Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

What does the GDPR mean for SMEs?

by The Gurus
June 27, 2017
in Editor's News
Share on FacebookShare on Twitter

The EU General Data Protection Regulation (GDPR) comes into force in the UK in May 2018 and is anticipated to have a significant impact on businesses across the country.
The GDPR is a replacement for the Data Protection Act 1998, and will apply to all organisations that process, handle and store any personal data of EU residents.
These new regulations mean businesses are required to gain consent  for all data collected from individuals, and provide clear and comprehensive privacy notices to help these individuals understand what they are opting into. Crucially, organisations of all sizes need to be able to prove that consent was given if they want to process any form of personal data.
Ultimately, the GDPR regulations mean increased powers for European Supervisory Authorities, including the ability to impose financial penalties of up to €20 million or four percent of the business’ worldwide annual turnover, for non-compliance or breaches.
With this in mind Ebuyer, a leading provider of storage, networking and security solutions to SMBs, has created a compliance checklist to help business owners avoid the potentially disastrous consequences of a compliance failure:
 

  1. Begin compliance discussions now with key people in your organisation.
  2. Document the personal data your organisation holds, where it came from and who it is shared with.
  3. Review your privacy notices. Under the GDPR, you will need to clearly identify the lawful basis for processing customer data, as well as how long you will retain it for and the customer’s right to complain about how you are using it.
  4. Have a robust process in place for locating and deleting individual customers’ data, if and when requested.
  5. Be aware of the new right to “data portability”. This means individuals have the right to request their personal data in a commonly-used, machine-readable format, provided to them free of charge and within one month.
  6. Review how you seek, record and manage consent for data collection. Remember consent must be explicitly provided: assumption of consent (for instance, via pre-ticked boxes on a web form) can breach regulations.
  7. Review how you will verify individuals’ ages, and how you will obtain parental consent to process the data of under-13s if required.
  8. Reinforce your existing data breach reporting procedures to ensure your organisation can meet the new timelines.
  9. Take steps to appoint a Data Protection Officer if you are required to, and consider who should be trained in, and responsible for, GDPR compliance even if not.

 
Amber Smith, Head of Sales at Ebuyer.com said: “The new GDPR regulations will have a significant impact on small businesses, who will need to begin taking steps to achieve compliance as soon as possible. But it’s not just SMEs who need to begin making these changes, as the law applies to all companies regardless of size, from sole traders to multinationals.
“This year’s ransomware attacks should already have emphasised the need for businesses to invest in robust antivirus and cybersecurity measures, but in case they didn’t, hopefully the GDPR and its new penalties for non-compliance will.”
To find out more about what you need to do to ensure your business complies, please visit: http://www.ebuyer.com/blog/2017/06/impact-of-the-gdpr-on-small-businesses/

Tags: CybergdprsecurityTechnology
ShareTweet
Previous Post

Majority of cyber professionals not confident UK government can protect itself from cyberattacks

Next Post

Stephanie Daman – The Cyber Industry has lost an inspirational soul

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol