< Back to latest news & events

Articles

GDPR is here!

June 2018

Have you made the necessary changes? In case you have been living under a rock (from a data protection point of view) for the last two years (or two weeks in some cases!), the most significant changes to the rules that govern the handling of personal data took effect on 25th May.

All retailers are only ever a step away from customers’ personal data and the impact these regulations have on the way personal data can be used, makes this subject relevant across the sector. While there has been some hype around huge new fines, no longer being able to use personal data the way you wish, or having to obtain consent for everything, most organisations have taken a pragmatic approach to these changes using them as an opportunity to get its ‘house’ in order and fully understand where and how personal data is stored and used. In many cases, those who have struggled to come to terms with the changes were not complying with the pre-existing regime in any event.

To be confident around compliance, organisations should first take time to understand what personal data they use, how it flows into, around, and out of the organisation, what it does with it and the lawful basis on which it is processed i.e. why is it justified in using it? (consent is one of six grounds). It will then need to check that any personal data is handled in line with the data protection principles, and in accordance with data subjects’ (identifiable living persons) rights. In large organisations, or where processing is large scale, of certain categories or potentially risky this understanding and analysis should all be documented in order to demonstrate compliance.

Alongside this shift in thinking around use of personal data and how it is documented, organisations should look at updating internal and external policies and consent procedures, so that they adequately reflect and, (importantly) clearly communicate how personal data is used. Relevant changes may include notifying data subjects of their updated rights under the GDPR, and advising them of the personal data obtained, together with what is being done with it and the lawful basis, it is being used for. Other updated duties around data breach reporting, the appointment of a Data Protection Officer and the use of Privacy Risk Assessments may also need to be factored in.

Having a complaint made against an organisation (not forgetting the associated impact on brand and customer confidence) continues to be a key risk in this area, and the Information Commissioner will have greater powers under GDPR including enhanced ability to investigate and levy fines. How the Information Commissioner and other European data protection authorities wield these increased powers over the next few months will certainly be of interest and may also prompt those who are behind in compliance to get up to speed.

Latest updates

Empowered, Not Replaced: The Risks and Rewards of Using AI Tools in Patent Prosecution

With the rapid rise of AI and extreme hype around generative AI tools in the workplace, patent firms around the world have had to seriously consider to what extent they …

Read article

EU Agrees on NGT Plant Regulation: What It Means for Patents and Licensing

The European Parliament and Council have reached a provisional agreement for plants developed using New Genomic Techniques (NGTs) – below we summarise the main points and set out the requirements …

Read article

When Retail Branding Meets Politics

(Inter IKEA Systems v Algemeen Vlaams Belang (Case C‑298/23) In November 2022, the Flemish political party Vlaams Belang presented its “IKEA-PLAN – Immigratie Kan Echt Anders” (“Immigration Really Can Be Different”). …

Read article

Office Closed Dates December 2025 / January 2026

HGF Office Closed Dates December 2025 / January 2026   UK Thursday 25 and Friday 26 December 2025 CLOSED Thursday 1 January 2026* CLOSED * Friday 2 January 2026 – …

Read article

Often Copied, Never Equaled: When Do Everyday Items Become Subject of Copyright?

The  borderline between ‘pure’ works of art and mere utilitarian objects” –  Can iconic, yet everyday products be protected under copyright? The above question was posed by Advocate General in …

Read article

T 0883/23: Dosage claims and their entitlement to priority when only the clinical trial protocol was disclosed in the priority application

In a recently issued decision by the EPO’s Board of Appeal (BoA), the BoA held that claims directed to a combination of active pharmaceutical ingredients (APIs) at particular doses were …

Read article

The end of the Brexit overhang for trade marks: review, refile and revoke.

On the 31st December 2025, five years will have passed since the end of the Brexit transitional period on 31st December 2020. Why is this relevant? For UK cloned trade …

Read article
Event - 14th January 2026

Seminar on The aftermath of G1/24 - has anything changed?

HGF is hosting a The aftermath of G1/24 – has anything changed? Which will be followed by networking, apero, and snacks. The Seminar will be held on Wednesday, 14th January …

Event details