{"id":40314,"date":"2018-02-21T13:10:52","date_gmt":"2018-02-21T18:10:52","guid":{"rendered":"https:\/\/granicus.com\/blog\/webinar-recap-comms-teams-prepare-gdpr\/"},"modified":"2024-02-22T09:49:54","modified_gmt":"2024-02-22T14:49:54","slug":"webinar-recap-comms-teams-prepare-gdpr","status":"publish","type":"blog_posts","link":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/","title":{"rendered":"[Webinar recap] How comms teams should prepare for the GDPR"},"content":{"rendered":"","protected":false},"author":11,"featured_media":40315,"template":"","resource_tax_market":[186,187,188,189,190],"resource_tax_dept":[196],"resource_tax_type":[164],"resource_tax_region":[],"resource_tax_outcomes":[204],"resource_tax_topic":[],"resource_tax_products":[192],"resource_tax_solutions":[209],"resource_tax_services":[],"class_list":["post-40314","blog_posts","type-blog_posts","status-publish","has-post-thumbnail","hentry","resource_tax_market-local-government-uk","resource_tax_market-central-government-uk","resource_tax_market-healthcare-uk","resource_tax_market-emergency-services-uk","resource_tax_market-housing-uk","resource_tax_dept-communications-public-relations-uk","resource_tax_type-blogs-uk","resource_tax_outcomes-customer-experience-uk","resource_tax_products-govdelivery-uk","resource_tax_solutions-digital-communications-uk"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>[Webinar recap] How comms teams should prepare for the GDPR | Granicus<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[Webinar recap] How comms teams should prepare for the GDPR | Granicus\" \/>\n<meta property=\"og:url\" content=\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\" \/>\n<meta property=\"og:site_name\" content=\"Granicus\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/granicusco\/\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-22T14:49:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1440\" \/>\n\t<meta property=\"og:image:height\" content=\"590\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@Granicus\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\"},\"author\":{\"name\":\"Granicus Marketing\",\"@id\":\"https:\/\/granicus.com\/uk\/#\/schema\/person\/86d618ccb52051e285962f72626e8881\"},\"headline\":\"[Webinar recap] How comms teams should prepare for the GDPR\",\"datePublished\":\"2018-02-21T18:10:52+00:00\",\"dateModified\":\"2024-02-22T14:49:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\"},\"wordCount\":10,\"publisher\":{\"@id\":\"https:\/\/granicus.com\/uk\/#organization\"},\"image\":{\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg\",\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\",\"url\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\",\"name\":\"[Webinar recap] How comms teams should prepare for the GDPR | Granicus\",\"isPartOf\":{\"@id\":\"https:\/\/granicus.com\/uk\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg\",\"datePublished\":\"2018-02-21T18:10:52+00:00\",\"dateModified\":\"2024-02-22T14:49:54+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage\",\"url\":\"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg\",\"contentUrl\":\"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg\",\"width\":1440,\"height\":590},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/granicus.com\/uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"[Webinar recap] How comms teams should prepare for the GDPR\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/granicus.com\/uk\/#website\",\"url\":\"https:\/\/granicus.com\/uk\/\",\"name\":\"Granicus\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/granicus.com\/uk\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/granicus.com\/uk\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/granicus.com\/uk\/#organization\",\"name\":\"Granicus\",\"url\":\"https:\/\/granicus.com\/uk\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/granicus.com\/uk\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/granicus.com\/wp-content\/uploads\/2023\/05\/Granicus-G-logo-Red.svg\",\"contentUrl\":\"https:\/\/granicus.com\/wp-content\/uploads\/2023\/05\/Granicus-G-logo-Red.svg\",\"width\":\"1024\",\"height\":\"1024\",\"caption\":\"Granicus\"},\"image\":{\"@id\":\"https:\/\/granicus.com\/uk\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/granicusco\/\",\"https:\/\/x.com\/Granicus\",\"https:\/\/www.linkedin.com\/company\/granicusinc\/\",\"https:\/\/www.facebook.com\/granicusco\",\"https:\/\/www.facebook.com\/granicuslac\",\"https:\/\/www.youtube.com\/@GranicusLAC\",\"https:\/\/www.instagram.com\/granicuslac\/\",\"https:\/\/www.linkedin.com\/company\/granicuslac\",\"https:\/\/twitter.com\/granicuslac\/\",\"https:\/\/twitter.com\/GranicusUK\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/granicus.com\/uk\/#\/schema\/person\/86d618ccb52051e285962f72626e8881\",\"name\":\"Granicus Marketing\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/granicus.com\/uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f18a3514fa5c1d54c5ef212b4ddd23f1946461a2d8d778191a29a45101706969?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f18a3514fa5c1d54c5ef212b4ddd23f1946461a2d8d778191a29a45101706969?s=96&d=mm&r=g\",\"caption\":\"Granicus Marketing\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"[Webinar recap] How comms teams should prepare for the GDPR | Granicus","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/","og_locale":"en_GB","og_type":"article","og_title":"[Webinar recap] How comms teams should prepare for the GDPR | Granicus","og_url":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/","og_site_name":"Granicus","article_publisher":"https:\/\/www.facebook.com\/granicusco\/","article_modified_time":"2024-02-22T14:49:54+00:00","og_image":[{"width":1440,"height":590,"url":"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@Granicus","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#article","isPartOf":{"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/"},"author":{"name":"Granicus Marketing","@id":"https:\/\/granicus.com\/uk\/#\/schema\/person\/86d618ccb52051e285962f72626e8881"},"headline":"[Webinar recap] How comms teams should prepare for the GDPR","datePublished":"2018-02-21T18:10:52+00:00","dateModified":"2024-02-22T14:49:54+00:00","mainEntityOfPage":{"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/"},"wordCount":10,"publisher":{"@id":"https:\/\/granicus.com\/uk\/#organization"},"image":{"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg","inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/","url":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/","name":"[Webinar recap] How comms teams should prepare for the GDPR | Granicus","isPartOf":{"@id":"https:\/\/granicus.com\/uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage"},"image":{"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg","datePublished":"2018-02-21T18:10:52+00:00","dateModified":"2024-02-22T14:49:54+00:00","breadcrumb":{"@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#primaryimage","url":"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg","contentUrl":"https:\/\/granicus.com\/wp-content\/uploads\/Blog_Header_webinar-recap-how-comms-teams-should-prepare-for-the-gdpr.jpg","width":1440,"height":590},{"@type":"BreadcrumbList","@id":"https:\/\/granicus.com\/uk\/blog\/webinar-recap-comms-teams-prepare-gdpr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/granicus.com\/uk\/"},{"@type":"ListItem","position":2,"name":"[Webinar recap] How comms teams should prepare for the GDPR"}]},{"@type":"WebSite","@id":"https:\/\/granicus.com\/uk\/#website","url":"https:\/\/granicus.com\/uk\/","name":"Granicus","description":"","publisher":{"@id":"https:\/\/granicus.com\/uk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/granicus.com\/uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/granicus.com\/uk\/#organization","name":"Granicus","url":"https:\/\/granicus.com\/uk\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/granicus.com\/uk\/#\/schema\/logo\/image\/","url":"https:\/\/granicus.com\/wp-content\/uploads\/2023\/05\/Granicus-G-logo-Red.svg","contentUrl":"https:\/\/granicus.com\/wp-content\/uploads\/2023\/05\/Granicus-G-logo-Red.svg","width":"1024","height":"1024","caption":"Granicus"},"image":{"@id":"https:\/\/granicus.com\/uk\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/granicusco\/","https:\/\/x.com\/Granicus","https:\/\/www.linkedin.com\/company\/granicusinc\/","https:\/\/www.facebook.com\/granicusco","https:\/\/www.facebook.com\/granicuslac","https:\/\/www.youtube.com\/@GranicusLAC","https:\/\/www.instagram.com\/granicuslac\/","https:\/\/www.linkedin.com\/company\/granicuslac","https:\/\/twitter.com\/granicuslac\/","https:\/\/twitter.com\/GranicusUK"]},{"@type":"Person","@id":"https:\/\/granicus.com\/uk\/#\/schema\/person\/86d618ccb52051e285962f72626e8881","name":"Granicus Marketing","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/granicus.com\/uk\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f18a3514fa5c1d54c5ef212b4ddd23f1946461a2d8d778191a29a45101706969?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f18a3514fa5c1d54c5ef212b4ddd23f1946461a2d8d778191a29a45101706969?s=96&d=mm&r=g","caption":"Granicus Marketing"}}]}},"acf":{"page_type":"internal","external_url":"","page_template":"centered","sidebar_position":"right","post_author":"","post_date":"","post_description":"","post_link":"","post_file":false,"media_gallery":false,"project_metrics_title":"","project_metrics":false,"show_hero":false,"hero_margin":false,"hero_type":"image","hero_subhead":"","hero_headline":"","hero_text":"","hero_button":"","hero_icon":false,"hero_image":false,"sidebar_type":"sticky","content_builder_sidebar_group":{"content_builder_sidebar":false},"flexible_page_builder_group":{"flexible_page_builder_fields":[{"acf_fc_layout":"wysiwyg","add_menu_anchor":false,"anchor_menu_text":"","wysiwyg_group":{"show_section":true,"alignment":"left","subhead":"","headline":"","wysiwyg":"<p><em>Communications professionals from Granicus, LGcommunications and Perago-Wales recently ran a webinar to help public sector comms teams prepare for the GDPR.<\/em><\/p>\n<p><em>[This is our\u00a0GDPR webinar\u00a0recap blog 1 of 3. Please note Granicus\u2019 comments on the GDPR are for informational purposes only and do not constitute legal advice. Please consult your data protection advisor or a lawyer for guidance on your obligations.]<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>GDPR quick recap<\/em><\/strong><\/p>\n<p>First, let\u2019s establish what &#8216;GDPR&#8217; actually is. The General Data Protection Regulation is a mandatory new legislation that comes into effect on 25 May 2018. It replaces the current Data Protection Act directive across Europe and applies to any organisation worldwide communicating with European citizens (Brexit doesn&#8217;t affect UK organisations&#8217; need to comply &#8211; we all must).<\/p>\n<p>The new law applies to both data controllers and processors, and non-compliance carries the risk of heavy financial penalties and legal action. The GDPR is the first comprehensive overhaul of EU data protection legislation in 20 years and aims to bring the law into step with our \u2018digital age\u2019.<\/p>\n<p><strong>The legislation sets out a number of obligations under the GDPR:<\/strong><\/p>\n<ul>\n<li>Broadened definition of \u2018personal data\u2019<\/li>\n<li>Set of core privacy principles<\/li>\n<li>Increased record keeping and accountability<\/li>\n<li>Stricter security and breach reporting<\/li>\n<li>Strengthened data subject rights<\/li>\n<li>Stricter contractual terms between controllers and processors<\/li>\n<li>Privacy must be \u2018by design\u2019<\/li>\n<li>Requires appointment of Data Protection Officer for certain organisations<\/li>\n<li>International transfer rules remain in effect as per previous regime (e.g. Privacy Shield and EU model clauses)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>[Simon Jones, LGcommunications] <\/em><\/strong><\/p>\n<p><strong><em>GDPR and the opportunity for public sector communications:<\/em><\/strong><\/p>\n<p>GDPR is something everyone in your organisation needs to understand and comply with, and preparation be left to your information governance team. All staff need training to understand any necessary changes in your business practices \u2013 especially the communications team since they collect and use a range of personal data for campaigns.<\/p>\n<p>The personal information you hold and permissions you have to hold that information will have a direct impact on your ability to communicate with citizens, businesses and staff. Get your GDPR preparation wrong and you severely impinge your ability to inform, engage and move people to action through campaigns. Or, ensure your operations are GDPR- compliant and be able to enhance your ability to communicate with the citizens that you serve.<\/p>\n<p>Simon Jones of LGcommunications emphasises that by auditing current processes and the information being held (and for what purposes), comms teams have a chance to tighten up their practices and get to know target audiences better, leading to a greater comms impact.<\/p>\n<p><strong>Simon\u2019s tips for communicators:<\/strong><\/p>\n<ul>\n<li>Show the value of information<\/li>\n<li>Keep it simple and engaging<\/li>\n<li>Make it real to the people you are engaging with<\/li>\n<li>It\u2019s about community not (the) council<\/li>\n<li>Give people a choice \u2013 on info you hold<\/li>\n<li>Don\u2019t apply pressure \u2013 they have the right to unsubscribe<\/li>\n<li>Segment your audience: \u201cYes\u201d, \u201cNo\u201d and \u201cDon\u2019t know\u201d<\/li>\n<li>Deliver a sustained campaign \u2013 give plenty of info and chances to opt in\/out<\/li>\n<li>Use it to find out more relevant information \u2013 where they live, what services they use, where they live etc (explain why this detail is needed as you collect it)<\/li>\n<li>Build GDPR into wider campaigns, be positive \u2013 it is about the rights of individuals.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>[Victoria Ford, Perago-Wales] <\/em><\/strong><\/p>\n<p><strong><em>Six steps to reach GDPR compliance:<\/em><\/strong><\/p>\n<ol>\n<li><strong>Awareness<\/strong><\/li>\n<\/ol>\n<p>Who needs to know about GDPR, how are you going to share this information with them? Make it relevant and engaging. All staff within your organisation must know what impact GDPR can have.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-19665\" src=\"https:\/\/uk.granicus.com\/wp-content\/uploads\/image\/jpeg\/Victoria-wheel.jpg\" alt=\"Victoria GDPR awareness steps\" width=\"665\" height=\"499\" \/><\/p>\n<ol start=\"2\">\n<li><strong>Information<\/strong><\/li>\n<\/ol>\n<p>Know what information you hold and be able to give evidence of why you need to hold that information. These are key requirement of GDPR. Consider:<\/p>\n<ul>\n<li>What do you hold?<\/li>\n<li>Where is it held?<\/li>\n<li>Why do you hold it?<\/li>\n<li>Who has access to it?<\/li>\n<li>Who do you share it with?<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li><strong>Lawful basis for processing<\/strong><\/li>\n<\/ol>\n<p>Processing personal data must be necessary \u2013 if you can reasonably achieve the same outcome without processing then you do not have a lawful basis. Article 6 of GDPR states at least one of these policies must apply whenever you process data:<\/p>\n<ul>\n<li>Legitimate interest<\/li>\n<li>Public task<\/li>\n<li>Vital interest<\/li>\n<li>Legal obligation<\/li>\n<li>Contracts<\/li>\n<li>Consent<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol start=\"4\">\n<li><strong>Gap analysis<\/strong><\/li>\n<\/ol>\n<p>Look at where you are now and where you need to be. This will enable you assess all your practices and identify areas that risk non-compliance to help you to create an action plan.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<ol start=\"5\">\n<li><strong>The \u2018individual rights\u2019 test<\/strong><\/li>\n<\/ol>\n<p>The GDPR has given individuals a lot more rights around the storage and use of their data. Are your teams ready to respond to individuals who send in requests, such as to delete all their data that you hold? Would you know where to find this data and how to comply with the request? Would you know when you have a right to reject their request and what to say?<\/p>\n<p>&nbsp;<\/p>\n<ol start=\"6\">\n<li><strong>Third party data sharing<\/strong><\/li>\n<\/ol>\n<p>Who do you share data with? Are they GDPR compliant? You must check every step of your supply chain and have GDPR-compliance written into all contracts.<\/p>\n<p>You can use these six steps to bring focus and control to how you approach the GDPR. But it is also key that you think about how you are going to communicate GDPR internally to reach a sustainable culture of compliance. Don\u2019t underestimate the importance of in-person regular training. Tick-box exercises aren\u2019t going to cut it.<\/p>\n<p>&nbsp;<\/p>\n<p><em><strong>Get help to prepare for the GDPR<\/strong><\/em><\/p>\n<p><em>If you&#8217;d like to get some help to ensure your digital communications delivered through govDelivery comply with the GDPR,\u00a0 <a href=\"mailto:info@granicus.com\">drop us an email<\/a>.<\/em><\/p>\n","button":""}}]},"posts_slider_group":{"show_section":true,"posts_slider":[{"add_anchor":false,"anchor_name":"","background_color":"green","slider_subhead":"","slider_headline":"Discover More Blogs","slider_text":"","slider_type":"blog_posts","manual_resources":false,"slider_resource_tax":"recent","add_additional_filters":false,"department_filter":false,"market_filter":false,"outcome_filter":false,"product_filter":false,"region_filter":false,"solution_filter":false,"topic_filter":false,"slider_link":{"title":"View All Resources","url":"\/uk\/learning-center\/","target":""},"slider_link_icon":false}]},"centered_layout_builder_clone":{"flexible_page_builder_group":{"flexible_page_builder_fields":[{"acf_fc_layout":"wysiwyg","add_menu_anchor":false,"anchor_menu_text":"","wysiwyg_group":{"show_section":true,"alignment":"left","subhead":"","headline":"","wysiwyg":"<p><em>Communications professionals from Granicus, LGcommunications and Perago-Wales recently ran a webinar to help public sector comms teams prepare for the GDPR.<\/em><\/p>\n<p><em>[This is our\u00a0GDPR webinar\u00a0recap blog 1 of 3. Please note Granicus\u2019 comments on the GDPR are for informational purposes only and do not constitute legal advice. Please consult your data protection advisor or a lawyer for guidance on your obligations.]<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>GDPR quick recap<\/em><\/strong><\/p>\n<p>First, let\u2019s establish what &#8216;GDPR&#8217; actually is. The General Data Protection Regulation is a mandatory new legislation that comes into effect on 25 May 2018. It replaces the current Data Protection Act directive across Europe and applies to any organisation worldwide communicating with European citizens (Brexit doesn&#8217;t affect UK organisations&#8217; need to comply &#8211; we all must).<\/p>\n<p>The new law applies to both data controllers and processors, and non-compliance carries the risk of heavy financial penalties and legal action. The GDPR is the first comprehensive overhaul of EU data protection legislation in 20 years and aims to bring the law into step with our \u2018digital age\u2019.<\/p>\n<p><strong>The legislation sets out a number of obligations under the GDPR:<\/strong><\/p>\n<ul>\n<li>Broadened definition of \u2018personal data\u2019<\/li>\n<li>Set of core privacy principles<\/li>\n<li>Increased record keeping and accountability<\/li>\n<li>Stricter security and breach reporting<\/li>\n<li>Strengthened data subject rights<\/li>\n<li>Stricter contractual terms between controllers and processors<\/li>\n<li>Privacy must be \u2018by design\u2019<\/li>\n<li>Requires appointment of Data Protection Officer for certain organisations<\/li>\n<li>International transfer rules remain in effect as per previous regime (e.g. Privacy Shield and EU model clauses)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>[Simon Jones, LGcommunications] <\/em><\/strong><\/p>\n<p><strong><em>GDPR and the opportunity for public sector communications:<\/em><\/strong><\/p>\n<p>GDPR is something everyone in your organisation needs to understand and comply with, and preparation be left to your information governance team. All staff need training to understand any necessary changes in your business practices \u2013 especially the communications team since they collect and use a range of personal data for campaigns.<\/p>\n<p>The personal information you hold and permissions you have to hold that information will have a direct impact on your ability to communicate with citizens, businesses and staff. Get your GDPR preparation wrong and you severely impinge your ability to inform, engage and move people to action through campaigns. Or, ensure your operations are GDPR- compliant and be able to enhance your ability to communicate with the citizens that you serve.<\/p>\n<p>Simon Jones of LGcommunications emphasises that by auditing current processes and the information being held (and for what purposes), comms teams have a chance to tighten up their practices and get to know target audiences better, leading to a greater comms impact.<\/p>\n<p><strong>Simon\u2019s tips for communicators:<\/strong><\/p>\n<ul>\n<li>Show the value of information<\/li>\n<li>Keep it simple and engaging<\/li>\n<li>Make it real to the people you are engaging with<\/li>\n<li>It\u2019s about community not (the) council<\/li>\n<li>Give people a choice \u2013 on info you hold<\/li>\n<li>Don\u2019t apply pressure \u2013 they have the right to unsubscribe<\/li>\n<li>Segment your audience: \u201cYes\u201d, \u201cNo\u201d and \u201cDon\u2019t know\u201d<\/li>\n<li>Deliver a sustained campaign \u2013 give plenty of info and chances to opt in\/out<\/li>\n<li>Use it to find out more relevant information \u2013 where they live, what services they use, where they live etc (explain why this detail is needed as you collect it)<\/li>\n<li>Build GDPR into wider campaigns, be positive \u2013 it is about the rights of individuals.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>[Victoria Ford, Perago-Wales] <\/em><\/strong><\/p>\n<p><strong><em>Six steps to reach GDPR compliance:<\/em><\/strong><\/p>\n<ol>\n<li><strong>Awareness<\/strong><\/li>\n<\/ol>\n<p>Who needs to know about GDPR, how are you going to share this information with them? Make it relevant and engaging. All staff within your organisation must know what impact GDPR can have.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-19665\" src=\"https:\/\/uk.granicus.com\/wp-content\/uploads\/image\/jpeg\/Victoria-wheel.jpg\" alt=\"Victoria GDPR awareness steps\" width=\"665\" height=\"499\" \/><\/p>\n<ol start=\"2\">\n<li><strong>Information<\/strong><\/li>\n<\/ol>\n<p>Know what information you hold and be able to give evidence of why you need to hold that information. These are key requirement of GDPR. Consider:<\/p>\n<ul>\n<li>What do you hold?<\/li>\n<li>Where is it held?<\/li>\n<li>Why do you hold it?<\/li>\n<li>Who has access to it?<\/li>\n<li>Who do you share it with?<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li><strong>Lawful basis for processing<\/strong><\/li>\n<\/ol>\n<p>Processing personal data must be necessary \u2013 if you can reasonably achieve the same outcome without processing then you do not have a lawful basis. Article 6 of GDPR states at least one of these policies must apply whenever you process data:<\/p>\n<ul>\n<li>Legitimate interest<\/li>\n<li>Public task<\/li>\n<li>Vital interest<\/li>\n<li>Legal obligation<\/li>\n<li>Contracts<\/li>\n<li>Consent<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol start=\"4\">\n<li><strong>Gap analysis<\/strong><\/li>\n<\/ol>\n<p>Look at where you are now and where you need to be. This will enable you assess all your practices and identify areas that risk non-compliance to help you to create an action plan.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<ol start=\"5\">\n<li><strong>The \u2018individual rights\u2019 test<\/strong><\/li>\n<\/ol>\n<p>The GDPR has given individuals a lot more rights around the storage and use of their data. Are your teams ready to respond to individuals who send in requests, such as to delete all their data that you hold? Would you know where to find this data and how to comply with the request? Would you know when you have a right to reject their request and what to say?<\/p>\n<p>&nbsp;<\/p>\n<ol start=\"6\">\n<li><strong>Third party data sharing<\/strong><\/li>\n<\/ol>\n<p>Who do you share data with? Are they GDPR compliant? You must check every step of your supply chain and have GDPR-compliance written into all contracts.<\/p>\n<p>You can use these six steps to bring focus and control to how you approach the GDPR. But it is also key that you think about how you are going to communicate GDPR internally to reach a sustainable culture of compliance. Don\u2019t underestimate the importance of in-person regular training. Tick-box exercises aren\u2019t going to cut it.<\/p>\n<p>&nbsp;<\/p>\n<p><em><strong>Get help to prepare for the GDPR<\/strong><\/em><\/p>\n<p><em>If you&#8217;d like to get some help to ensure your digital communications delivered through govDelivery comply with the GDPR,\u00a0 <a href=\"mailto:info@granicus.com\">drop us an email<\/a>.<\/em><\/p>\n","button":""}}]}},"post_slider_clone":{"posts_slider_group":{"show_section":true,"posts_slider":[{"add_anchor":false,"anchor_name":"","background_color":"green","slider_subhead":"","slider_headline":"Discover More Blogs","slider_text":"","slider_type":"blog_posts","manual_resources":false,"slider_resource_tax":"recent","add_additional_filters":false,"department_filter":false,"market_filter":false,"outcome_filter":false,"product_filter":false,"region_filter":false,"solution_filter":false,"topic_filter":false,"slider_link":{"title":"View All Resources","url":"\/uk\/learning-center\/","target":""},"slider_link_icon":false}]}},"call_to_action":{"hide_call_to_action":false,"color":"red","custom_cta":false,"custom_subhead":"","custom_headline":"","custom_description":"","custom_link":null,"custom_image":false}},"_links":{"self":[{"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/blog_posts\/40314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/blog_posts"}],"about":[{"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/types\/blog_posts"}],"author":[{"embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/users\/11"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/media\/40315"}],"wp:attachment":[{"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/media?parent=40314"}],"wp:term":[{"taxonomy":"resource_tax_market","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_market?post=40314"},{"taxonomy":"resource_tax_dept","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_dept?post=40314"},{"taxonomy":"resource_tax_type","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_type?post=40314"},{"taxonomy":"resource_tax_region","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_region?post=40314"},{"taxonomy":"resource_tax_outcomes","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_outcomes?post=40314"},{"taxonomy":"resource_tax_topic","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_topic?post=40314"},{"taxonomy":"resource_tax_products","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_products?post=40314"},{"taxonomy":"resource_tax_solutions","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_solutions?post=40314"},{"taxonomy":"resource_tax_services","embeddable":true,"href":"https:\/\/granicus.com\/uk\/wp-json\/wp\/v2\/resource_tax_services?post=40314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}