This is a complex and demanding piece of EU regulation that, in effect, replaces the Data Protection Act in the UK. At its heart is the desire to ensure all EU citizen’s personal data is protected, transparent and accessible upon request, relevant to purpose and can be removed upon request. The covers data held by an organisation and when it transfers or processes that data to or via a third party. As we have less than 250 employees and we do not process personal data as such it is reasonable to assume that we are exempt. But we do hold information that is personal in nature regarding our clients while they engage us. When we mentor or coach our clients share information that is intended for our ears and eyes only. We use that information to help our clients and, as none of us are super human, we have to record that information somewhere! Therefore, regardless of whether we are exempt or not, we take the security and confidentiality of our client’s personal information extremely seriously. We trade on our reputation and that is based on our personal professionalism and integrity. So, what steps do we take? Under the GDPR, the lawful basis for us to hold personal data is “Consent”; the individual has given clear consent for us to process their personal data for a specific purpose. Therefore, our first action is to gain consent from our clients to hold their personal data. Normally we achieve this by entering into a “Non-disclosure agreement” (NDA) with the client or their employer to manage the taking, holding and confidentiality of their personal data. We record client personal data in two forms: in a note book during the mentoring or coaching sessions, and in the Cloud via an iMac or a MacBook Pro laptop. When we record client data in the note book we use a code to represent the client to protect their identity. This is not full proof but it does make it harder to link the notebook content to an individual should we lose a notebook. Whilst we take material care over the custody of our notebooks, we cannot give a 100% guarantee that it will not be lost or stolen. There are occasions when we capture personal data digitally. This raises two specific risks: unauthorised access and loss. We use an iMac as our main processing machine and MacBook Pros as our onsite-portable machines. The machines are linked via Apple’s iCloud. All client data and the IP of the business is stored encrypted via iCloud. No data is specifically held on the hard drives of the machines. The iCloud provides back up and security against loss of data. Access to our machines is strictly controlled, both physically and logically. In addition to a series of password protection levels, the machines operate within a VPN, have advanced firewall and anti-virus and malware protection, and are scanned regularly. All emails are sent via the VPN. A cyber related and data security risk assessment is undertaken quarterly. When a client engagement has ended and there is no longer a purpose for us to hold that client’s personal data, it is erased from our systems; both in digital and written form. No system is 100% secure but for the risk levels associated with our business we believe we have taken “reasonable” steps to ensure our client’s data is both secure and only used for the purpose that it given for. Unless our clients have asked us to we never divulge who our clients are. Whilst we do name sponsoring organisations for some client engagements on our web site, we do not name any mentoring or coaching clients or discuss the details of our engagements.