As we bring our Data Protection Fundamentals series to a close, we want to cover the last questions raised in our survey. As these are some great topics, this blog is intended as a starting point to help you identify key issues and signpost you to more detailed guidance.
1. When do you need consent and what must you tell people?
The first step in processing personal data is identifying your lawful basis for doing so. There are seven set out in the UK GDPR; you must decide which is most appropriate for each of your processing activities, as each applies in different situations.
Consent is just one of these lawful bases and is only appropriate if you can offer people real choice and control over how you use their data.
Situations where consent may not be appropriate include:
- if you cannot offer the individual a genuine choice;
- if you would still process the personal data without consent; or
- if you make consent a precondition of providing a service. In order to rely on consent as your lawful basis, it must be obtained, recorded and managed in the right way. This includes ensuring that consent is valid. In order to validly collect consent you must be able to demonstrate that the consent was
- Freely given: People must be able to refuse consent without detriment and must be able to withdraw consent easily at any time. It also means consent should be unbundled from other terms and conditions.
- Specific and informed: Consent must be specific to each purpose – individuals should be able to choose which types of processing they agree to. As a minimum, individuals must be told:
- your organisation’s name (and any other controllers relying on the consent);
- why you want the data (purpose);
- what you will do with it (processing activities); and
- that they can withdraw consent at any time (and how to do so).
- Unambiguous indication: It must be obvious that the individual has consented, and what they have consented to. You must keep clear records to demonstrate who consented, when, how, and what they were told at the time. You should also keep consent under review and refresh it if your purposes or processing change.
For more information on when consent is invalid, and cannot be relied upon, see our website for more details.
If you are unsure whether consent is the right approach, try our interactive tool to help you identify the most appropriate lawful basis for your processing.
2. Artificial Intelligence (AI) – How do you use emerging technologies such as AI responsibly and lawfully?
If used well, AI has the potential to make organisations more efficient, effective and innovative. However, AI may involve risks for individuals, as well as compliance challenges for organisations.
A useful starting point to make sure your adoption of emerging technologies is compliant is to remember that data protection law is technology-neutral. The same principles apply whether you are using AI or more traditional systems. We have explored some these principles in our previous blogs. By way of reminder, the key principles are: (a) Lawfulness, fairness, and transparency, (b) Purpose limitation, (c) Data minimisation, (d) Accuracy, (e) Storage limitation, (f) Integrity and confidentiality. Underpinning all of these principles is accountability.
Referring back to these principles when considering the use of emerging technologies such as AI can be a helpful starting point, as they provide a consistent framework for assessing your approach. They can support you in thinking through key questions, such as whether your use of AI is necessary and proportionate, how you will ensure transparency with individuals, and what safeguards may be appropriate.
As the AI landscape is evolving at pace, there are increasing opportunities to innovate safely and responsibly. Please refer to our website for up-to-date guidance.
3. Data security – How can you protect personal data from loss, misuse, or unauthorised access?
Keeping personal data secure is a fundamental requirement of data protection law, and one that applies regardless of the size or resources of your organisation.
We recognise that for many VCS organisations, this can feel challenging. However, effective security does not always require complex or costly solutions. In many cases, it is about embedding good practice consistently across your organisation.
These measures can range from implementing appropriate technical controls to ensuring staff and volunteers understand their roles and responsibilities when handling personal data. Many are straightforward to put in place, and you may already have some of them in operation without recognising them as part of your organisation's data protection framework. Alongside our practical ways to keep your IT systems safe and secure, we also have some quick data security wins to help you and your staff embed small but powerful personal security measures, such as:
- Installing anti-virus and malware protection
- Using secure Wi-Fi connections
- Limiting access to appropriate individuals (access controls)
- Taking care when sharing screens
- Following appropriate data retention practices
- Properly disposing of old IT equipment and records
Alongside this, we have tools to help you assess your current level of security and identify areas for improvement. Taking a proactive approach can help prevent incidents, rather than reacting to them after the fact.
The National Cyber Security Centre has resources, toolkits and guidance on data security.
What's coming next
We are pleased to share that the ICO has some exciting announcements coming in the months ahead for small to medium organisations that are seeking to strengthen their data protection practices. We look forward to sharing more details on this in the near future. Stay up to date by following the ICO on social media:
· X/Twitter: @ICOnews
· Facebook: /ICOnews
· LinkedIn@ Information Commissioner's Office
· TikTok: @informationcommissioner
· YouTube: @InformationCommissionersOffice
We will also be carrying out a survey to capture the views of those who have followed along with this series, and we would be very grateful for any feedback you can provide so that we can continue to improve and ensure our support remains relevant, practical and effective.
Thank you to everyone for following along with the Data Protection Fundamentals series, engaging with the posts and attending the webinar. We encourage you to use these materials as a starting point, alongside our wider guidance, tools and resources to help you on your compliance journey.