Skip to main content
SwiftCase
PlatformSwitchboardFeaturesSolutionsCase StudiesFree ToolsPricingAbout
Book a Demo
SwiftCase

Workflow automation for UK service businesses. Created in the UK.

A Livepoint Solution

Platform

  • Platform Overview
  • Workflow Engine
  • Case Management
  • CRM
  • Document Generation
  • Data Model
  • Integrations
  • Analytics

Switchboard

  • Switchboard Overview
  • Voice AI
  • Chat
  • Email
  • SMS
  • WhatsApp

Features

  • All Features
  • High-Volume Operations
  • Multi-Party Collaboration
  • Contract Renewals
  • Compliance & Audit
  • Pricing
  • Case Studies
  • Customers
  • Why SwiftCase

Company

  • About
  • Our Team
  • Adam Sykes
  • Nik Ellis
  • Implementation
  • 30-Day Pilot
  • Operations Pressure Map
  • For Your Role
  • Peer Clusters
  • Engineering
  • Careers
  • Partners
  • Press
  • Research
  • Tech Radar
  • Blog
  • Contact

Resources

  • Use Cases
  • Software
  • ROI Calculator
  • Pressure Diagnostic
  • Pilot Scope Estimator
  • Board Case Builder
  • Free Tools
  • Guides & Templates
  • FAQ
  • Compare
  • Glossary
  • Best Practices
  • Changelog
  • Help Centre

Legal

  • Privacy
  • Terms
  • Cookies
  • Accessibility

Stay in the loop

Cyber Essentials CertifiedGDPR CompliantUK Data CentresISO 27001 Standards

© 2026 SwiftCase. All rights reserved.

Back to Blog
Security

We're GDPR compliant, are you?

Consumers and businesses are increasingly savvy about how companies handle their data. With the advent of ‘Big Data’ and targeted, personalised.

Dr. Adam Sykes

Dr. Adam Sykes

Founder & CEO

May 24, 2018
5 min read

Consumers and businesses are increasingly savvy about how companies handle their data. With the advent of ‘Big Data’ and targeted, personalised direct-marketing, clients are growingly concerned about what business know about them, how they are using that information and, after some high-profile breaches, the safety of their data.

General Data Protection Regulation (GDPR) brings new data security requirements for businesses that apply from today, the 24th of May 2018. Despite being EU regulations, the UK still comes under the new rules and will continue to do so, notwithstanding the current Brexit position.

The area covered by these rules relates to any business who processes data of a resident of the EU, irrespective of whether any payment is made for the service provided. Applicable non-EU companies should have appointed a representative in the EU. Cloud services are not exempt from the new regulations.

Fines for companies breaching the rules are very hefty and can be up to 4% of annual global turnover (AGT) or €20 million (whichever is higher). There is a reduced penalty rate of up to 2% of AGT for not keeping records in order, failure to notify a breach or conduct an impact assessment. These sanctions put pressure on businesses to ensure that the systems they use to deal with client data are secure.

It is now no longer possible to hide the request for consent for data use in some waffling small print. The application must be clear, in plain-English, and just as easy to withdraw as to sign up. The purpose of the data must be transparent, and the consent must be distinct from any other matters.

Data breaches must be stated to the relevant bodies within 72 hours of becoming aware of the incident if the violation results in risk to the rights and freedoms of the individuals, whose data is concerned. Also, companies who process data must inform their clients without undue delay. These new regulations make it vital that you deal with companies who will look after your data and comply with these policies.

Clients have the right to request all the information that you hold on them, details of where it is being processed and for what purpose. An electronic copy of this data should be provided free of charge (although some exemptions for costs do exist). It is important to check that your current system provider can export this information without excessive administration resources on your behalf.

The regulations also specify that companies should only hold data for the purpose that has been agreed by the client and the completion of works, also data access should be limited on a need-to-know basis. Therefore, your data management system should have separation of duties and data minimisation features to fulfil these obligations.

Clients have the right to be forgotten, with some exemptions. So, if their data is no longer required under the original use that consent was given, your data management system must be able to erase their information. Clients also have the right to request their data to be rectified within a definite period of a month, with extensions of 2 months in complex cases.

Overall, there are significant responsibilities on companies to ensure that they satisfy with these data security measures.

SwiftCase is a workflow management system, that can streamline your business processes and data capture while ensuring GDPR compliance.


Ready to automate your workflows?

SwiftCase helps operations teams streamline their processes with powerful workflow automation, case management, and AI-powered communication tools.

Book a demo | View pricing | Explore the platform

Related Articles

Security

Mortgage Enquiry Guide

June 4, 20249 min read
Security

Keep Compliant, Keep your Company

December 22, 20216 min read
Security

Imagine giving your clients access to you 24/7

October 18, 20215 min read

Get automation insights delivered

Join operations leaders who get weekly insights on workflow automation and AI.

About the Author

Dr. Adam Sykes
Dr. Adam Sykes

Founder & CEO

Founder & CEO of SwiftCase. PhD in Computational Chemistry. 35+ years programming experience.

View all articles by Adam →

Related Free Tools

GDPR Data Retention Calculator

Check UK GDPR retention periods and deletion dates for 30+ data types.

Try free

FCA Compliance Checker

Free self-assessment across Consumer Duty, complaints, and governance.

Try free

BCP Builder

Build a Business Continuity Plan with guided templates.

Try free

11.8M+ cases processed

Enterprise security, built in

ISO 27001 certified, fully encrypted, and hosted in UK data centres. Your data stays safe.

See Our Security
Book a Demo