Building trust through data
Data protection touches every organisation, whether you handle customer details, staff records or marketing lists. This collection brings together straightforward resources on UK GDPR, including the basics, common pitfalls and practical steps you can take to stay compliant. If you’re unsure what applies to you, we can help you get clarity.
Resource collection
Breach notification
The UK GDPR introduces stricter penalties for organisations where there has been a personal data breach.
Consent
Organisations need to review how they obtain consent from individuals to hold and process their data.
Data controllers and data processors
As well as imposing obligations on data controllers the UK GDPR imposes direct obligations on data processors.
Data management
Organisations need to properly manage data to be able to comply with requests from individuals. Under the UK GDPR, individuals have increased rights to manage the information which data controllers and data processors hold, process, and keep about them.
Data protection officers
Whether or not you are legally obliged to appoint a data protection officer depends on the nature of your organisation.
Data subject access requests
Businesses must respond to requests from individuals to receive a copy of the data they hold about them.
Ensuring UK GDPR compliant marketing
With the UK GDPR now in force, you should review how you obtain, store and use customers’ data for marketing purposes.
Lawful basis
To lawfully process personal data, you must be able to demonstrate you have a lawful basis and you should set this out in your privacy notice.
Managing employee data under UK GDPR
Employee data should be managed and reviewed periodically to ensure your business maintains compliance with the UK GDPR.
Mediation
Mediation provides high levels of flexibility and confidentiality and is increasingly popular in the commercial world. We’re highly experienced at using it successfully for clients.
Personal data and special category data
The UK GDPR singles out some personal data as likely to be more sensitive and requiring more protection.
Privacy notices
Organisations must update privacy notices to detail the lawful basis for processing, data retention periods, and the right to complain to the ICO.
Recovery of evidence for claims in Scotland
There is no automatic entitlement to relevant information in litigation in Scotland, and the procedure for recovery of documents is very different to other jurisdictions.
The right to erasure
Organisations need to have processes in place to enable them to manage requests from individuals for data to be deleted.
UK GDPR compliant business practices
We look at what the introduction of new data protection rules means for your approach to customers and business contracts.
UK GDPR privacy notice for candidates
Lindsays is a "data controller". This means that we are responsible for deciding how we hold and use personal information about anyone who applies to work with us.