By using this site, you agree to the Privacy Policy and Terms & Conditions.
Accept
routeonerouteonerouteone
  • News
    • Show all
    • Awards & Events
    • Deliveries
    • Environment
    • Exhibitor News
    • Euro Bus Expo 2024
    • Features
    • Legal
    • Minibus and minicoach
    • Operators
    • Opinion
    • People
    • Suppliers
    • Vehicles
  • Vehicles
    • Find a Vehicle
    • ZEV Comparison Tool
    • Sell a Vehicle
    • Vehicle Seller Dashboard
  • Insights
  • Careers
  • Events
    • British Tourism & Travel Show
    • Euro Bus Expo
    • Innovation Challenge
    • Livery Competition
    • routeone Awards
  • Advertise
  • Contact
    • Share your news
    • Subscribe
    • Update Subscription Details
  • Latest Issue
  • SIGN UP
Search
© 2024 routeone News. All Rights Reserved.
Reading: GDPR: Keep your customer data in secure places
Share
Font ResizerAa
routeonerouteone
Font ResizerAa
Search
  • News
    • Show all
    • Awards & Events
    • Deliveries
    • Environment
    • Exhibitor News
    • Euro Bus Expo 2024
    • Features
    • Legal
    • Minibus and minicoach
    • Operators
    • Opinion
    • People
    • Suppliers
    • Vehicles
  • Vehicles
    • Find a Vehicle
    • ZEV Comparison Tool
    • Sell a Vehicle
    • Vehicle Seller Dashboard
  • Insights
  • Careers
  • Events
    • British Tourism & Travel Show
    • Euro Bus Expo
    • Innovation Challenge
    • Livery Competition
    • routeone Awards
  • Advertise
  • Contact
    • Share your news
    • Subscribe
    • Update Subscription Details
  • Latest Issue
  • SIGN UP
Follow US
© 2024 routeone News | Powered by Diversified Business Communications UK Ltd
- Advertisement -
-
routeone > News > GDPR: Keep your customer data in secure places
News

GDPR: Keep your customer data in secure places

routeone Team
routeone Team
Published: January 16, 2018
Share
SHARE

Businesses will face stricter regulations on data protection from May thanks to the EU’s General Data Protection Regulation. It’s focused on protecting the privacy of individuals, with some major penalties

GDPR will mean changes for businesses that hold data on their customers

If you’re a coach or bus operator, you will hold data on your customers. Thanks to the EU’s General Data Protection Regulation (GDPR), which applies from 25 May, you may need to make changes to how you hold and handle it.

The purpose of GDPR is to protect consumers against cybercrime. It is applicable to all organisations – including SMEs – and central to it is their consent. That means active agreement, and it will be necessary to show an audit trail of consent.

Individuals may withdraw that consent at any time. Their records must be deleted entirely, in line with the ‘right to be forgotten’.

Businesses must also be sure of exactly where data is held, and there are also tight reporting requirements should a breach occur. In other words, GDPR requires good data protection by design and default.

A sound footing?

As is typical of an EU Regulation, that concerning GDPR is an extensive document. The UK Information Commissioner’s Office (ICO) has issued guidance on how to prepare for GDPR, including a 12-step checklist.

The most important aspect is contained in the introduction. Although GDPR will replace current laws on data protection, many of GDPR’s main concepts and principles are much the same as those in the outgoing Data Protection Act.

“If you comply with the current law, then most of your approach to compliance will remain valid under GDPR and can be a starting point,” says the guidance. “However, there are new elements and significant enhancements, so you will have to do some things for the first time and do some things differently.”

A report by BT advises businesses that every process, IT application and area of infrastructure has to revolve around protection of privacy. Systems used must also be proactive, and not reactive.

The EU will take failures to observe GDPR seriously. Fines of up to 2% of turnover can be levied, while a breach of the rights of a person whose data is held by the company can lead to a financial punishment of double that.

What to do?

Besides ensuring that all of your relevant staff are aware of GDPR, the ICO advises businesses to document what personal data they hold, where it has come from, and who it is shared with.

Doing that will help them to satisfy GDPR’s accountability element. “That requires organisations to be able to show how they comply with the data protection principles, for example by having policies and procedures in place,” says the guidance.

Customers can demand their data is deleted as a ‘right to be forgotten’

The key to GDPR’s requirements, however, is individuals’ rights. “On the whole, they are the same as those under the Data Protection Act, but with some significant enhancements.

“If you are geared up to give individuals their rights now, then the transition to GDPR should be relatively easy,” says the ICO document.

If an individual makes a subject access request, organisations will have less time to comply. Individuals will have the right to complain to a supervisory authority if their request is refused, and a stronger right to have all of their data deleted.

Children’s needs

Importantly for operators who hold records of children that use their services, GDPR brings in special protection for youngsters. If you rely on consent to collect information about them, you may need a parent or guardian’s permission to process that data lawfully.

“Achieving compliance with GDPR requires more than putting a new process or piece of technology in place,” warns the BT report. “Organisations have to look at their entire security landscape, because it underpins their efforts to understand and protect their data. Without a successful security strategy in place, they will suffer the financial, regulatory and reputational consequences that follow a serious breach.”

Although it may sound like more red tape – and despite Brexit, GDPR will become part of British law thanks to the Great Repeal Bill – BT says that it is also an opportunity for businesses.

“GDPR offers an opportunity to review and redesign security strategies in a way that protects data against new and existing threats, and builds a strong brand based on public trust,” it says. “As long as data is protected, digital transformation is the way forward.”

Whether you are a coach or a bus operator, there is no doubting that IT and cloud-based computing will play an ever-increasing part in your business’ day-to-day dealings. Data breaches have been reputational disasters for those organisations that have suffered them; GDPR will protect your customers, and it will also protect you.

Read the ICO report at bit.ly/2D6vZqy

routeone comment

No operator will react to GDPR with glee, but as detailed in the ICO guidance, those organisations that practice good data security are already in a good place to comply.

The potential for significant fines should GDPR not be observed, or if a data breach occurs, are clear. In both cases, but particularly the latter, reputational damage is likely to be just as serious, considering that operators’ relationships with their customers are built on trust.

Time to prepare for GDPR is running out; it is four months away. There are many reports, guidance documents and sundry else online, and various organisations can give advice on the subject.

TAGGED:BusCoachDiversified CommunicationsMagazineMiniPlusrouteONE
Share This Article
Facebook LinkedIn Threads Email Copy Link
Previous Article Never too big to fail
Next Article IRTE Skills Challenge returns: Bigger and better than ever
- Advertisement -

Latest News

Temsa HD12 and HD13 delivered to Cresta Coaches under Asset Alliance rental deal
Temsa pair join Cresta Coaches on Asset Alliance rental agreement
Deliveries
Go-Ahead London – Managing Director
Careers Jobs
andy burnham tfgm £15.6 billion (1) The funding announced by Chancellor Rachel Reeves today (4 June) has been allocated to several combined mayoral authorities to use on rail, tram, road and bus infrastructure. Transport for Greater Manchester revealed today that part of the £2.5 billion it will receive will go towards making the Bee Network fully battery-electric by 2030. An as-yet undecided portion of that will support a planned investment in 1,000 new zero-emission buses over that period, the mayoral authority said. That is part of plans to build the UK's "first fully integrated, zero-emission public transport system", with trams and trains also set to benefit. Liverpool City Region's already announced BRT system is among the projects to which its £1.6 billion will be allocated. Under those plans - due for realisation by 2028 - a high-speed network will be served by articulated buses which are modelled on the 'Glider' in Belfast. It is due to link Liverpool city centre with John Lennon Airport, and Liverpool FC and Everton FC's respective stadia along three routes. Although the model of bus has not been confirmed, a Van Hool Exqui.City on loan from Belfast was last year used as a demonstrator. That 18m vehicle can accommodate around 30% more passengers than a typical bus and has three sets of double doors. The funding will also go towards buses elsewhere in the city as the region heads towards franchising services by 2027. Liverpool Mayor Steve Rotheram with a 'Glider' which was on loan from Belfast last year - an example of the sort of bus which could serve the new BRT Bus services in the East Midlands region will be boosted by the funding, thanks to the £2 billion handed to it today by the government. Some of that allocation will be used for a rapid transit network on the Trent Arc between Nottingham and Derby. Between the two cities, the Freeport, Infinity Park Investment Zone and Ratcliffe-on-Soar will also benefit from the improved bus services. South Yorkshire Mayoral Combined Authority's newly announced commitment towards bus franchising has been boosted by £350 million in funding as part of that region's allocation. The funding for West Yorkshire will help build new bus stations in Bradford and Wakefield. Likewise, the Tees Valley Mayoral Authority will put its sum towards a new £15 million bus station in Middlesbrough. Transport Secretary Heidi Alexander says: "Today marks a watershed moment on our journey to improving transport across the North and Midlands – opening up access to jobs, growing the economy and driving up quality of life as we deliver our Plan for Change. "For too long, people in the North and Midlands have been locked out of the investment they deserve. With £15.6bn of government investment, we’re giving local leaders the means to drive cities, towns and communities forward, investing in Britain’s renewal so you and your family are better off."
TfGM’s all-electric bus plan boosted by new £15.6 billion package
News
Local Transport Minister opens First Bus electric depot in Hengrove
Local Transport Minister opens First Bus electric depot in Hengrove
Bus
- Advertisement -
-

routeone magazine is the indispensable resource for professional UK coach, bus and minibus operators. The home of vehicle sales and the latest bus and coach job vacancies, routeone connects professional PCV operators with complete and unrivalled news coverage.

  • Terms & Conditions
  • Privacy Policy
  • GDPR Policy
  • Sustainability
  • Advertise
  • Latest Issue
  • Share Your News
routeonerouteone
Follow US
© 2024 routeone News | Powered by Diversified Business Communications UK Ltd