Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. News and events
  3. Law Society news
  4. GDPR – New year, new guidance

GDPR – New year, new guidance

4th January 2018 | Professional support | Data protection

Tim Musson, Convener of the Law Society of Scotland’s Privacy Law Committee, gives us an update on the latest General Data Protection Regulation (GDPR) guidance.

Clients keep saying to me: “How can we possibly comply with the GDPR, there’s no guidance available?”

Of course, there is the Regulation itself and, like any other law, we must comply. The problem is that the GDPR is complicated and compliance is difficult.

Official guidance is provided by the ICO and the Article 29 Working Party (the working party), which was set up by article 29 of the Data Protection Directive and consists of a representative from a data protection regulatory authority from each EU Member State. As the GDPR is an EU Regulation, most of the guidance must come from the working party.

And just in time for Christmas, the working party delivered five new pieces of guidance in December!

We now have the following official guidance:

  • Guidelines on the right to "data portability"
  • Guidelines on Data Protection Officers (DPOs)
  • Guidelines on The Lead Supervisory Authority
  • Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk"
  • Guidelines on the application and setting of administrative fines
  • Guidelines on Personal data breach notification
  • Guidelines on Automated individual decision-making and Profiling

The following new items are still at the consultation stage but should nevertheless prove very useful:

  • Adequacy Referential (updated)
  • The elements and principles to be found in Binding Corporate Rules
  • The elements and principles to be found in Processor Binding Corporate Rules
  • Guidelines on Consent
  • Guidelines on Transparency

You can read all the guidance from the Article 29 Working Party on the European Commission website.

The new items are probably the most significant so far. The Adequacy Referential may well have an impact on whether the EU will see the post-Brexit UK as ‘adequate’ for data protection purposes. This will have major implications for businesses trading with the EU. The Guidelines on Consent have been eagerly awaited because of their consequences for direct marketing (the ICO’s draft guidelines and consultation on consent were put on hold earlier this year in anticipations of these). The Guidelines on Transparency are also very significant as ‘transparency’ is one of the core themes of the GDPR, with greatly increased requirements of information provision to data subjects.These are not easy reading!

The Privacy Law Sub-Committee will be considering its response to these consultations.

While we are still expecting guidance on a host of further topics, we can no longer say there isn’t a great deal of guidance.

The task, as we start a new year, is to catch up with this guidance and consider how it impacts on our businesses. Happy reading!

Read all the guidance from the Article 29 Working Party.

Tim Musson has been delivering a number of Law Society of Scotland CPD & Training events on data protection and the GDPR. Find out more about upcoming CPD courses.

GDPR blog

Tim Musson, Convener of the Law Society of Scotland’s Privacy Law Committee, explains why the General Data Protection Regulation (GDPR) is all-important for law firms.

GDPR Personal data breaches

Anna Drozd, policy adviser on professional issues at our Brussels Office, explains what personal data breaches are and how to report them under the GDPR.

GDPR legal basis and why it matters

Carolyn Thurston Smith, policy executive at the Law Society of Scotland, explains the legal bases in article 6 of the General Data Protection Regulation (GDPR).

GDPR changes to consent

Domhnall Dods, regulatory solicitor and GDPR expert at Towerhouse and member of the Law Society’s Privacy Law Committee, explains the changes to rules around consent in the General Data Protection Regulation (GDPR).

GDPR data protection officers

Dr Kenneth Meechan, member of the Law Society of Scotland’s Privacy Law Committee, explains the new rules on data protection officers and sets out some important tasks which all law firms should consider.

GDPR

Our guide to data protection from the perspective of a legal practice

Read more about GDPR
Add To Favorites

Additional

Categories

  • New lawyers
  • Law Society news
  • Regulation
  • Research and policy
  • Legal aid
  • Professional support
  • Wellbeing
  • Business support
  • Equality and diversity
  • International
  • In-house lawyers
  • Schools
  • For the public
  • Videos
  • Fraud alerts
  • Career growth
  • Member benefits
  • Law and technology
  • Professional skills courses
  • Aberdeen
  • Edinburgh
  • Glasgow
  • Perth
  • Inverness
  • Commercial skills for young professionals
  • Roadshow
  • CPD event
  • Working in-house
  • Public Policy Committee
  • Roadshows
  • careers
  • property (non-commercial)
  • licensing
  • Journal online news
  • Sustainability
  • Policy committees

News Archive

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2013

Related articles

  • Law Society members reach new career heights
  • New partnership bolsters Law Society sustainability commitment
  • Spring celebrations for newly accredited Law Society members
  • Celebrations at first banking and finance paralegal accreditation
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited