INTERACTIVE SOFTWARE

GDPR Compliance – Does your LIMS or CRM system have what you need to comply?

Using encryption to secure data

Using encryption to secure data

GDPR stands for General Data Protection Regulation and was designed to give EU citizens more control over their data. The GDPR legislation came into force on 25th May 2018. Its introduction was very difficult to ignore due to the deluge of “Security Policy update” emails that went out. You’ve updated your Security Policy and allocated roles and responsibilities, but now the dust has settled, it’s time to think about how much work it will take to manage your data effectively.  This can be time-consuming if you are trying to do this manually. This is where your software systems can help. But does your LIMS or CRM system have the right tools to help you achieve GDPR compliance?

The legislation is new, but the data management requirements aren’t

GDPR is just putting best practice into a formal legislative structure. In addition, for those companies in the UK, the Data Protection Act has been in place for more than two decades to help protect information.

The companies that have earned the most trust from their customers are the ones that already follow this and these newly mandated practices. These are the ones that manage their customer data the best. Poor practice eventually comes to light and some huge companies have recently learned how difficult it can be to rebuild trust after sloppy data practices are highlighted. Poor customer data management brings high monetary and reputational costs – especially after the new legislation came into effect.

What system features are relevant to GDPR?

Although most companies deal with some common areas of data, each company will have a different way of managing it. Your CRM and LIMS systems need the flexibility to cope with those little differences that make your company and its services unique. You still share common requirements for the underlying features though. These include the following:

Software that has data protection options and tools at its core

One risk to consider is that your system supplier has added a “bolt on” module to cope with GDPR. Ideally, you’d prefer if these features were already built into the core of the product. And, even better, have been in place and used for years. These requirements aren’t new so you shouldn’t have to work with features that have no track record.

We have always put data protection tools at the heart of Achiever’s design. Our customers have been using the tools for more than 15 years, so they have a proven track record.

Many large institutes have relied on Achiever to manage their sensitive data for years including Chris Chambers, at the University of Leeds:

“Leeds Teaching Hospital NHS Trust is happy that its database system, Achiever Medical, has the necessary robust auditing and encryption tools to both protect our donor identifiable data and also to manage it effectively. We have been using Achiever Medical to manage and segregate the data of separate teams for 9 years and this now extends to 31 teams. Achiever Medical has now been extended to managing our internal auditing and will allow us to record consent appropriately and manage/remove data as required, to fully comply with GDPR.”