GDPR – are you up to speed? Bransom

By Chris Garland, Managing Director - Bransom

As a developer and provider of stock management and EPoS systems, it’s inevitable that we will be an integral part of a retailer’s business. And so, with GDPR coming fully into law on May 25th, we’ve been actively working with our clients to help them along their path to GDPR compliance. Worryingly, recent research suggests that less than 40% of businesses are aware of GDPR, with less than 40% of those actively planning compliance, according to the Department for Digital, Culture, Media and Sport.

GDPR is complex – it covers all the aspects of personal data held for a company’s day-to-day business, whether for customers, staff or suppliers, and no single piece of software can provide a fully compliant solution. Your business processes should be well documented and meet the obligations of the new laws. You need a clear and easily understandable privacy policy which states what you do with data. (Personal data includes any held on your customers, your staff, and your suppliers, and the fines for data breaches are potentially huge, so take the time to get it right.)

Your IT systems must be designed with privacy in mind. Some businesses believe GDPR is just about marketing, but that’s just one aspect of this new pan-European regulation. For example, personal data processed for marketing has to comply with the appropriate legal basis for that processing (usually consent, or legitimate interest). If an individual exercises his rights under the new regulations to have his data removed, you must do so, including from any backups that you hold (except for data you are required to keep by law).

Similarly, you should have processes in place which document what data you hold and where, so the details can be provided to anyone who asks for it.

Our bsmart system incorporates much of the functionality required to reach compliance, including staff access controls, prompts for salespeople to ask for marketing consent, tracking of that consent and data management for Subject Access Rights or data removal.

It’s just one step on the road, but it’s a step we can help you take. For more information, please contact

The information contained in this article is for guidance, and should not be taken as legal advice, you should consult your IT and legal advisors.


Show More

Chris Garland

Alessandro is a trained journalist just getting started in the writing arena. He’s madly obsessed with Japanese culture, a passionate reader and adores niche video games. When he isn't getting sore thumbs from playing classic Nintendo games, he’s working as an editorial assistant for Mulberry Publications. Feel free to drop him a line with any story ideas.

Related Articles


Adblock Detected

Please consider supporting us by disabling your ad blocker