What we do
data protection & PRIVACY
Running a business means using personal data.
That will trigger data protection and privacy laws at home and, if you sell overseas, often abroad. Although the rules vary from one place to another, most data protection laws share some key principles:
- Keep records of what personal data you are processing and why
- Safeguard personal data against accidental loss and unlawful access
- Act promptly if you suffer a personal data breach
- Be transparent and fair with people when you use their data
- Have policies in clear and widely understandable language
- Keep personal data accurate and up to date
Plain English Law advises organisations worldwide on the UK laws covering data protection (the UK GDPR and the Data Protection Act 2018) and e-privacy (PECR 2003). We are also well connected with data protection and privacy lawyers across the rest of the world.
data protection services
data breach response
data subject requests
UK GDPR REPRESENTATIVE SERVICE
FOR DATA PROTECTION OFFICERS
?
FAQ's
Got a question about data protection and privacy law?
Take a look at our FAQs.
The original GDPR — or the General Data Protection Regulation — is European Union legislation that came into force in 2018. The UK was still an EU member at that time.
With Brexit, the UK adopted a somewhat modified version of the original GDPR, coupled with complementary rules in the Data Protection Act 2018. As a result, we now refer to the UK GDPR and the EU GDPR as separate laws.
Fortunately, for most businesses the UK GDPR is effectively the same as the EU GDPR on most issues. The rules haven’t changed significantly yet. And if the UK GDPR diverges from the EU version in the future, UK businesses may still need to comply with the EU GDPR when processing personal data about people located in the EU.
Underpinning the UK GDPR is the belief that privacy is a fundamental right. As digital technologies extend further into our lives, so too do the threats to our personal privacy.
For governments worldwide, there’s a balance to be struck. Some voters are happy for businesses to use their personal data to sell more and create jobs. Others demand robust privacy protection.
The UK GDPR tries to strike a balance by letting organisations use personal data if they stick to a series of data protection principles. Some view the UK GDPR as too restrictive and anti-business. Others argue there are too many loopholes, enforcement is lax and personal data is still routinely misused without serious consequences.
Wherever you sit in the debate, the UK GDPR is law.
The official GDPR definition is ‘any information relating to an identified or identifiable natural person’.
What does that actually mean?
A ‘natural person’ just means a living human being. They are ‘identified or identifiable’ if it’s at least reasonably possible to work out who the information is about, and ‘any information’ is as broad as it sounds.
‘Relating to’ means information that describes a person accurately. Importantly, it also includes information about a person that is not accurate.
In practice, working out whether the information relates to ‘an identified or identifiable natural person’ is usually straightforward. Often they are named directly in the data itself. Sometimes you can work out indirectly who they are, from a job title or other contextual details.
However, a document with someone’s name on it is not necessary full of personal data about that person. Think about all the emails you send or receive at work. They all have your name, but the contents of the emails will mostly not be about you. (As an example, consider an email about a customer order. It will rarely tell the reader anything about you, aside from the fact you sent or received it.)
This term — also known as ‘Article 9 data’ — covers particularly sensitive personal data that could be misused to discriminate against or persecute an individual.
Under the UK GDPR, special category personal data covers:
- Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership
- Genetic data
- Biometric data — for example facial recognition, retina scans, fingerprints — when used to uniquely identify an individual
- Data about an individual’s health, sex life, or sexual orientation
Article 9 data is subject to extra protections under the UK GDPR and the Data Protection Act 2018 (they must be read together). This kind of personal data can only be used under a limited set of conditions.
Processing special category data without justification can lead to significant penalties, not to mention an almost guaranteed PR disaster for the company.
In the UK GDPR, processing means performing ‘any operation or set of operations’ on the data. In plain language, ‘processing’ means ‘doing stuff’ with data. This includes:
- Collecting, storing, retrieving;
- Analysing, organising, sharing;
- Archiving, deleting, and destroying data.
Important: merely storing data is processing it. Keeping data just in case it might come in useful one day is still processing it (and is difficult or impossible to justify).
Minimising data storage is one of the most effective ways for companies to reduce their privacy risk. Why?
Data subject
Every item of personal data is data about one or more living individuals. Those individuals are called ‘data subjects’ under the UK GDPR.
An organisation can’t be a data subject because it’s not an individual. Therefore, personal data about an organisation does not exist.
However, the organisation’s employees are data subjects. You might have personal information about the employees of your customers and customers, past and present employees, unsuccessful job candidates, and employees of your vendors. The data could be as simple as name and contact details, or it could be more detailed and potentially intrusive.
Controller
Whenever personal data is processed, someone must be acting as a controller of that processing — usually an organisation such as a company or public sector agency.
Controllers are the decision makers. They decide ‘the purposes and means of the processing of personal data’. In plainer language, a controller decides why and how personal data is being processed.
To decide who is a controller, ask which organisation decides what data to process, why it’ll be processed, who will do the processing, and where and how it will be done.
A controller can do their own processing, or contract out to another organisation.
Some processing activities have a single controller. Some datasets are processed in many different ways, with different processing operations under different controllers.
Finally, some situations involve more than one controller acting together, as ‘joint controllers’. This is a potentially risky situation for a controller to be in, and it needs careful management. Joint controllers can become liable for each other’s UK GDPR violations.
Processor
A processor is essentially a service provider, processing personal data on behalf of a controller.
Processors do not decide the purposes and means of processing. If they start making those decisions, they automatically become controllers. If you are supposed to be a processor only, but you start using the data for your own purposes, you usually become a controller no matter what your data processing agreement says.
Acting as a controller will trigger a number of compliance requirements, including letting all the data subjects know who you are and what you are doing with the personal data.
