General Data Protection Regulation - are we up to date?

Br Dent J. 2020 Aug 14. doi: 10.1038/s41415-020-1844-8. Online ahead of print.

Abstract

Introduction The General Data Protection Regulation (GDPR) is now at the core of data protection and provides more rights than ever before for individuals to control the data that is held about them, and holds organisations accountable.Materials and methods Questionnaire-based knowledge audit consisting of 18 questions relating to GDPR, which was created and distributed to all staff at departmental audit meetings. The gold standard was set that all members of staff were required to pass the questionnaire, with the pass mark set at 14/18. This was followed by a tailored teaching session in conjunction with an online delivery element.Results Cycle 1 was completed in December 2018; the pass rate was 1.6% (1/63) with a response rate of 87.5% (63/72). Scores ranged from 5-14 out of 18. Following dissemination of results, a tailored teaching session was conducted in conjunction with online learning. Cycle 2 was completed in February 2019; the pass rate was 83.9% (47/56) with a response rate of 77.7% (56/72). Scores ranged from 3-18 out of 18.Conclusions Initially, staff knowledge of GDPR was inadequate. Staff knowledge improved with tailored teaching; however, knowledge and understanding of GDPR requires further improvement to meet the gold standard. Therefore, repeat cycles of tailored teaching and audit are planned. It is important that all staff have a good understanding and working knowledge of GDPR to ensure compliance in all areas of practice.