Come May next year, every business in the UK will be subject to strict new EU regulations on data protection. Despite Brexit looming, the government has confirmed that the General Data Protection Regulation (GDPR) will be adopted, replacing current laws on data handling.
With its broad definition of what constitutes personal data, virtually every business will be affected by the GDPR. Handling and storing any personal data, be it employee records, customer details, even the names and email addresses of business contacts, will mean you have to comply with beefed-up rules aimed at protecting privacy.
The GDPR replaces the Data Protection Act. The main differences will be as follows:
- An expectation for businesses to plan for data protection 'by design', and be able to document how they do so
- Greater accountability for data breaches, including a requirement for businesses to report breaches within 72 hours
- Much stiffer penalties - a maximum fine of £20 million, compared to £500,000 under current UK law
- An expectation on businesses to gain consent before processing, using or storing personal data, and explain what the data is being used for if asked
- An expectation on businesses to only use data that is necessary, and to delete it once it is no longer useful
- A requirement for all organisations to delete data held on an individual if they request it
Many of these changes will require all businesses to adopt new policies, protocols and working practices to ensure they remain compliant. For the UCaaS industry, there are particular implications around the technology, but there are also great opportunities for vendors, resellers and service providers to add value by helping end users with compliance.
New responsibilities
One of the main issues facing cloud communications once the GDPR comes into effect is the way that a cloud network transmits and stores data outside a client company. As Ian Moyse, UK sales director at Natterbox, points out: "The GDPR is going to affect everyone in UCaaS, both customer (data controller) and cloud vendor (data processor)."
Ian here alludes to the fact the GDPR has in part been designed to update data protection in the light of new technologies like the Cloud. It recognises that hosted services have created a new relationship whereby one business handles and uses data as part of its day to day operations (the data controller), while another runs the technical side of the processing and storage on their behalf (the data processor).
These new types of relationship in computing and communications technology have created two separate fronts in the battle to protect data - what happens in the client company and what happens in the provider's data centre. The GDPR defines specific roles, responsibilities and levels of accountability for each.
Ian feels confident, however, that UCaaS vendors are well placed to meet these new responsibilities because security has always been a top priority in the development of cloud communications. "Security and data questions around the Cloud have remained the top questions and concerns for the past 10 years, but the cloud market has continued to grow and expand at an accelerated pace. What does this tell us? That the needs of customers for high security, protection and comfort can be met in most cases."
Kris Wood, EMEA VP at Fuze, believes UCaaS vendors need to do all they can to take the weight of regulatory compliance off customers, and ensure the way their systems handle and process data are watertight.




