BS 10012 is a British standard that outlines the specifications for a Personal Information Management System (PIMS). This was introduced in 2009 to help organisations manage personal information and comply with data protection laws.
The standard was updated in 2017 to reflect the GDPR’s requirements, making it an ideal framework for regulatory compliance. For example, it includes specific guidance on each principal, helping organisations meet the requirements of BS10012 and GDPR.
After implementing BS 10012 for a number of organisations, here are our Top tips on implementing BS 10012.
- Establish a PIMS team – this is not a one-person job. You will need to have input from all areas that are involved with personal data.
- Carry out a Privacy Impact Assessment – It is important to understand where all the personal identifiable data is within the organisation, how it is collected and how it is disposed. (remember this is all Data – soft and hard copies – get in to all the drawers and cupboards)
- Data mapping – collate the information on a data matrix, this would show all the information in one place.
- Carry out a risk assessment – the data matrix will flag up any risks that need addressing
- Update documentation – Ensure all documents are updated i.e data protection policies, cookie policy and privacy policy.
- Training, training and more training – people are the weakest link, ensure ALL staff have had BS 100012 training
- Conduct Internal Audits – to verify compliance and check your systems are effective.
Implementing a PIMS can be challenging so if you would like assistance please contact us for further information on: enquiries@blackmoresuk.com
Can I implement BS 10012 instead of GDPR
Yes. BS 10012 incorporates all the requirements of GDPR, but the key benefit is that it drives ongoing review and improvement of controls implemented to manage these requirements – now and thereafter.
Neither GDPR or BS 10012 alignment happens without input or effort. Both require action and top level commitment from a business. There is no ‘off the shelf’ magic answer as every business is different, with its own processes, people, clients and suppliers – all of which generate personal data that needs to be effectively managed within a business.
How much work is involved in implementing BS10012
Neither GDPR or BS 10012 alignment happens without input or effort. Both require action and top level commitment from a business. There is no ‘off the shelf’ magic answer as every business is different, with its own processes, people, clients and suppliers – all of which generate personal data that needs to be effectively managed within a business.
Gone are the days when a simple communicated Data Protection policy and registration with the Information Commissioner would suffice for Data Protection compliance. One of the biggest changes is the ‘accountability’ principle underpinning the six other principles. You now need to be able to prove you have applied all the principles within your business.
Over and above just the basic principles, you should be striving to:
- Demonstrate that you understand what personal data you control or process,
- Identify the legal basis for processing
- Demonstrate the steps you have taken to understand and control/mitigate risk
- Communicate requirements to interested parties
- ‘Bake in’ Data Protection within your organisation (including required processes and review of planned/unplanned changes)
- Review performance and strive for continual improvement.
When you consider the potential consequences of getting any of this wrong – 4% of global annual revenue or €20M whichever is greater – why wouldn’t you take the best practice approach and implement BS 10012?
Our 7 Steps to Success
The Blackmores ISO Roadmap is a proven path to go from idea to launching your ISO Management System.
Whether you choose to work with one of our ISO Consultants, our isologists, or work your own way through the process on our isology Hub, we’re certain you’ll achieve certification in no time!
We have a proven step by step process that our ISO Consultants implement as soon as our working relationship begins. We use our specialist skills and industry knowledge to determine what is already on track and where improvements can be made. We live and breathe ISO standards, we know the standards inside out so you don’t have to.
Our ISO Consultants can help you implement systems for any ISO Standard. See the full list for specialised standards here.
What our clients have to say
Trusted by leading organisations across all sectors, we support companies of all sizes in any location.
Listen to our Podcast
Welcome to the ISO Show podcast, dispelling myths and sharing tips for success to improve your business with ISO Standards. Join us to hear interviews with successful business leaders as they share their ISO journey with you.
Get top tips via audio master classes “ISO Steps to Success” on the most popular ISO Standards.