{"id":4504,"date":"2018-06-11T15:32:05","date_gmt":"2018-06-11T19:32:05","guid":{"rendered":"https:\/\/www.sage.com\/en-us\/blog\/?p=4504"},"modified":"2026-02-12T05:21:52","modified_gmt":"2026-02-12T10:21:52","slug":"gdpr-for-finance-professionals","status":"publish","type":"post","link":"https:\/\/www.sage.com\/en-us\/blog\/gdpr-for-finance-professionals\/","title":{"rendered":"GDPR for finance professionals: 3 things you need to know"},"content":{"rendered":"<header class=\"entry-header has-dark-background-color entry-header--has-illustration entry-header--has-illustration--generic\">\n\t<div class=\"container\">\n\t\t<div class=\"entry-header__row row align-center\">\n\t\t\t<div class=\"col col-lg-7 col-xlg-6 entry-header__content\">\n\t\t\t\t\t\t\t<div class=\"component component-single-header\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"entry-header__misc text--subtitle text--uppercase text--small\">\n\t\t\t\t\t\t\t<a href=\"https:\/\/www.sage.com\/en-us\/blog\/category\/money-matters\/\" class=\"entry-header__link\">Money Matters<\/a>\t\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t<div class=\"entry-title-wrapper\">\n\t\t\t\t\t<h1 class=\"entry-title\">\n\t\t\t\t\t\tGDPR for finance professionals: 3 things you need to know\t\t\t\t\t<\/h1>\n\t\t\t\t<\/div>\n\n\t\t\t\t\t\t\t\t\t<p class=\"entry-header__description\">\n\t\t\t\t\t\t\t\t\t\t\t<\/p>\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/div>\n\t<div class=\"single-post-details container\">\n\t\t<div class=\"col\">\n\t\t\t<span class=\"posted-on \"><time class=\"entry-date published\" datetime=\"2018-06-11T15:32:05-04:00\">June 11, 2018<\/time><\/span><span class=\"reading-time\"> min read<\/span>\n\t\t<button\n\t\t\ttype=\"button\"\n\t\t\tclass=\"social-share-button button button--icon button--secondary js-social-share-button\"\n\t\t\tdata-share-title=\"GDPR for finance professionals: 3 things you need to know\"\n\t\t\tdata-share-url=\"https:\/\/www.sage.com\/en-us\/blog\/gdpr-for-finance-professionals\/\"\n\t\t\tdata-share-text=\"Please read this interesting article\"\n\t\t>\n\t\t\t<span class=\"social-share-button__share-label\">Share<\/span>\n\t\t\t<span class=\"social-share-button__copy-label\" hidden>Copy Link<\/span>\n\t\t\t<span class=\"social-share-button__copy-tooltip\" aria-hidden=\"true\" hidden>Copied<\/span>\n\t\t<\/button>\n\n\t\t\t\t<\/div>\n\t<\/div>\n<\/header>\n\n\n\n<div class=\"wp-block-post-author\">\n\t\t\t<div class=\"co-authors\">\n\t\t\t\n\t\t<div class=\"entry-author-wrapper\">\n\t\t\t<a class=\"entry-author\" href=\"https:\/\/www.sage.com\/en-us\/blog\/author\/keirthomasbryant\/\">\n\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2025\/04\/Keir-350x350.jpg\" class=\"entry-author__image\" alt=\"Keir Thomas-Bryant\" srcset=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2025\/04\/Keir-350x350.jpg 350w, https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2025\/04\/Keir.jpg 600w\" sizes=\"auto, (max-width: 40px) 100vw, 40px\" \/>\t\t\t\t<span class=\"entry-author__name\">Keir Thomas-Bryant<\/span>\n\t\t\t<\/a>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t<\/div>\n\t\t<\/div>\n\n\n\n<p>The deadline for compliance with the European Union\u2019s (EU\u2019s) <a href=\"https:\/\/www.sage.com\/en-us\/gdpr\/\" target=\"_blank\" rel=\"noopener noreferrer\">General Data Protection Regulation (GDPR)<\/a>&nbsp;was last month. It affects all businesses and as finance professionals, you need to know what it means for you and your company.<\/p>\n\n\n\n<p>The focus is on personal data, or data about individuals, and is <a href=\"https:\/\/www.sage.com\/en-us\/blog\/gdpr-10-important-things-your-business-needs-to-know\/\" target=\"_blank\" rel=\"noopener noreferrer\">a significant shake-up<\/a> that affects any sole trader, partnership, corporation, public authority, agency or another body that processes the personal data of individuals who are based in the EU. This includes suppliers and other third parties a company might use to process personal data on their behalf.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>Businesses in all industries work with personal data such as contact details, bank account information and National Insurance numbers. These belong to customers, suppliers, sub-contractors, and employees, and must all be secured under the new regulation.<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>Let\u2019s&nbsp;look at&nbsp;three examples of&nbsp;how the GDPR might affect <a href=\"https:\/\/www.sage.com\/en-us\/\" target=\"_blank\" rel=\"noopener noreferrer\">finance professionals<\/a>&nbsp;during their day-to-day work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-1-don-t-get-caught-out-by-international-transfers\"><strong>1. Don\u2019t get caught out by international transfers<\/strong><\/h2>\n\n\n\n<p>Regulatory compliance&nbsp;might&nbsp;be viewed by many as an administrative burden.&nbsp;However, ignoring the GDPR or getting it wrong could have costly repercussions.<\/p>\n\n\n\n<p>A serious GDPR infringement is the failure to observe the requirements for international transfers \u2013&nbsp;if the data is being transferred to a country outside the EU that isn&#8217;t deemed to have adequate security levels. It&#8217;s these things that can incur the really hefty fines under the GDPR.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>The GDPR continues the general&nbsp;prohibition on sending personal data outside the European&nbsp;Economic Area to a country&nbsp;that does not provide adequate&nbsp;protection.<\/p>\n\n\n\n<p>At the time of writing, the countries deemed by&nbsp;the European Commission to provide \u201cadequate\u201d protection&nbsp;are: US companies that self-certify to the European Union-US Privacy Shield arrangement (note: this does not mean&nbsp;the US as a country is&nbsp;considered to provide adequate&nbsp;protection), Andorra, Argentina, Canada (limited to PIPEDA),&nbsp;Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New&nbsp;Zealand, Switzerland and Uruguay.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>Where no adequacy&nbsp;decision exists, transfers can only be made in limited&nbsp;circumstances, including on the basis&nbsp;of consent, the use&nbsp;of standard contractual clauses published by the European&nbsp;Commission or, in the case&nbsp;of inter-company transfers, the&nbsp;use of Binding Corporate Rules.<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-2-do-you-need-nbsp-a-data-protection-officer-nbsp\"><strong>2. Do you need&nbsp;<\/strong><strong>a data protection officer<\/strong><strong>?<\/strong><span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/h2>\n\n\n\n<p>The supervisory authority can impose a fine of up to 4% of annual global turnover, or \u20ac20m, whichever is greater. However, there&#8217;s a two-tier system in play.<\/p>\n\n\n\n<p>The lower tier is half of that, so up to 2% of annual global turnover or \u20ac10m, whichever is greater. The lower tier is for breaches that aren\u2019t considered to be as significant \u2013 so, for example, things like not appointing a data protection officer (DPO) when it&nbsp;is mandatory.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>Among other things under the GDPR, companies and&nbsp;any third parties that process&nbsp;personal data on their behalf will need to appoint a DPO if&nbsp;the core activities of the business or third parties involve&nbsp;monitoring&nbsp;of individuals on a large scale,&nbsp;or if the core&nbsp;activities&nbsp;consist of processing on a large scale of special&nbsp;categories of personal data, including data relating to criminal&nbsp;convictions and offenses.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>The DPO needs to have expert&nbsp;knowledge of data protection law, although they don\u2019t necessarily&nbsp;need to be an employee and could instead be employed on a&nbsp;service contract to fulfill the role. Details of the DPO will need to&nbsp;be communicated to the supervisory authority, such as the <a href=\"https:\/\/ico.org.uk\/\">ICO&nbsp;<\/a>in the UK.<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>It will be the job of the DPO to inform the company and its staff about their obligations under the GDPR. They will also have to monitor compliance with the GDPR (and any other data protection laws or requirements).<\/p>\n\n\n\n<p>This could include managing data protection impact assessments, conducting internal audits and&nbsp;organizing&nbsp;staff training. The DPO will also be the first point of contact for data-protect-related inquiries from supervisory authorities&nbsp;such as the ICO, and the point of contact for any individuals whose data is processed by the company \u2013 including customers, clients, and employees.<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-3-finance-professionals-should-u-se-the-opportunity-to-improve-nbsp-data-quality-nbsp\"><strong>3<\/strong><strong>. Finance professionals should u<\/strong><strong>se the opportunity to improve&nbsp;<\/strong><strong>data quality<\/strong><span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/h2>\n\n\n\n<p>But&nbsp;it\u2019s&nbsp;not all bad news.&nbsp;Finance departments&nbsp;should also think about the way the <a href=\"https:\/\/www.sage.com\/en-us\/blog\/data-protection-infographic\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR<\/a> can result in better data quality, through initiatives like a centralized data repository where data is deduplicated and cleaned up.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>Alongside compliance, businesses should think about adding analytics to the high-quality data that may result. Reliable information can result in a more accurate and enriched customer database, which chief financial officers can leverage to make better decisions.<\/p>\n\n\n\n<p>Remember that most people won\u2019t immediately demand that their data be deleted. If you\u2019re providing a good service, many will be happy to allow your business to use their data if it benefits them.&nbsp;<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n\n<p>For example, it allows you to better understand them and tailor your service for what they need. Customers will be happy if you present your product at the right time to them through your understanding and wise management of their personal data.<span data-ccp-props=\"{&quot;201341983&quot;:1,&quot;335559739&quot;:280,&quot;335559740&quot;:280}\">&nbsp;<\/span><\/p>\n\n\n<div class=\"single-cta\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">Subscribe to our Sage Advice Newsletter<\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p>Get our latest business advice delivered directly to your inbox.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"#gate-ab515c6e-7e90-4c2f-a67e-113872516e8b\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t>Subscribe<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"1440\" height=\"810\" src=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1073797282-1440x810.jpg\" class=\"single-cta__image\" alt=\"Working from home with tea in hand\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1073797282-1440x810.jpg 1440w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The deadline for compliance with the European Union\u2019s (EU\u2019s) General Data Protection Regulation (GDPR)&nbsp;was last month. It affects all businesses and as finance professionals, you need to know what it means for you and your company. The focus is on personal data, or data about individuals, and is a significant shake-up that affects any sole [&hellip;]<\/p>\n","protected":false},"author":280,"featured_media":4531,"menu_order":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sage_video":false,"post_featured_image_hide":false,"footnotes":""},"categories":[43],"tags":[116],"business_type":[41],"lilypad":[],"context":[],"industry":[57],"persona":[100],"imagine_tag":[242],"coauthors":[542],"class_list":["post-4504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-money-matters","tag-compliance","business_type-growing-business","industry-financial-services"],"sage_meta":{"region":"en-us","author_name":"Keir Thomas-Bryant","featured_image":"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2018\/06\/womaninoffice.jpg","imagine_tags":{"242":"Financial services"}},"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Sage Advice US","distributor_original_site_url":"https:\/\/www.sage.com\/en-us\/blog","push-errors":false,"_links":{"self":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts\/4504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/users\/280"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/comments?post=4504"}],"version-history":[{"count":1,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts\/4504\/revisions"}],"predecessor-version":[{"id":35269,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts\/4504\/revisions\/35269"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/media\/4531"}],"wp:attachment":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/media?parent=4504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/categories?post=4504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/tags?post=4504"},{"taxonomy":"business_type","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/business_type?post=4504"},{"taxonomy":"lilypad","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/lilypad?post=4504"},{"taxonomy":"context","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/context?post=4504"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/industry?post=4504"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/persona?post=4504"},{"taxonomy":"imagine_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/imagine_tag?post=4504"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/coauthors?post=4504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}