Welcome Guest! The IOSH forums are a free resource to both members and non-members. Login or register to use them

Postings made by forum users are personal opinions. IOSH is not responsible for the content or accuracy of any of the information contained in forum postings. Please carefully consider any advice you receive.

Notification

Icon
Error

Options
Go to last post Go to first unread
AlanDEdgington  
#1 Posted : 18 May 2018 14:02:47(UTC)
Rank: New forum user
AlanDEdgington

The F10 contains names, addresses, phone numbers and email addresses of duty holders and is posted visibibly on a notice board in a site office. How will this now be affected or controlled under new GDPR regs?

Spacedinvader  
#2 Posted : 18 May 2018 14:13:10(UTC)
Rank: Forum user
Spacedinvader

Not required to fill in boxes - http://forum.iosh.co.uk/...ter---Names-in-the-boxes

Aside from that you just need their consent for it to be there.

Roundtuit  
#3 Posted : 18 May 2018 15:54:01(UTC)
Rank: Super forum user
Roundtuit

An F10 is not the What you need to know poster - it details a project under CDM. As CDM is a regulatory requirement unless they re-write the statutory instrument I would say the F10 is one of the "permitted by regulation" exceptions to GDPR
Roundtuit  
#4 Posted : 18 May 2018 15:54:01(UTC)
Rank: Super forum user
Roundtuit

An F10 is not the What you need to know poster - it details a project under CDM. As CDM is a regulatory requirement unless they re-write the statutory instrument I would say the F10 is one of the "permitted by regulation" exceptions to GDPR
WatsonD  
#5 Posted : 21 May 2018 08:14:25(UTC)
Rank: Super forum user
WatsonD

Firstly, the email address are usually work email and address company address, which are our professinoal identities anyway.

We have to remember that the spirit of GDPR is intended for all the banks, insurance companies, googles and amazons of this world who were selling our information and using it to bombard us with marketing relating to a recent purchase: "Just brought a car, how about some insurance/shampoo/ breakdown cover, etc."

Therefore, GDPR is about how companies are using the information. It is just a clarification of the Data Protection act. As it has been allowed under DPA 1998, I don't expect anything to change.

Hsquared14  
#6 Posted : 21 May 2018 08:41:34(UTC)
Rank: Super forum user
Hsquared14

GDPR does not apply to data relating to compliance with legal requirements so there is nothing to worry about.

Woolf13  
#7 Posted : 21 May 2018 11:24:21(UTC)
Rank: Forum user
Woolf13

As already stated as the F10 is a legal requirement GDPR does not apply. The other reason for this is it is public facing business information e.g. work telephone and email etc.

If there was "personal" information contained to prevent marketing etc. GDPR would come into play and this is when, at the concept of your project, you would complete a Data Protection Impact Assessment (DPIA), which is a must under GDPR.

Essentially as already stated above it is those organisations, e.g. banks and Human Resources style functions which handle personal information which are most affected by the changes.

I hope that helps.

Users browsing this topic
Guest
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.