GDPR: locking down your data

11 July 2018
Summer 2018

Acuity explores how businesses must now take extra care with its rules on data privacy, consent and security.

GDPR gives back control to individuals over the data that companies hold on them, and will harmonise European data legislation.

However, the new Data Protection Act, which came into force at the same time as GDPR, has complicated the situation for optometrists. All ‘public authorities’, which include primary care providers such as practices offering General Ophthalmic Services (GOS), now have a statutory requirement to appoint a data protection officer (DPO) or use the services of one. The Information Commissioner’s Office (ICO) states that DPOs must be independent, adequately resourced and experts in data protection.

The Optical Confederation (OC), which opposed the classification of smaller, high-street practices as public authorities, said that a DPO “will place a disproportionate and costly new burden on small businesses that provide NHS services, going far beyond the requirements of GDPR.” One provider offering NHS services and employing three practitioners was quoted more than £11,000 for an external company to provide DPO support for a year (OC, 2018). However, the ICO has indicated that it will be pragmatic in its approach and that providers should be proportionate in the measures they take to comply with GDPR. At the time of going to press, the OC were continuing to work with the ICO and the NHS so that it, and the College, can provide new guidance. However, the OC still cautions against appointing an expensive external provider.

Login to read the rest of this article.

Sign in to continue

Forgotten password?
Register

Not already a member of The College?

Start enjoying the benefits of College membership today. Take a look at what the College can offer you and view our membership categories and rates.

Related further reading

We are pleased to announce that each nation's health system has confirmed that they support a move to the ‘Green’ phase on Tuesday 10 May 2022. From then, the College’s COVID-19 Amber phase guidance will no longer apply in all UK nations.

This outlines a COVID-19 Urgent Eyecare Service delivered from a network of optical practices, acting as urgent eye care hubs, to support the immediate and recovery phase of the coronavirus pandemic.

Read our response to GOC's call for evidence to review the Opticians Act (1989).