🔒 Be Secure
Once you have access to customer data, it is your responsibility to keep it secure.
If there is a data breach and customer information is compromised, you could face enforcement action and fines from the ICO. Make sure you:
🔑 Password-protect or encrypt files and emails containing customer data.
👥 Only give access to customer data to people who need it.
🛡️ Keep customer information secure when storing or sharing it.
📋 Subject Access Requests
If a customer contacts you asking why they are receiving marketing from you, you should be able to explain how you obtained their data and why you are using it.
You must respond to a valid Subject Access Request (SAR) within the applicable legal timeframe. In most cases, organisations have one month to respond.
💡 Tip: Make sure you have processes in place to identify, manage and respond to data protection requests.
🗑️ Right to Be Forgotten
Customers may have the right to request that their personal data is deleted from your systems.
If a customer asks to be removed from your database, you should assess and action the request in accordance with applicable data protection laws. This is particularly important if they have also asked you to stop receiving marketing communications.
🤔 Still Confused?
GDPR can feel like a lot to take in, but there is plenty of guidance available to help.
For more information, visit the ICO website, where you'll find useful guidance on data protection and GDPR.
⚠️ Please note: We are not legal advisors. If you're unsure about your legal obligations, we recommend seeking advice from a solicitor or other qualified legal professional.
