This article forms part of a collection to introduce you to what Data Protection and ‘GDPR’ are. It’s based upon staff training that we’ve provided for companies to make sure they had a basic working knowledge and were able to take the steps to protect individuals personal information in their care.
This guide takes you through the overview and basics of Who and What the GDPR applies to. If you have any questions or require consultation or guidance please don’t hesitate to contact me to discuss further.
The General Data Protection Regulation has a much wider definition then the Data Protection Act 1998 that it replaced and covers any information relating to an identified or identifiable living person (even if it's from a collection of data).
When it comes to Website development and infrastructure management, A great example of this is an IP Address - As an IP Address can be used with other information - Like a Name in circumstances to identify someone, it's considered personal data. Other examples Like Name, Address etc are far more obvious. There are 'special categories' of data to cover off more sensitive information that an organisation might store such as; Racial or ethnic origin, political or religious opinions, or information regarding an individuals health (including biometric data such as blood tests, fingerprints and DNA), sex life or sexual orientation.
The GDPR isn't just limited to digital databases but paper-based as well - Generally any bit of data that can be used to identify someone is covered and should only be used and stored if needed and even then should be done so with a good level of security and training.
If you’re trying to work out if the data you hold is Personally Intenfitifable Information (PII) then ask yourself the following questions;
Very simply GDPR applies to all EU organisations and public authorities (such as the Government) that store or process the personal data of EU citizens. On top of this post-Brexit (The exit of the UK from the EU) for the UK it's worth saying that the GDPR was shrined into UK law as part of the Data Protection Act 2018 and has not yet been repealed and as such UK organisations and British citizens also fall under this definition. This means that no matter where in the world the organisation is based if it offers goods and services to individuals in the EU (and the UK) then it must abide by these rules or face legal action.
When it comes to organisations the responsibilities can be broken down into two categories; Those that apply to Data Processors and additional responsibilities that Data Controllers must abide by.
First a quick reminder about the terminology of Data Subject, Data Controller and Data Processor.
To give an example – You (The Data Subject) might work at an IT company (Data Controller) and have submitted your financial information to them to be paid. Your company itself doesn’t handle it’s own finances and outsources them to a specialist accountancy firm (Data Processor) who take your financial details, store them and process as directed by your company.
Data Controllers could also be your bank, your local supermarket, your local government etc.
If your company does have third-party acting on its behalf to process data that falls under GDPR then you will need to make sure you have a contractual agreement with them that lays out the scope of this and the responsibilities that organisation has to adhere to GDPR while working with you.
The only organisations / public entities that GDPR does not apply in full to are certain law enforcement activities where personal data may be processed for national security purposes. It's also important to say that GDPR doesn't apply to personal activities and as such if you write your partners name on a shopping list and lose it in Tescos you cannot be fined by the ICO.

© 2023 Innatus Digital Ltd
Company Registration no. 12849413
Registered in England Wales