The General Data Protection Regulations (GDPR) came into effect on 25th May 2018, and the Board has implemented the policy below to comply and “legalise” all personal data held in our records. Although many of the concepts and principles in the new legislation are in line with those contained in the Data Protection Act (DPA), there are new elements and significant enhancements to consider. For example, the GDPR states that organisations must determine and document the lawful basis for holding personal data, explaining why it is required, how it is used and the consequence of it not being available.