
With the future workplace hybrid, there are a number of steps that companies – and their employees – need to take to protect their data and make their systems more efficient and compliant.
Managing Director Jason Dixon shares his top tips on adhering to the strict GDPR guidelines and facilitating productivity and efficiency – for both home workers and their employers:
1. Only use approved technology
The simplest and most effective way to keep data secure is to only use approved devices to access work-related documents and emails. Companies should provide employees with all the necessary technology to undertake their jobs, so there’s really no need to use personal items.
Approved technology should also be password protected and encrypted. Laptops, desktops or tablets should have the latest antivirus and antimalware software to date to avoid being targeted by hackers. It’s also worth noting that the same levels of protection don’t tend to be installed on personal devices.
Employees should also avoid downloading work email or messenger apps on their personal devices, as this could be considered a GDPR breach if confidential information is accessed.
And, to avoid loss or theft, securely store all work devices away at the end of the day.
2. Share and communicate securely
Only use communication facilities provided by your employer, and only use secure messaging apps and approved document sharing systems. If you’re unsure of how secure your emails are, password protect documents and share passwords on a different channel.
Our new Docuflo software uses the latest technology – encompassing Artificial Intelligence (AI), Optical Character Recognition (OCR), QR codes, workflow automation, Application Programming Interface (API) integration, mobile apps, Scan & Go and digitisation – which enables documents to be scanned, sent, received and retrieved through a secure portal with end-to-end encryption. This means only the recipient can access the enclosed information.
It also integrates with other Microsoft applications, CRM and ERM and stock management systems – as well as most accounting software – for seamless information sharing, allowing documents to be edited and shared, as well as for private information to be withheld.
Secure communication whilst working from home should also take into account where you set up your home office. Don’t have your screen facing the window or open door where people see information. If you leave your workstation throughout the day, close your laptop or turn off your screen.
Likewise, if you share your home or working space with others, try to make calls and meetings where others cannot overhear or oversee your screen.
3. Make sure everyone’s up to speed on their responsibilities
Since the introduction of GDPR, companies developed policies, procedures and guidance to ensure compliance. Now that staff are working remotely, it’s essential that these are updated and reviewed. Employers should also take a look at their current cybersecurity framework and adapt it to cover hybrid working.
Staff should then be briefed so that they understand their responsibilities under the GDPR. Holding training sessions and creating regular lines of communication for employees to ask questions and report any concerns should be a priority.
For anyone who’s unsure about your own responsibilities under the GDPR regulations, speak to your data protection officer, cybersecurity team, IT department or business leaders.
4. Avoid downloads
Downloading documents or files presents a range of risks. Firstly, the website you’re downloading from may not be secure, meaning hackers could gain access to your network and therefore confidential information. When working from home, be extra cautious when it comes to accessing unsecured websites. And don’t open weblinks or attachments that don’t seem safe.
Secondly, downloading files directly to your PC means that information is then stored there. So, if it’s stolen or lost, the download is also taken, and the information is at risk. Where possible, you should access data remotely through your works intranet or shared documents system.
5. Take care with print outs
When you’re in the office, it’s likely that you’ll have shredders or confidential waste bins to dispose of print outs, but this might not be the case at home. Printing anything from meeting agendas to emails, expense forms to CV’s could put you at risk of GDPR breach.
Working from home demands a different security standard and workflow process than being in the office.
Despite hybrid working being most likely for the majority of UK workers, there are still many employers and employees who haven’t yet made robust enough provisions when it comes to keeping data private and secure.
We encourage business leaders to look at their existing working practices and processes – in terms of data security, productivity and therefore profitability – and consider whether everything is working as efficiently and effectively as it should.
We carry out a detailed dataflow audit before every Docuflo installation, which is a really useful process for every company to go through. Our GCHQ-approved partners subsequently carry out security skills training, which helps ensure everyone within the organisation is up to speed on the system and their responsibilities.
This all does wonders to ensure businesses are best equipped to meet data privacy requirements and able to lead and manage remote teams effectively.