Call our Experts on 0333 014 6220 - For Support [email protected] - For Enquiries enquiries@immervox.com

Five Data Protection Checks Every SME Should Make

Data protection isn’t just a compliance exercise. The launch of the ICO’s new Data Protection Essentials programme is a useful reminder that data protection isn’t something that only matters to large organisations with dedicated compliance teams. Most businesses handle personal information every day. The question is whether that information is being handled securely, appropriately, and consistently.

The ICO says its new training is designed to help smaller organisations understand how data protection applies to everyday activities, including sharing information, managing records, marketing and reducing the risk of data breaches.

But you don’t necessarily need to wait until you’ve completed a training course to start asking some basic questions. Here are five checks we think every SME should consider:

  1. Who can access your information?

One of the simplest questions to ask is: Does everyone who can access our information actually need to?

Businesses naturally accumulate information over time. Employees change roles, new people join and others leave, while systems and applications are added to the mix. It’s easy for access permissions to become broader than they need to be.

Consider whether employees only have access to the systems and information required for their role. For example, does someone in sales really need access to HR information? Does a former employee still have an active account? Are shared accounts being used where individual accounts would provide better control?

Access should be reviewed regularly rather than simply being set once and forgotten.

  1. How are you sharing information?

Email makes sharing information incredibly easy. It can also make mistakes incredibly easy. A document can be sent to the wrong person. A spreadsheet containing personal information can be attached to the wrong email. Sensitive information can be forwarded without considering who ultimately receives it. Think about how your employees share information internally and externally.

Are they using approved systems?

Do they understand what information can and can’t be shared?

Do they know what to do if they send something to the wrong person?

The ICO’s wider security guidance recommends limiting access to those who need it and taking care when sharing information electronically.

  1. Are you keeping information for longer than you need it?

“We might need it one day” isn’t necessarily a good data retention strategy. Businesses can end up with years of old customer records, documents, emails and spreadsheets sitting across servers, cloud platforms and individual devices. The more information you hold, the more information there is to protect.

The ICO specifically recommends not keeping personal data for longer than necessary and points out that reducing the amount of information held can also reduce the potential impact of a data breach.

It’s worth asking:

  • What information do we hold?
  • Why are we holding it?
  • How long do we need it?
  • Where is it stored?
  • How do we securely dispose of it when it is no longer required?

Good data housekeeping can be surprisingly effective.

  1. Would you know what to do if something went wrong?

Imagine an employee realises they’ve sent a customer spreadsheet to the wrong person.

Or an employee’s laptop is stolen.

Or someone clicks on a convincing phishing email and their account is compromised.

Who do they tell? And what happens next?

Having a process for dealing with incidents can make a significant difference. Employees need to know who they should report an incident to and understand that reporting a mistake quickly is better than hiding it. This is particularly important because cyber security incidents and data protection incidents can overlap. A compromised email account, for example, could potentially expose personal information.

  1. Do your employees know what good data protection looks like?

Technology can reduce risk, but it can’t eliminate the human element. Employees make decisions every day about:

  • What information they share
  • Which links they click
  • Where they save files
  • Who they give information to
  • How they respond to suspicious emails
  • What they do when something goes wrong

The ICO’s new Data Protection Essentials programme is designed partly to build that knowledge and confidence. It includes bite-sized training that can be completed at an individual’s own pace. That makes it particularly useful for smaller businesses where formal training can otherwise be difficult to fit into a busy working day.

Don’t make data protection harder than it needs to be

 

Good data protection doesn’t necessarily mean implementing complicated systems or creating endless paperwork. Often, it’s about getting the fundamentals right and making sure people understand why those fundamentals matter.

The ICO’s new programme provides a useful starting point for SMEs. And once you’ve identified the areas where your organisation could improve, it’s worth looking at the technology supporting those processes.

At Immervox, we help businesses assess and improve the IT and cyber security environment that sits behind their day-to-day operations.

If you’re not sure whether your current systems are giving your business the protection they should, our team can help you identify the gaps and work out what to tackle first.

 

Compliance Bulletin

Have a question? Feel free to use the contact form below and a member of the team will be in touch shortly.

There are lots of ways to reach us.

Call the team on 

0333 014 6220

For technical support, email

[email protected]

For new sales enquiries, email

[email protected]

For finance enquiries, email

[email protected]

Write to us at 

Immervox Ltd
22 Hornsby Square
Southfields Business Park
Basildon
Essex
SS15 6SD

Share the Post:

Let us help you today

Give the team a call today on 0333 014 6220, or register your details with us online and one of the Immervox team will be in touch to discuss the first stages of building your bespoke IT and telecommunications solution.

Compliance Bulletin