The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR).
If you hold and process information about your clients, employees or suppliers, you are legally obliged to protect that information. Under the Data Protection Act 2018 you must make sure the information is:
If you handle personal information you may need to register with the Information Commissioner’s Office (ICO) as a data controller. Notification is a statutory requirement and every organisation that processes personal information must notify the ICO unless they are exempt. Failure to notify is a criminal offence.
The ICO has an online Data Protection Self-Assessment Toolkit which provides a ‘health check’ of where organisations are currently in relation to the specific areas covered in the toolkit: records management, security and the handling of subject access requests.
About Data Protection
The ICO has produced lots of resources about Data Protection for organisations which includes tools to assess your lawful basis for processing personal information and resources for reporting a data breach.
Organisations can also sign up to the ICO E-newsletter to stay up to date with new guidance as and when it is released.
The ICO advice service for small organisations Tel: 0303 123 1113
Learn more
We have a series of Data Protection courses which are open to all voluntary sector organisations, with a discount for SCVO members.
The ICO have shared the information governance and legislation training modules they provide to their staff as part of their internal training and made these available for everyone to access.
Resources