitter_card":"summary_large_image","twitter_creator":"@TeamKineticUK","twitter_site":"@TeamKineticUK","twitter_misc":{"Written by":"Chris Martin","Estimated reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#article","isPartOf":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/"},"author":{"name":"Chris Martin","@id":"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/person\/faa34760f4a3d387850388450ba51cb6"},"headline":"Are you ready for GDPR?","datePublished":"2018-04-23T13:17:13+00:00","dateModified":"2018-04-24T13:36:39+00:00","mainEntityOfPage":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/"},"wordCount":2321,"commentCount":2,"publisher":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/#organization"},"keywords":["best practice","data","GDPR","volunteer","volunteer management"],"articleSection":["Application Features and Tutorials","Policy and Operations","Technical Updates","Whitepaper"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/","url":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/","name":"Are you ready for GDPR? - TeamKinetic","isPartOf":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/#website"},"datePublished":"2018-04-23T13:17:13+00:00","dateModified":"2018-04-24T13:36:39+00:00","breadcrumb":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/teamkinetic.co.uk\/blog\/2018\/04\/are-you-ready-for-gdpr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/teamkinetic.co.uk\/blog\/"},{"@type":"ListItem","position":2,"name":"Are you ready for GDPR?"}]},{"@type":"WebSite","@id":"https:\/\/teamkinetic.co.uk\/blog\/#website","url":"https:\/\/teamkinetic.co.uk\/blog\/","name":"TeamKinetic","description":"Connect, with great value volunteer management software","publisher":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/teamkinetic.co.uk\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/teamkinetic.co.uk\/blog\/#organization","name":"TeamKinetic","url":"https:\/\/teamkinetic.co.uk\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2023\/06\/logo-TeamK.png","contentUrl":"https:\/\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2023\/06\/logo-TeamK.png","width":1850,"height":498,"caption":"TeamKinetic"},"image":{"@id":"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/TeamKineticUK","https:\/\/twitter.com\/TeamKineticUK","https:\/\/www.instagram.com\/teamkineticuk\/","https:\/\/www.linkedin.com\/company\/teamkinetic\/","https:\/\/www.youtube.com\/c\/TeamKinetic"]},{"@type":"Person","@id":"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/person\/faa34760f4a3d387850388450ba51cb6","name":"Chris Martin","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/teamkinetic.co.uk\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/18fdb09a46964a776472ea0edea8ee9b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/18fdb09a46964a776472ea0edea8ee9b?s=96&d=mm&r=g","caption":"Chris Martin"},"url":"https:\/\/teamkinetic.co.uk\/blog\/author\/christeamkinetic-co-uk\/"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p8AVXm-ss","jetpack-related-posts":[{"id":1822,"url":"https:\/\/teamkinetic.co.uk\/blog\/2018\/05\/gdpr-frequently-asked-questions-for-teamkinetic\/","url_meta":{"origin":1764,"position":0},"title":"GDPR Frequently Asked Questions for TeamKinetic","author":"Rolf Herbert","date":"18th May 2018","format":false,"excerpt":"This document will continue to develop over time as we respond to more questions from our customer and users.\u00a0 Please feel free to subscribe to stay up to date. 1. Do we need to get renewed consent from every volunteer and provider? We will be asking all volunteers and providers\u2026","rel":"","context":"In &quot;Policy and Operations&quot;","block_context":{"text":"Policy and Operations","link":"https:\/\/teamkinetic.co.uk\/blog\/category\/policy-and-operations\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":6289,"url":"https:\/\/teamkinetic.co.uk\/blog\/2020\/08\/we-are-updating-our-terms-and-conditions\/","url_meta":{"origin":1764,"position":1},"title":"We are updating our Terms and Conditions","author":"Chris Martin","date":"14th August 2020","format":false,"excerpt":"Periodically we review and update our operating terms and conditions that form the basis of our relationship with our customers. This time around we are proposing two changes that we wanted to clarify with our customers. Since the introduction of GDPR we have been reviewing our approach to data processing\u2026","rel":"","context":"In &quot;Policy and Operations&quot;","block_context":{"text":"Policy and Operations","link":"https:\/\/teamkinetic.co.uk\/blog\/category\/policy-and-operations\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1525,"url":"https:\/\/teamkinetic.co.uk\/blog\/2018\/01\/teamkinetic-new-eula-and-data-policy\/","url_meta":{"origin":1764,"position":2},"title":"TeamKinetic: New EULA and Data Policy","author":"Chris Martin","date":"29th January 2018","format":false,"excerpt":"On Friday 26th January 2018 our new EULA and Data Policy was enacted. Since 2016, organisations have been preparing for the reformation of data protection in the form of GDPR (General Data Protection Regulation). For many organisations operating within the third sector, a certain apprehension has loomed, driven by concerns\u2026","rel":"","context":"In &quot;News &amp; Views&quot;","block_context":{"text":"News &amp; Views","link":"https:\/\/teamkinetic.co.uk\/blog\/category\/news-views\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2024\/02\/blog-image-36.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2024\/02\/blog-image-36.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2024\/02\/blog-image-36.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":3111,"url":"https:\/\/teamkinetic.co.uk\/blog\/2019\/06\/how-can-your-not-for-profit-prepare-for-brexit\/","url_meta":{"origin":1764,"position":3},"title":"How Can YOUR Not-For-Profit Prepare For Brexit?","author":"Rolf Herbert","date":"6th June 2019","format":false,"excerpt":"You may not know much about Brexit considering it's not spoken about every single day! There are many rules and regulations that will affect the economy and organisations as a direct result of Brexit. This also applies to civil society organisations or Not-for-profits. So, how exactly can these types of\u2026","rel":"","context":"In &quot;News &amp; Views&quot;","block_context":{"text":"News &amp; Views","link":"https:\/\/teamkinetic.co.uk\/blog\/category\/news-views\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2107,"url":"https:\/\/teamkinetic.co.uk\/blog\/2018\/08\/good-bad-and-ugly-of-the-internet-for-volunteer-managers\/","url_meta":{"origin":1764,"position":4},"title":"Understanding the Good, the Bad and the Ugly of the internet for volunteer managers","author":"Chris Martin","date":"30th August 2018","format":false,"excerpt":"TeamKinetic believes that the internet has the potential for transformation in our world comparable to the Gutenberg's printing press\u00a0, but if the last few years have taught us anything, it's that the internet reflects both the very best and very worst of human nature. What do volunteer managers need to\u2026","rel":"","context":"In &quot;Community&quot;","block_context":{"text":"Community","link":"https:\/\/teamkinetic.co.uk\/blog\/category\/community\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2018\/08\/flat550x550075f.u1-272x300.jpg?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":16876,"url":"https:\/\/teamkinetic.co.uk\/blog\/2025\/09\/iso-27001-certification\/","url_meta":{"origin":1764,"position":5},"title":"TeamKinetic: Setting the Standard for the Sector with ISO 27001 Certification","author":"Alex Evans","date":"12th September 2025","format":false,"excerpt":"Achieving ISO 27001 certification is a significant undertaking. For us at TeamKinetic, it was a worthwhile investment that underscores our deep commitment to data security and governance. This certification is not just a badge; it's a testament to our ongoing efforts to protect our clients' information and to set the\u2026","rel":"","context":"In &quot;News &amp; Views&quot;","block_context":{"text":"News &amp; Views","link":"https:\/\/teamkinetic.co.uk\/blog\/category\/news-views\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2025\/09\/ISO27001.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2025\/09\/ISO27001.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2025\/09\/ISO27001.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2025\/09\/ISO27001.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/teamkinetic.co.uk\/blog\/wp-content\/uploads\/2025\/09\/ISO27001.png?resize=1400%2C800&ssl=1 4x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=1764"}],"version-history":[{"count":7,"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1764\/revisions"}],"predecessor-version":[{"id":1797,"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1764\/revisions\/1797"}],"wp:attachment":[{"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=1764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=1764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teamkinetic.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=1764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}