Before you start, you may with to visit the official Government ICO section on GDPR
So...you might be asking, what is GDPR all about? Well GDPR is coming into play to better protect the information that is held of individuals by the companies that procure them. It is centered around the principles of transparency and consent. All companies will need to comply and GDPR stretches far beyond the existence of a website and right into your business practices as a whole.
Principally, you should be assessing your entire business and asking yourselves the following:
1. What personal information are we collecting about our customers and employees (and potential employees).
2. What are we using this personal information for and is it justified.
3. Where and how are we storing this data.
4. How long are we retaining this information for.
Note that GDPR only concerns itself with data that is able to identify an individual and not a company. This includes personal emails (and not generic emails such as accounts@)
GDPR will inevitably mean changes in how you operate parts of your business and to improve transparency and integrity of the data you keep. Beyond these changes it also means that you have to have a clear and transparent policy on all of the above and potentially appoint a Data Protection Officer if required.
