Home » Frequently Asked Questions
The General Data Protection Regulation (GDPR) came into effect on 25th May 2018. It sets out rules for how organisations process personal data and requires us all to be able to demonstrate compliance with data protection law. Many organisations have undertaken a “GDPR gap assessment” which helps them identify areas that need improvement. They can then use this assessment to create a GDPR project plan and identify what technical and organisational measures to put in place.
The GDPR applies to the processing of personal data by automated means as well as to manual processing if the personal data are contained in a filing system. As most businesses and organisations process personal data, it is likely that the GDPR will apply to you.
The first step on the road to compliance is to carry out a data protection assessment of your organisation to identify any gaps in compliance and corresponding risks. A detailed project plan with clear tasks, responsibilities and timelines will assist you on your compliance journey.
In certain cases, organisations will have a statutory obligation to appoint a DPO. For example, where there is regular and systematic monitoring of individuals on a large scale. It is up to each organisation to assess whether it is required and if so, the organisation must register the DPO with the Data Protection Commission.
A Data Protection Impact Assessment (DPIA) is an assessment which is carried out on a new project, product, service or processing activity to determine whether the proposed new data processing poses any risks to the rights of the individuals whose personal data is being processed. The aim is to identify risk and implement measures to reduce or eliminate the risk. In certain cases, there is a statutory requirement to carry out a DPIA.
While is it important that you protect personal data from accidental loss, destruction or damage and against unauthorised or unlawful processing, security is just one of the principles of the GDPR. You must also make sure you are compliant with the other data protection principles.
Consent is just one of the lawful bases for data processing and not always the most appropriate one to rely on. You should review the lawful basis for each of your data processing activities and decide which one applies.
The Data Protection Commission recommends that the following non-exhaustive list of factors be taken into consideration when selecting the appropriate DPO training programme:
For DPOs we offer Certified Information Privacy Professional/Europe (CIPP/E) and also Certified Information Privacy Management (CIPM) training in partnership with the International Association of Privacy Professionals (IAPP). CIPP/E and CIPM certification is the gold standard in data protection training globally for DPOs. We also offer ‘train the trainer’ workshops in specific topics such as data breach management; data protection impact assessment and data subject assess requests.
The Data Protection Commission recommends that the following non-exhaustive list of factors be taken into consideration when selecting the appropriate DPO training programme:
Certified Information Privacy Professional/Europe (CIPP/E) and Certified Information Privacy Management (CIPM) training is ideal training for those who have responsibility for data protection in their company or organisation. If you are not aiming to acquire a data protection certification, we offer a Data Protection Masterclass. This is a full day ‘in-house’ training course in Data Protection Fundamentals which will give you a firm grounding in data protection essentials.
We provide Data Breach Response training so that your staff understand what a data breach is and how to reduce the likelihood of a breach occurring. If a breach does happen, our training will ensure your staff are prepared and understand the necessary and appropriate steps to take.
We have experience in providing training in both data subject access request procedures and Freedom of Information requests. We can explain how these two regimes overlap and how to ensure your procedures are compliant.
We provide data protection training on a national basis either on site or off site depending on your requirements.
We offer specific e-learning products to introduce your whole staff to GDPR. Your staff can easily and quickly register for the course and it takes 30 minutes to complete the training. After concluding each topic, users will have the opportunity to test their knowledge by completing a multiple-choice questionnaire, the results of which can be tracked and reported.
Upon completion of the course, trainees are awarded a certificate of completion. This also serves to demonstrate that data protection training has been provided to staff, which forms a part of your accountability obligations under the GDPR.
Cookie | Duration | Description |
---|---|---|
__stripe_mid | 1 year | Stripe sets this cookie cookie to process payments. |
__stripe_sid | 30 minutes | Stripe sets this cookie cookie to process payments. |
cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category . |
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
CookieLawInfoConsent | 1 year | Records the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie. |
elementor | never | This cookie is used by the website's WordPress theme. It allows the website owner to implement or change the website's content in real-time. |
JSESSIONID | session | The JSESSIONID cookie is used by New Relic to store a session identifier so that New Relic can monitor session counts for an application. |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
woocommerce_cart_hash | session | This cookie is set by WooCommerce. The cookie helps WooCommerce determine when cart contents/data changes. |
Cookie | Duration | Description |
---|---|---|
__cf_bm | 30 minutes | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
bcookie | 1 year | LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID. |
bscookie | 1 year | LinkedIn sets this cookie to store performed actions on the website. |
lang | session | LinkedIn sets this cookie to remember a user's language setting. |
lidc | 1 day | LinkedIn sets the lidc cookie to facilitate data center selection. |
wp_woocommerce_session_* | 2 days | WooCommerce sets this cookie to make a unique code for each customer so that it knows where to find the cart data in the database for each one. |
Cookie | Duration | Description |
---|---|---|
_fbp | 3 months | Facebook sets this cookie to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising after visiting the website. |
_ga | 2 years | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
_ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
_ga_P2DEMKMP2R | 2 years | This cookie is installed by Google Analytics. |
_gcl_au | 3 months | Google Tag Manager sets the cookie to experiment advertisement efficiency of websites using their services. |
CONSENT | 2 years | YouTube sets this cookie via embedded YouTube videos and registers anonymous statistical data. |
Cookie | Duration | Description |
---|---|---|
IDE | 1 year 24 days | Google DoubleClick IDE cookies store information about how the user uses the website to present them with relevant ads according to the user profile. |
test_cookie | 15 minutes | doubleclick.net sets this cookie to determine if the user's browser supports cookies. |
VISITOR_INFO1_LIVE | 6 months | YouTube sets this cookie to measure bandwidth, determining whether the user gets the new or old player interface. |
YSC | session | Youtube sets this cookie to track the views of embedded videos on Youtube pages. |
Cookie | Duration | Description |
---|---|---|
_cfuvid | session | Description is currently not available. |
li_alerts | 1 year | Description is currently not available. |
li_gc | 5 months 27 days | No description |
m | 2 years | No description available. |
VISITOR_PRIVACY_METADATA | 6 months | Description is currently not available. |
wffn_ay_1e37cffd5ec47397c8db4ea354fb2b8c | session | Description is currently not available. |
wffn_ay_60788fe5afe63b445a1d2b0b73b53d6c | session | Description is currently not available. |
wffn_ay_6af562e4dfd92cb654c7e3eef4ba6e00 | session | Description is currently not available. |
wffn_ay_7062c098eb0ceb1d8a49d870c1452142 | session | Description is currently not available. |
wffn_ay_fd5c68771c3e033278c7df1cc9801288 | session | Description is currently not available. |
wffn_browser | 2 days | No description |
wffn_flt | 2 days | No description |
wffn_is_mobile | 2 days | No description |
wffn_referrer | 2 days | No description |
wffn_si | 1 day | No description |
wffn_timezone | 2 days | No description |
woocommerce_items_in_cart | session | No description available. |
wp_woocommerce_session_6914927dc2b54e4765bd5474dd9a15c5 | 2 days | No description |