I like the spreadsheet David – very interesting. I agree with your blog post in many respects. I’ve tried to stay away from the alarmist stuff about fines too. As you rightly say, if you have been following DPA requirements then GDPR is not a huge leap however as we know, what many companies say they do differs from what they actually do. For me GDPR may require a culture change in many organisations and that is very hard to do. I think some of the practical issues around the right to be forgotten will cause enormous problems too (I wouldn’t what to be the person in the NHS trying to work this out!). But as many things concerned with IT and governance – do the basic right and then everything else should fall into place.
I like the spreadsheet David – very interesting. I agree with your blog post in many respects. I’ve tried to stay away from the alarmist stuff about fines too. As you rightly say, if you have been following DPA requirements then GDPR is not a huge leap however as we know, what many companies say they do differs from what they actually do. For me GDPR may require a culture change in many organisations and that is very hard to do. I think some of the practical issues around the right to be forgotten will cause enormous problems too (I wouldn’t what to be the person in the NHS trying to work this out!). But as many things concerned with IT and governance – do the basic right and then everything else should fall into place.
Couldn’t agree more Chris, many thanks for the comments.