Most of the year outer layers protect us from scrutiny, but whether it is a holiday in the sun or an enquiry from a regulator, our level of preparedness can quickly and devastatingly be exposed!
This is true of almost any industry but has particular resonance for Transport and Logistics where the very different regulatory worlds of the Traffic Commissioner and the Information Commissioner can combine in unexpected and unhelpful ways.
The four little letters, G D P R, have been burnt into the public consciousness over the last 10 years. So much so that even the smallest and most niche commercial enterprises have a published privacy notice on their website and data protection policies in place. Unfortunately just like if you want to be Beach-Body-Ready in August it won’t be enough to have hit the Gym for a single week in January. To be Data Compliance Ready requires more than just a ‘one-and-done’ exercise in creating documentation.
Additionally, like going to the Gym there is no single one size fits all activity to achieve the goal of being ‘ready’ in terms of compliance. Each organisation needs to take care to tailor its approach to its own particular characteristics. Just as some might continually train to improve their abdominals or their biceps, organisations need to consider where their compliance might be most exposed, and do regular equivalent work there.
Privacy notice
An organisation might have a Privacy Notice that is (or was) generically compliant, but such a document provides only a very superficial layer of protection. This is because any scrutiny of the content would instantly reveal that it fails to properly address the specific contexts and risks of the relevant organisation. That might be because they have recently enthusiastically adopted an extensive range of helpful telematics technologies, but critically have never revisited the data protection documentation to properly (or at all) cover that processing. Or more problematically they might find themselves caught between the rock and a hard place of two different regulators because a generic, untailored and unreviewed Privacy Notice has drafting that to make life easy in terms of satisfying one regulator, has effectively prohibited the organisation’s ability to voluntarily co-operate with the other (because for example undertakings are given that data will only be shared where the organisation is under a legal obligation to do so. This can present difficulties for an operator who is simultaneously trying to meet their duties to notify the Traffic Commissioner of matters affecting good repute - a term that is not always easy to define).
Whilst the Privacy Notice is the most visible and obvious piece of data protection compliance documentation, it is far from the only one. Compliance documents are not documents that can be written in stone unfortunately, they must evolve in sync with the organisation they relate to, as it develops and changes. Like the scales at the gym the longer it has been since they were last looked at, the less likely it is that that version is still accurate.
Keeping a competitive advantage
To keep a competitive advantage the best organisations are constantly trying new processes and technology, and often to great commercial or other effect. Whether this is AI optimised route planning using geotracking, or lifesaving blind-spot/driver safety systems, that benefit is put at significant risk of being undermined if the associated compliance work doesn’t keep up the same pace and focus. Failure to have properly constituted and comprehensive processor agreements with the geotracking service provider could mean a single enquiry leads to months where the organisation is unable to use the system as compliance is retro-engineered from scratch, allowing competitors to catch up. Similarly safety monitoring systems are notoriously fragile as regards the regulatory requirements as to consent, necessity and transparency. Even very limited resistance or a complaint from employees could potentially require such systems to be decommissioned or significantly altered/reduced if the compliance work isn’t properly tailored to the circumstances.
At least in terms of the Summer holidays there is the certainty that the risk will every year fall like clockwork in August and we can plan accordingly. With data compliance the potential for exposure of under-prepared and unfit-for-scrutiny documentation is a constant year-round threat. It can be triggered by a complaint, or an exercise of data rights or a regulator spot check, amongst other things. Worst of all there is no quick fix, and prevention is better than a cure. It is therefore also true that with data protection there is sadly no substitute to putting in the hard work in advance and on a regular basis.
So, with that all said and done, there has never been a better time to consider whether your organisation has a data six-pack or a data pot belly and to get your team and expert others engaged to achieve and maintain your goals!“