The impact of GDPR on remote working
These are unprecedented times for businesses, other organisations, and for society in general. The social distancing measures introduced in many countries to slow the rate of COVID-19 spread mean that many more people are now working from home every day. This has required a rapid upscaling in the remote working capacity across all sectors. The recent explosion in the popularity of video conferencing apps is a testament to the new working reality. Besides the technical and security challenges that this is causing IT departments, it is also a new experience for many workers.
This increased remote working brings with it increased risks. On one level there are increased security risks related to working on external networks, possibly having data on personal devices, and opening up potentially sensitive data screens or personally identifiable information (PII) to other family members who are also at home. We can also be sure there will be an increase in cyberattacks and other malicious activity like Phishing emails as criminals attempt to capitalise on a somewhat turbulent situation.
These risks have implications for data protection and adherence to the GDPR and other regulatory practices. GDPR still applies today irrespective of the change in working conditions everyone is experiencing. All businesses and organisations that collect and store client data still need to protect it. Providing secure IT systems is the bedrock for delivering GDPR compliance. Renaissance and our trusted partners provide the tools to secure any IT system and network infrastructure. Contact us today to discuss any topic related to your current and future IT needs. Read on for some thoughts on how to protect data when everyone is working from home.
Guidelines and IT Support Team
Many organisations produced a data protection policy and guidelines in the run-up to GDPR go live. Now would be a good time to review and ensure that everyone still follows what they say about protecting data and PII. If necessary update the guidelines to reflect remote access to data and systems, if this was not part of the originals. If there is no existing set of guidelines in place, then Renaissance and our partners can help you quickly adopt one.
Workers can become isolated when they don’t have their colleagues around to discuss things. There is a lot of knowledge exchanged in an office in real-time every day. This is especially true for questions about IT systems and data protection. Many people will be using remote access tools or other business applications in a new way. It would be a good idea to have IT staff available online, or via phone, to answer any queries that might arise. If there is no dedicated IT team, then designating some experienced personnel to fill this role for part of their day would make sense. With a reduction in what is expected of them in their normal position, of course.
Ensuring data and PII Privacy
The data protection policy and guidelines should cover the core requirements to protect data under GDPR. But there are some other risks that working from home will bring, that may not come to mind for everyone. It would be good to communicate the items in the list below to home workers:
- Remote working environment - ideally remote work would be done on a computer that is in a separate room so that no one else could see any information on the screen. This may not be possible for many people who have a family at home. They should set up their screen so that it is facing away from others as much as possible to protect PII information.
- Password-protected screensavers - related to the above. Any devices in use should be set to show a screensaver after a set period of inactivity. With a password required to dismiss the screensaver. This will be standard practise on corporate devices, but in some cases, personal devices may be in use for work. Ensure that staff enable the security features available on these devices.
- Use strong passwords - again, mainly for personal devices. Make sure staff use strong passwords, and that they don’t share the passwords with their family.
- Use central systems or Cloud services - were possible make sure that all data accessed remains on central IT systems or in the Cloud. With secure VPN and HTTPS access over the Internet.
- Encrypt everything - If data does need to be stored on remote devices, then ensure that it is encrypted. This is easy to do on all current systems that might be in use. Let you IT experts guide anyone working remotely through enabling it if required. If data needs to be stored on removable storage devices, then ensure that only hardware-encrypted USB and external hard drives are used. Our ClearCrypt storage solutions will enable this.
- Don’t use unsecured WiFi - Most home workers will be using their broadband WiFi. Make sure that they have it secured with a password, and that security features are enabled. If for security reasons you don’t want a homeworker using their WiFi then consider a 4G mobile WiFi (MiFi) device from your mobile supplier. This will provide connectivity over the cellular network and can be secured with corporate policies.
- Update advice regularly - emphasise that staff should be aware of Phishing attacks and that they should not click on any links in emails. Have a central account that all suspicious emails should be forwarded to for vetting.
This is not an exhaustive list. A full list would make this a very long article indeed, and would then be your security guidelines and policies document! If you need help or advice with any aspect of home working and the security of data associated with that, then contact us.

