General Data Protection Regulation compliance update

GDPRFrom May 2018 the Data Protection Act is superseded by the EU General Data Protection Regulation (GDPR) , which is a significantly-stricter regime to protect personal information online. I have recently completed our GDPR review.

The two critical changes are

  • Explicit consent is required for processing sensitive personal data.
  • Parental consent will be required to process the personal data of children under the age of 16 for online services.

 

What counts as sensitive personal data?

  1. Health and genetic data
  2. Biometric data
  3. Racial or ethnic data
  4. Political opinions
  5. Sexual orientation

Of these, only (3) is relevant to Yacapaca. In order for our analytics module to continue to report results broken down by ethnic origin category, we would need written permission from the parent or guardian of every child in the school.

That game, I’m afraid, ain’t worth the candle, so from September that metadata category will be withdrawn. If you use that analysis, you will need to export the raw data and re-import it into a service such as SIMS that still stores this data.

This is not the only change we will need to achieve full GDPR compliance, but it is both the main one and the only one that requires an immediate change. We will be working behind the scenes to ensure we are in full compliance well before the May deadline.

One thought on “General Data Protection Regulation compliance update

  1. Pingback: Top ten FAQs | Yacapaca

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s