A distinctive local company with national standards. Practical Credit Control & New [GDPR] Data Protection Regulations

Similar documents
Data held by BASC clubs and syndicates - a brief guide

PRIVACY NOTICE LAST UPDATED: SEPT. 2018

Firefighters Pension Scheme

What does GDPR and the new Data Protection Act mean to Brokers/Intermediaries?

LAMP Services Limited Privacy Notice v1.2 4 th March Controller

ARE YOU READY FOR THE NEW DATA PROTECTION LAWS?

Corporate Stakeholder Pension Plan

The contract is important so that both parties understand their responsibilities and liabilities.

privacy notice who is responsible for processing your personal data and who you can contact in this regard reasons for processing your data

The GDPR how to prepare MiFID II where are we now? Wednesday 21 February 2018

Home Insurance. Privacy Notice

Welcome To Your Data Protection Journey. Paula Tighe Information Governance Executive

Terms and conditions for large and corporate businesses for the supply of gas and electricity ( corporate terms )

Your Data Your Rights

WELCOME TO FULL COVER AND DAMAGE COVER

Personal Data. Protection Policy

EnerSys UK Pension Scheme (the Scheme) Privacy Notice

Group Personal Pension Flex

Customer Privacy Notice Edition

DATA SUBJECT ACCESS REQUEST POLICY AND PROCEDURE

Data Protection Privacy Notice for people not directly involved in the accident

Vodafone. Insurance. Vodafone. Power to you. Vodafone Business Premier Inclusive Damage and Breakdown Insurance

Terms and Conditions:

DATA PROTECTION POLICY

Fraudulent Check, Credit Card Fraud and ID Theft Guide

Warehouse Money Visa Card Terms and Conditions

Vodafone. Insurance. Vodafone. Power to you. Vodafone Corporate Damage and Breakdown Insurance

Next Generation Guarantor Application Form

SILCHESTER INTERNATIONAL INVESTORS DATA PROTECTION POLICY

Your Right Hand Finance Ltd (YRH) Subject Request Policy

Member Circular March Implementation of the EU General Data Protection Regulation 2016/679 General Guidance to Members

henriksen limited This document sets out how Henriksen processes data and your rights as the data subject.

Hillgate Travel GDPR Response. Privacy Policy

Privacy Policy. Effective Date 1 December 2017

Citizens Advice / ABCUL Frequently asked questions for advisers

PRIVACY NOTICE issued by DALE Accounting and Tax Services Ltd

Privacy Policy. Amendment History. Trustee Name

GDPR: The future of marketing and commercialisation of data. Alexander Brown & Matt Dyer, Simmons & Simmons

DATA PROTECTION NOTICE

Group Stakeholder Pension Plan Key features

The New EU General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR): action plan for pension scheme trustees

What you need to know about credit card processing? The basics of credit card processing? A diagram showing the flow of data authorization

Personal Lending Products

Southern Golden Retriever Rescue Data Protection Policy

WHAT DECISIONS WILL YOU NEED TO TAKE? GETTING READY FOR THE GDPR PART FOUR LEGAL ISSUES AND TRUSTEE DECISIONS

Rental Exchange Frequently Asked Questions

Group Flexible Retirement Plan

T s And C s. General terms and conditions. It s Ours. June 2018

AMIST Super. Privacy Policy

Policyholder details form

Highland Distillers Pension Scheme (the "Scheme") Privacy Notice

The Nortel Networks UK Pension Plan (the Plan) Privacy Notice

WELCOME TO FULL COVER AND DAMAGE COVER

HEALTH INSURANCE. Consumer Information. Privacy Notice Consumer Rights at Renewal. March 2018

The Retirement Account Application form

Power of Attorney Application to Appoint an Attorney to Operate an Account(s)

Privacy Policy. For the purposes of Data Protection Legislation the data controller is the Company.

Privacy Statement. Introduction

Claims Management Claim Form. When you have filled in the form, please send it to us at:

PRIVACY NOTICE 1. WHAT IS A PRIVACY NOTICE & WHY IS IT IMPORTANT?

TAX TAX & ACCOUNTANCY & ACCOUNTANCY

Loaded Everyday card terms and conditions

Fixed Deposit Account Terms & Conditions

Introducing ICS Umbrella

Bank Account. Terms and Conditions

OUR TERMS OF BUSINESS AND COMMITMENT TO YOU

TPR answers to questions asked by Aon Consulting

ING Privacy Policy. Issued June 2017

REVOLVING CREDIT APPLICATION

Family Assist Guarantor Supplementary Application Form

Man and Machine - Data Protection Policy

Privacy Policy. NESS Super is committed to respecting your right to privacy and protecting your personal information.

ScottishPower Gas and Electricity. General Terms and Conditions for Domestic Customers

WELCOME TO FULL COVER AND DAMAGE COVER - MOBILE PHONE AND TABLET INSURANCE FOR LARGE BUSINESS

British Bankers Association submission to the consultation on the legal framework for the fundamental right to protection of personal data

Tax Certification Form for Business Customers

RENTAL APPLICATION. Property Applying For: * When do you want or need to move in: Have you Viewed this Property?

The Retirement Account

Westpac Privacy Policy.

EU General Data Protection Regulation vs. Swiss Data Protection Act (in the Private Sector 1 )

INTERNATIONAL SOS. Data Protection Policy. Version 1.8

Pension Automatic Enrolment Your questions answered. This provides the answers to some of the questions that you have

2018 Australian privacy outlook

Firm Registration Form - Equity Release and Mortgage products

Pension Trustees. Final Countdown to the GDPR

Self Invested Personal Pension (SIPP) Key Facts

BUY TO LET MORTGAGE APPLICATION FORM

General Data Protection Regulations Briefing (the presentation you ve all been waiting for)

Dear. Scottish Equitable Stakeholder Scheme (the Scheme ) Group Stakeholder Pension plan application

RAY WHITE (EMERALD) 80 Egerton Street Emerald QLD 4720 PH: FAX:

Legal Compliance Education and Awareness. Privacy Act (Commonwealth)

1.5 If your personal details change, please contact us at Jonathan Tait & co, 9 Crown Street, Aberdeen, AB11 6HA.

CTIAQ - Credit Reporting Policy

Conditions of Use Latitude Infinity

General and Products Liability

ENGIE Prepayment. A Guide to your prepayment meter

Ark Syndicate Management Limited. Privacy and Transparency Notice. Version 1

1. What Data do we collect and where do we get it from?

Conditions for supplying energy to small and medium enterprises (November 2016)

Transcription:

A distinctive local company with national standards Practical Credit Control & New [GDPR] Data Protection Regulations 1

Introduction DSL started collecting veterinary debt 11 years ago and now help over 700 practices collect what s owed to them. We are known throughout the veterinary world as the go to collection and debt prevention specialist. Debt Prevention guidance is given free to our customers and, as far as we know, its a first in the debt collection industry. Credit Control - Top Tips 2

Meet the Team 3

DSL & VPMA DSL have teamed up with VMG to deliver Roadshows around the UK to promote Practical Credit Control and Compliance within the new GDPR regulations. GDPR General Data Protection Regulation Formally Known as DPA 1998 New Regulations set to come into force in May 2018 Article 5 of GDPR requires demonstrable compliance with the new regulations. [Demonstrable, clearly, apparent or capable of being logically proved] Ensuring staff are aware of your organisation s data protection policy is now more important than ever. ICO: Information Commissioner's Office 4

What is GDPR? GDPR applies across Europe and despite Brexit the UK Government has signed up to it. The new regulations begin 18 th May 2018 and you must be ready!! Failure to comply could land you in court with a criminal record. 5

Why is GDPR Necessary? The GDPR is designed to harmonise data protection law throughout Europe and to modernise it. A great deal has changed in the last two decades, not least the ways in which personal data is collected and processed by organisations. In particular, the growth of the internet and the significant increase in the amount of personal data being transferred, stored, and processed online means that legislation that worked 20 years ago is, in many respects is no longer up to the task. 6

Will the Law Affect Me? Simply put, if you handle personal data of any kind you are already subject to the Data Protection Act 1998, yes, it will. The GDPR will apply to all organisations operating within the EU and to organisations outside the EU that deal with individuals within the EU. The good news is that if you are already complying with the Data Protection Act, you re off to a strong start. Nonetheless, it is very important to be aware of, and to understand, your obligations (existing and new) under the GDPR. 7

Key Changes Increased accountability and greater responsibilities within organisations to ensure that personal data is protected and processed within the bounds of the law; A wider range of data will now be classed as personal data ; Data processors (e.g. contractors and service providers) will now also be regulated; The penalties for failure to comply will be much stronger (up to 20m or 4% of total worldwide turnover, whichever is higher); New procedures requiring data controllers to notify the ICO of data breaches within 72 hours of the breach; Enhanced individual rights including greater transparency and the right to be forgotten ; The requirement for many organisations to appoint a Data Protection Officer where personal data processing is significant; and Stricter rules on consent given by data subjects to the collection and processing of their personal data. 8

Information You Hold Document what type of personal information you hold, where it came from and who you share it with. GDPR requires you to maintain records of your processing activities, i.e. a company GDPR Policy. GDPR requires organisations to show how they comply with data protection principles by having effective policies and procedures in place. If you have inaccurate personal data and have shared it with another organisation, you have to tell the other organisation about the inaccuracy so they can correct their records. 9

Staying Safe Awareness All decision makers and key people in the organisation need to know the law is changing. Appreciate the impact this will have and identify areas of risk. Do you have a Data Protection Policy? Do you have a Risk Register? Do you have a Data Protection Officer? 10

Good Credit Control Know Your Customers Think of all the hoops you have to jump through when you register to join a website or buy something on line? Customers must complete an application form and provide proof of identity and be over 18 years old. Give your customer a welcome pack. 11

Customer Registration What documents do new customers need to bring with them to register? Individual Name / Address / Date of Birth / Mobile & Land Line Number / Email Address / Utility Bill / Driving Licence / Passport [Photographic] etc. Limited Company Director / Company Secretary. Remember, it s the limited company that will owe you money, not the individual company officer. 12

How Can You Reduce Risk and Stay Compliant with GDPR Gather lots of information about your customers. Keep a copy of documents used to prove ID. Scan copies to the customer computer file, only authorised staff can access the documents. A good example of Practical Compliance with GDPR regulations [Formally DPA 1998] 13

Who is Responsible for Enforcing the New General Data Protection Regulations [GDPR] Information Commissioner's Office [ico.] An independent body set up to uphold information rights. Personal data is information relating to an identifiable living individual. Whenever personal data is processed, collected, recorded, stored or disposed of it must be done within the terms of the Data Protection Act (DPA). 14

Individuals Will Be Held Responsible!! 15

An Actual Fine Imposed in 2017 Stuart Franklin has been prosecuted at Birmingham Magistrates Court for the offence of unlawfully disclosing personal data. The defendant, who at the time worked at a Walsall based domestic services company, emailed the CVs of 26 job applicants to a third party company without his employer, the data controller s, consent. Mr Franklin pleaded guilty to the offence under section 55 of the Data Protection Act, and was fined 573, ordered to pay 364 prosecution costs and a 57 victim surcharge. 16

Do You Have a GDPR Policy? 17

What Should Be In Your Policy? Consent in a written declaration New GDPR principles demands where consent is given as part of a written declaration which also concerns other matters, the request for consent should be clearly distinguishable from other matters and be presented in a clear and easily accessible form and should not be lost in the small print of your terms and conditions document. Ideally consent should be set out separately within your terms and conditions document and in a clear and concise format. 18

Key Points What does the Data Protection Policy Include, here are some relevant examples. Lawful, Fair, and Transparent Data Processing. Processed for Specified, Explicit & Legitimate Purposes [Pet Owner Records & None Payment] Accuracy of Data & Keeping Data Up to Date. Secure Processing and Storage. Rectification of Personal Data. 19

Information Prevents Debt Robust credit control starts when a customer walks through the door. Tighten your registration procedures and it goes without saying, bad debt will reduce. If a customer asks for an account, doesn t have insurance or can t pay straight away, ask for ID and some money on account before you agree to carry out treatment. Insist the customer signs your Terms & Conditions along with a consent form, back it up with proof of ID and a verified address. Give the customer a copy of your Terms & Conditions & Consent form. Don t be afraid to ask for money on account. Remember, if you go ahead without obtaining information, you may be working at a loss!! 20

Good Credit Control Supports GDPR Compliance 21

It s Not Rocket Science Review your customer registration form: does it ask the right questions? Train staff to obtain the right information. Insist a member of staff takes responsibility for the Registration Process. Introduce a Welcome Pack and be sure to include a signed copy of your Terms & Conditions with a GDPR Consent Section Signed. Arrange for a member of staff to take responsibility for customer payments. Use the Vet Pay App to take payment when away from the practice, it will reduce bad debt. 22

Dealing with Disputes Do you have a clear policy for dealing with disputes? Do you have a copy on display in public areas? Do you give customers a copy for their records? Are you open and honest about late payment charges? Tell customers costs will be added if they do not pay on time. 23

Add Collection Charges Do Your Existing T&Cs allow you to recover administration, collection and legal costs. Ensure you investigate and resolve disputes quickly. Make a key member of the team responsible for the process. DON T FORGET TO ADD COLLECTION COSTS BEFORE SENDING THE DEBT TO DSL. Additional costs incurred will be added by DSL. 24

Conclusion If you don t get the right information, this could be what happens to your / our Letters R 25

Credit Control Top Tips Have a dedicated credit control resource. Have accurate customer data. Send out reminders on time. Telephone customers / chase payment. After 30 days pass bad debt to a specialist recovery agency. A credit control partner provides an experienced, dedicated resource to recover your money. 26

What does a Debt Recovery partner do? Call Email Letter Text Visit Customer s Address Legal Action Provide a dedicated resource committed to collecting your outstanding accounts. Collect debt up to 6 years old. 27

Why DSL Vet specialists Extension of your brand We treat your money as if it is our own Pay weekly Contingency based You pay us only when we collect Can offer arrangements to pay bill over a period of time Identify vulnerable customers Allow you to concentrate on your day jobs We can visit your customer at their property 28

Does The New GDPR Regulations Affect Door Knocking? Reality is, No they don t!! Staff at DSL already comply. Dealing with Neighbours and family members face to face can be tricky. How do collection officers obtain information about family members or Neighbours without breaking the regulations? 29

Why is Door Knocking So Successful? Intelligence A Way Forward Legal Action [with confidence] Payment / Ability To Pay. Address Confirmation. Vulnerable Individuals. Dispute Resolution Write Off. 30

Most debts selected for personal visit fall into the following categories: Refused to Pay Can t Pay Moved Away Passed Away Unresolved Client Dispute Insurance Underpayment Excess Not Paid Insurance paid to pet owner rather than vet 31

Door Knocking Delivers Informed decisions = Good Decisions 32

A way forward What can we gain from intelligence gathered? Let s look at what type of information we have and what that tells us. 33

Intelligence Gathered During a Visit Residence confirmed, no reply, left letter. Gone away trace to new address. Unable to confirm residency, left letter, no reply, send to trace. New address obtained, restart collection process at new address. Discover vulnerable and hardship customers. Type of property visited detached, semi, terraced, flat, council, private rental, owner occupied. Condition of property good, fair, poor, very poor. Each case is assessed and placed on the appropriate track for next action. 34

Summary Carry on doing what you do, but, do it better!! Implement new procedures & Policy s - GDPR Policy document. Risk Assessment document. Complaint Handling Policy. Revised Customer Registration Form. Welcome Pack. Review / Revise Terms & Conditions to reflect GDP Regulations. 35

Q & A 36