The ICO’s UK Information Commissioner, Elizabeth Denham delivered a speech earlier this year, outlining a key component of GDPR – cybersecurity. The Government’s recent cyber risk survey found that 69% of businesses say senior management consider cyber security a high priority for their organisation, however, only half of businesses have acted to identify cyber risks.
“Payroll info, employee details, people’s expenditures - it’s your responsibility to keep that information secure and ensure that individuals’ rights are respected, with the risk of enforcement action and damaging publicity for your company if you get that wrong,” she warned. And, with it becoming mandatory to report a personal data breach, if it’s likely to result in a risk to people’s rights and freedoms, it’s important to safeguard HR data to the utmost.
Where should I start?
“Organisations need a good governance policy, outlining who is responsible for security. clear lines for reporting, ensuring risk management, carrying out reviews around possible threats and determining relevant actions,” Ken Gaines, City & Guilds’ Digital Industry Expert, advises. “Businesses also need clear policies on all aspects that can threaten security; such as guidelines about using websites at work, keeping login details confidential and being diligent when sharing information.”
UK
United States

