The General Data Protection Regulation (GDPR) comes into effect on 25th May 2018, yet many decision-makers and business leaders are still unsure of what GDPR is and what they should do to prepare for it. We’ve created this guide for Microsoft Dynamics NAV users to understand exactly what is and isn’t covered in their solution.
What is the GDPR?
The General Data Protection Regulation (GDPR) is a new EU law for the protection of personal data. It replaces the current Data Protection Act 1998 in the UK. The GDPR applies to “personal data”, which includes any information relating to an identifiable person. There is no distinction between a person’s private, public or work roles. Personal data can include names, email addresses, social media posts, locations, bank details, IP addresses and cookies. The GDPR aims to unify all EU member states’ approaches to data regulation and ensure that all data protection laws are equally applied across the EU. One key aim of GDPR is to empower individuals and give them control over their personal data. This will protect EU citizens from organisations irresponsibly using personal data by governing how they manage and protect it and ensuring they respect individual choice – no matter where data is sent, processed or stored. For UK businesses, Brexit does not mean a quick getaway from the GDPR. Firstly, the GDPR affects any business that collects and stores data on EU residents and is not reliant on the business itself being based within the EU – if you collect data on EU residents, you must comply. Secondly, by the time Britain leaves the EU on 29th March 2019, the GDPR will already be in place. Theresa May has confirmed that ‘existing EU laws in force in the UK will be converted into full UK laws’. Under the GDPR, EU residents will have the right to access readily-available information in plain language about:- How their personal data is used
- Access to their personal data
- Having their personal data deleted or corrected
- Restricting or objecting to the processing of their personal data, such as for marketing or profiling purposes
What is Microsoft doing to help with the GDPR?
Microsoft is taking a number of measures to help organisations safeguard personal data in compliance with the GDPR. They are building a more secure environment for all Microsoft products with investments in additional features and functionality. Microsoft outlines GDPR compliance in 4 key stages:- Discover – Identify what personal data you have and where it is stored.
- Manage – Govern how personal data is used an accessed.
- Protect – Establish security controls to prevent, detect and respond to vulnerabilities and data breaches.
- Report – Execute on data requests, report data breaches and keep required documentation.
Which Microsoft solutions are GDPR compliant?
Microsoft has announced that any Microsoft Dynamics NAV solutions in mainstream support will be updated with tools to aid GDPR compliance, including:- Dynamics NAV 2015
- Dynamics NAV 2016
- Dynamics NAV 2017
- Dynamics NAV 2018