Pay online

Privacy notice

Contact us

Map

Client login

01332 202660

e-signing

guide

email

Accountant background

ARCHIVE

NEWS

BUSINESS

Cybersecurity failings are rife amongst UK SMEs

ARCHIVE

NEWS

BUSINESS

NOV 2017

OUR

PROCESS

GET IN TOUCH
WITH US

GET TO KNOW

US

UK-based SMEs are not doing enough to ensure the data they hold is secure, it has been reported.

Findings from a newly-published report show that more than two out of three SMEs considered that there was room for improvement in protecting their business data, while four out of 10 questioned said they did not have a cybersecurity policy in place.

The figures were published with just six months remaining until the General Data Protection Regulation (GDPR) comes into force in May 2018.

GDPR sets tough new standards for organisations’ data protection procedures, with steep penalties for those found to be non-compliant or guilty of a breach.

A key requirement of GDPR is that businesses which hold sensitive data on a large scale will need to appoint a data protection officer. At the moment, just 84 per cent of businesses questioned said they had a dedicated employee responsible for IT and cybersecurity.

Individuals will receive a number of new rights under the GDPR – which will also strengthen some of the existing rights offered under the Data Protection Act.

According to the Information Commissioner’s Office (ICO) individuals will have the following rights: the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object.

Whilst many of the principles from the DPA will remain, the GDPR will bring with it several new concepts and approaches, which have been described as a “game changer for everyone”.

Businesses will be adversely affected – as many will need to implement organisation-wide changes to ensure that any personal data is processed in compliance with the GDPR’s requirements.

One notable change is that companies that currently rely on ‘consent’ as a legal basis for processing personal data will need to assess the consents that they currently hold and the mechanisms through which such consents are provided in future. This is because ‘implied consent’ will no longer be deemed valid under the GDPR.

It is crucially important that businesses ensure they are fully compliant with the new regime, as enforcement powers will also increase under the GDPR – meaning that non-compliance may result in harsher ICO investigations than was previously the case.

Registered office: 61 Friar Gate, Derby, Derbyshire, DE1 1DJ   T: 01332 202660

Adrian Mooy & Co is the trading name of Adrian Mooy & Co Ltd.  Registered in England No. 05770414

       Services

Member of the Association of Chartered Certified Accountants
Phone

01332 202660

61 Friar Gate  Derby  DE1 1DJ

Sign

  up

 

Newsletter 

Tax planning
Tax problems