Skip to content

15 August, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • disclosure

      Cyber resilience is a test of leadership

      Cyber threat is moving fast, and boards need to step up now in order to...

      climate litigation

      Why climate transition is a governance imperative

      The ‘just transition’ to a sustainable, resilient economy means navigating systemic change fairly and successfully.

      board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

  • Comment
      • View all
    • climate litigation

      Why climate transition is a governance imperative

      The ‘just transition’ to a sustainable, resilient economy means navigating systemic change fairly and successfully.

      create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC Annual Review of Audit Quality 2026

      This Financial Reporting Council report uses findings from its supervisory activities to assess audit quality...

      Governance Guide: How Boards Drive Growth

      This Board Agenda Governance Guide investigates how directors can evolve to drive performance and growth...

      Organizational Transformation in the Age of AI

      This World Economic Forum paper looks at how organisations must re-architect their workflows and operating...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

GDPR and staff data: the final countdown

by Lucy Trevelyan on January 25, 2018

General Data Protection Regulation comes into force in May, with sweeping new requirements for businesses that handle personal data.

data, data protection, GDPR

Image: Rawpixel.com / Shutterstock

Favorite

Businesses across the EU have just four months to prepare for the implementation of General Data Protection Regulation (GDPR).

The new regulation—which will take immediate effect from 25 May 2018 without any need for domestic law ratification—introduces sweeping new requirements for companies handling personal data.

“Businesses need to understand the data held within the organisation, where that data comes from and where/how it is stored…”

–Sybille Steiner, Irwin Mitchell

Sybille Steiner, partner at law firm Irwin Mitchell, said that organisations need to conduct data audit to identify areas where action needs to be taken to ensure compliance.

“Businesses need to understand the data held within the organisation, where that data comes from and where/how it is stored, what happens to it while it is within the organisation and when and how it is deleted.

“Where any areas of non-compliance are identified, or where activities pose a risk, the business will need to formulate a plan to address them.”

GDPR requires organisations which process data—whether internally or externally—to obtain “specific, informed and freely given” consent from individuals whose data is being processed. This means businesses need to check their consent practices and existing consents and refresh them if they don’t meet the GDPR standard.

Consent requires a positive opt-in; pre-ticked boxes or any other method of default consent will not suffice, and consent requests should be kept separate from other terms and conditions.

Steiner said that it is common for businesses to have general “catch-all” consent clauses within employee contracts or data protection policies.

“These will no longer be valid forms of consent and businesses need to review employment contracts and policies to decide whether consent should be relied upon at all and if yes, in which form.”

Data protection review

Data protection policies need to be reviewed, she said, and should clearly set out:

  • what personal data is and why data protection is important;
  • information about the collection and use of personal data, on what basis and why this is processed;
  • what the data rights of employees are and how the employer will ensure these are upheld;
  • how data breaches are dealt with; and
  • the consequences, for the business and individual, of non-compliance.

“The written policy should also set out when and how specific categories of personal data are deleted,” she added. “It should include the new ‘right to be forgotten’, requiring data processors to delete personal data where the data is no longer necessary for the purpose in relation to which it was collected, consent has been withdrawn or if the data was processed in breach of the GDPR.”

All staff should be trained in handling data, she said, and businesses should have an internal reporting procedure in place to ensure they abide by the GDPR duty on all organisations to report any data breach within 72 hours.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Are you asking the right questions of your data team?
    August 5, 2021
    Question mark surrounded by binary code

    Knowing how to ask great questions is perhaps the most underappreciated skill of great data-driven leaders.

  • Ethics in the technology sector remains a headline issue
    January 26, 2022
    Businessman has biometric data scanned

    For a second year running technology is the sector that garnered the most news stories about ethical lapses—with data privacy a key concern.

  • Boards are ‘inundated with data’ and face growing compliance risks
    January 10, 2024
    inundated with data

    Organisations are struggling to achieve the data literacy that would empower their decision-making, new survey reveals.

  • Embrace data analytics to boost risk assessment, advises CIIA
    November 30, 2022
    risk data analytics

    Chartered Institute of Internal Auditors’ report cites a lack of skills, resources and time as organisational barriers to effective analysis.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy