< Back to latest news & events

Retail Scanner

GDPR is here!

June 2018

Have you made the necessary changes? In case you have been living under a rock (from a data protection point of view) for the last two years (or two weeks in some cases!), the most significant changes to the rules that govern the handling of personal data took effect on 25th May.

All retailers are only ever a step away from customers’ personal data and the impact these regulations have on the way personal data can be used, makes this subject relevant across the sector. While there has been some hype around huge new fines, no longer being able to use personal data the way you wish, or having to obtain consent for everything, most organisations have taken a pragmatic approach to these changes using them as an opportunity to get its ‘house’ in order and fully understand where and how personal data is stored and used. In many cases, those who have struggled to come to terms with the changes were not complying with the pre-existing regime in any event.

To be confident around compliance, organisations should first take time to understand what personal data they use, how it flows into, around, and out of the organisation, what it does with it and the lawful basis on which it is processed i.e. why is it justified in using it? (consent is one of six grounds). It will then need to check that any personal data is handled in line with the data protection principles, and in accordance with data subjects’ (identifiable living persons) rights. In large organisations, or where processing is large scale, of certain categories or potentially risky this understanding and analysis should all be documented in order to demonstrate compliance.

Alongside this shift in thinking around use of personal data and how it is documented, organisations should look at updating internal and external policies and consent procedures, so that they adequately reflect and, (importantly) clearly communicate how personal data is used. Relevant changes may include notifying data subjects of their updated rights under the GDPR, and advising them of the personal data obtained, together with what is being done with it and the lawful basis, it is being used for. Other updated duties around data breach reporting, the appointment of a Data Protection Officer and the use of Privacy Risk Assessments may also need to be factored in.

Having a complaint made against an organisation (not forgetting the associated impact on brand and customer confidence) continues to be a key risk in this area, and the Information Commissioner will have greater powers under GDPR including enhanced ability to investigate and levy fines. How the Information Commissioner and other European data protection authorities wield these increased powers over the next few months will certainly be of interest and may also prompt those who are behind in compliance to get up to speed.

Latest updates

The EPO Board of Appeal comments on the scope of the morality exclusion from patentability

The recent decision, T1553/22 of the Board of Appeal required the Board to consider the scope of the exclusions from patentability under Article 53(a) EPC. The invention in this case …

Read article

HGF ranked highly recommended in the WIPR Trade Mark Rankings 2025

HGF has been recognised as a leading firm in the recently published World IP Review (WIPR) Trade Mark Rankings 2025. This achievement highlights our continued commitment to excellence in trade …

Read article

T1977/22: Can claims defined by open-ended ranges ever be sufficiently disclosed?

The EPO’s Board of Appeal’s decision in T1977/22 provides an interesting review of the case law concerning the compatibility of whole range sufficiency and claims defined as a result to …

Read article

The draft of The Genetic Technology (Precision Breeding) Regulations 2025 reveals practical details on how to obtain a Precision Bred Organism status

In a recent blog post we discussed the Precision Breeding Regulatory Framework developed by the Food Standards Agency (FSA). Further details on the application process for Precision Bred Organism confirmation …

Read article

A £2.1M Lesson: The Power of Confidential Information

A recent High Court ruling1 serves as a stark reminder of the importance of respecting confidential business information. Hambro Perks, was found guilty of breaching confidentiality and ordered to pay …

Read article
Event - 6th March 2025

IQPC Global IP Exchange Europe 2025

HGF is sponsoring the IQPC Global IP Exchange Europe, which will be held on the 11th-12th March 2025 in Meliá, Berlin. Head of Electronics, Chris Benson, will be chairing the …

Event details

IP Ingredients: Pouring Over the Verdict: What Thatchers v Aldi Means for Food & Drink Brands

Readers of our IP Ingredients blog may recall that we covered something of this case last summer in our post IP Ingredients: Summer case law review. The dispute between Thatchers …

Read article