Most organisations will by now have updated their data protection policies to reflect and meet the requirements of the GDPR. unfortunately the sheer size of the potential fines and penalties means no UK company or organisation can afford to take the GDPR lightly. Data Protection can no longer be a write and forget policy or a tick box activity privacy will have to be embedded into every policy, procedure, practice or project. Existing activities need to be reviewed against your new data protection and privacy policies and every new activity, be it policy, procedure, practice or project will need to scrutinised for potential privacy breach at every stage. If not handled correctly this will be a huge task. Consider for example staff use of mobile phones and the potential for data breach. Do you even know where the data on the phones is stored ? does the phone automatically back up personal data such as email, sms, voicemails, pictures etc to ...