The art of the perfect fit

Are you ready for the GDPR?

Posted by D.R.A.W in News · May 2018

The new General Data Protection Regulation (GDPR) comes into effect on the 25th May 2018 - have you taken the necessary steps to comply?

The new General Data Protection Regulation (GDPR) affects all businesses, in varying degrees, based on the sorts of information you collect about customers, clients and employees, and whether you have obtained permission to hold this information.

To try and decipher the legislation and what your responsibilities are can be a bit of a mine field, especially with the inevitable grey areas in new legislation. You need to comply, whilst remaining commercial in your decision-making about how to implement measures that protect your business.

Key points to note are that you must obtain permission from all of your contacts, before 25th May, to continue to contact them in future and record their preferences. If a contact wishes to be removed from your database, you must comply with this.

We have put together a few guidelines of steps you can take to achieve compliance, as recommended by the ICO (Information Commissioners Office) going forward:

  • Take a look at the 12 steps to take right now on the ICO’s website
  • You may also want to look at the guide covering all aspects of GDPR
  • It is also important to determine if you are holding data based on ‘legitimate interest’. The ICO has also created some guidance on how to conduct legitimate interest assessments and how to consider if legitimate interest can be used as the basis of holding and processing data. It is useful to conduct a test for each type of data processing activity that is carried out, as follows:
    • Identify the legitimate interest – what is the purpose of processing the data?
    • Carry out the necessity test – is the data processing necessary to achieve organisational objectives?
    • Carry out a balancing test – is processing the data likely to negatively impact the individuals rights?
    • Organisational risk – are there implications to your business, whether legal, operational or reputational?


Please note, this article is for information purposes, and we suggest for any specific advice required relating to your business, that you seek the appropriate legal guidance.

Notes from DRAW · 02.05.2018

Read More

Working in the Arts – Art Tech Special: Rebecca Davison-Mora

Rebecca Davison-Mora is the Communications Manager at Arcarta, a due diligence platform that supports the art market. Previously she worked in various leadership roles at arts institutions and commercial galleries in Toronto, Canada. She holds a Master’s degree in Arts and Cultural Management…

Working in the Arts – Art Tech Special: Nick Walter

This week for working in the arts we spoke to Nick Walter, CEO of Vortic Art. Vortic is a powerful virtual reality and digital exhibition ecosystem for galleries, institutions and collectors to quickly and sustainably curate, share, and revisit exceptional exhibitions with any viewer, anywhere in…

Working in the Arts – Art Tech Special: Tanya Van Sant

For the next few weeks we are focusing our Working in the Arts segment on the intersection between art and technology. To kick things off we chatted to Tanya Van Sant, Vice President of Personnel at Artlogic. Since 1994, Artlogic has been building technology to improve the art world. With complete…

Working in the Arts: Bridget Rambeau

This month’s Working in the Arts segment is US focussed as we chat to Bridget Rambeau who works at Hauser & Wirth in LA. So, where do you work? Hauser & Wirth, at the Los Angeles gallery. And what is your job title? Registrar What time did you wake up and what are you usual working…