Aug
23
Are you sat there thinking well isn’t that obvious to know what personal data I collect and use? If you are, you are in the minority. It is very surprising how many businesses don’t really know what data they are collecting and using or in some cases collecting and not using.
One of the key tasks that any business needs to do, in their data protection compliance journey, is to find out what data they collect and use.
Remember you will be breach of the GDPR principles if you collect too much personal data and don’t actually do anything with it. Similarly, if you collect too little personal data for a business activity you can also be breaching the GDPR principles.
It is therefore really important to understand what personal data you collect and use, and why you actually need it.
Knowing what data you have is essential for various other aspects of your GDPR compliance, including:
So it is really important to have some sort of data inventory in place.
How you build a data inventory is entirely up to you.
By just doing a simple Google search you will find various free templates available. However you will probably find that you will need to adapt these templates to be more specific for your own business needs.
There are businesses who provide electronic data mapping tools. There is obviously a cost to these which can be an expensive outlay for a business. If you are a large business that collects and uses lots of different types of personal data for different purposes it may be money well spent. If you are a small business though I would have a go at doing a manual data inventory yourself.
You can very simply create a manual data inventory template in a Word document or Excel spreadsheet. Firstly, your data inventory needs to record all your different processing activities. Secondly it should, at the very least, include the following details:
Think about all the different ways in which you have collected the data, e.g. online web form; customer order; exhibition stand, etc.
These are all the different types of individuals who you got the data from, e.g. customer; member of the public; supplier; employee; etc.
These are all the different types of personal data that are being processed, e.g. employment; medical; financial; etc.
Think about why you need the data and what will you be using it for, e.g. employment purposes; fulfil a customer order; marketing; etc.
Remember before you begin collecting and using personal data you need to identify a lawful ground to undertake the processing, e.g. consent, contractual obligation, etc. You will need to identify additional lawful grounds if you are processing any of the special categories of personal data, e.g. medical data, racial or ethnic data, religious data, etc.
Think about who you sharing or disclosing the data to, who has asked for the data, who you give the data to for them to undertake work on your behalf (known as a data processor), etc.
List all the countries and the GDPR appropriate safeguard you have in place to make that transfer, e.g. standard contractual clauses, adequacy regulation, etc.
Think about how long you intend to keep the data for. Do you have any legal obligation to keep the data for a set period of time.
What are the security measures you have in place to store the data.
It makes GDPR compliance easier. As outlined earlier a data inventory will help you comply with lots of other areas of GDPR.
It can make GDPR compliance harder. Without knowing what data you have and why, you will spend more time, resource and money trying to comply with all your other GDPR compliance obligations.
The UK’s Information Commissioner’s Office could ask you about your personal data collection and use. If the ICO has received a complaint about your processing activities they will investigate. They will want to know all about why you need the data, how you get it and what you do with the data.