Whether you are a Data Controller or a Data Processor you have responsibilities under the General Data Protection Regulation (GDPR). A controller determines the purposes and means of processing personal data, whereas a processor is responsible for processing personal data on behalf of a controller and you are required to maintain records of personal data and processing activities.
SRA – new focus on “principles” not “rules”
The SRA is focussing on ‘principles’ and ‘professional judgement’ as opposed to ‘rules’ A principle based system is more uncertain than fixed rules and therefore it is more important to legal practices to have a set of recorded systems and controls in place that are applied consistently across the firm. The rules are clear particularly … Read more