What Does GDPR mean for you

Slides:



Advertisements
Similar presentations
POSSIBLE THREATS TO DATA
Advertisements

Guide to Massachusetts Data Privacy Laws & Steps you can take towards Compliance.
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Act. Lesson Objectives To understand the data protection act.
Data Protection for Church of Scotland Congregations
UNIT 3C Security of Information. SECURITY OF INFORMATION Firms use passwords to prevent unauthorised access to computer files. They should be made up.
General Purpose Packages
Local Government Reform and Compliance with the DPA Ken Macdonald Assistant Commissioner (Scotland & Northern Ireland) Information Commissioner’s Office.
Data Protection for Church of Scotland Congregations.
Breakaway Session 2: Data Protection and The Role of the Data Protection Supervisor Michael Mingle Director, NTSS Solutions (UK) D ATA P ROTECTION C ONFERENCE.
Objectives  Legislation:  Understand that implementation of legislation will impact on procedures within an organisation.  Describe.
Legal and Compliance Workshop July 28, 2016 Presented by: Lucy Du-Jones, Founder and Managing Director, du-tian.
General Data Protection Regulation (EU 2016/679)
Chapter 40 Internet Security.
The Data Protection Act 1998
Data Protection Regulation
Ian De Freitas, Partner, Farrer & Co 6 September 2017
CISI – Financial Products, Markets & Services
Handling Personal Data
General Data Protection Regulations and the IoT
Handout 2: Data Protection and Copyright
Microsoft 365 Get help with regulatory compliance
General Data Protection Regulation (GDPR)
GDPR – What’s it all about???
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
GDPR Overview Gydeline – October 2017
Business Risks of Insecure Networks
The Data Protection Act 1998
General Data Protection Regulation
Data Protection Legislation
GDPR Overview Gydeline – October 2017
INTRODUCTION TO GDPR 19/09/2018.
GENERAL DATA PROTECTION REGULATION (GDPR)
Vikas Dewangan (Senior Technology Architect)
All data occupies physical space, even if we don't think of it as such.
New Data Protection Legislation
GDPR and Health and Safety
The general data protection regulations practicalities for practice
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
G.D.P.R General Data Protection Regulations
Data Protection and GDPR – An introduction for Baptist Churches
The new data protection rules
General Data Protection Regulations
General Data Protection Regulation
Data Protection Managing risk is not just about health and safety and insurance. It’s about data protection too. New stricter data protection legislation.
Identify the laws and guidelines that affect day-to-day use of IT.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
A whistle stop tour of GDPR
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
Finham Primary School – GDPR Practice Guidelines
Recording Clinical Data
GDPR How does it apply to me?.
General Data Protection Regulation May 25th 2018
GDPR (General Data Protection Regulation)
Preparing for GDPR Sharing experiences of the process and using the British Canoeing Toolkit bit.ly/BCGDPRToolkit
How we’ll prepare for the General Data Protection Regulation (GDPR)
Information management and communication
General Data Protection Regulations 2018
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
GDPR Quiz Today’s trainer: Click here to use Kahoot! 1
Recording Clinical Data
Recording Clinical Data
#eaThinkData Get Ready for GDPR #eaThinkData.
How it affects policies and procedures
Understanding Data Protection
General Data Protection Regulation Q & A Session
Data Protection What can I do? GDPR Principles General Data Protection
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

What Does GDPR mean for you

What is GDPR The General Data Protection Regulation is legislation coming into effect for businesses in the UK in May 2018 In essence it is an enhancement to existing privacy regulations in the UK currently enforced by the Information Commissioners Office under the UK Data Protection Act. The Regulation is a European one however because it comes into force before the UK leaves it will be relevant and UK government has already said they would expect to implement it in UK law anyway.

What Does It Regulate Personal Data, This is defined as any data record which can directly or indirectly identify an individual. This includes but is not limited to Date of birth Address Email address NI Number Passport Number Bank details

What Are the Obligations. There are a number of requirements but to be brief. Any personal data must have the explicit permission of the owner (subject) for you to have it (so not a tick box left unticked) Any data you hold must be only used for the purpose you requested it and nothing else and must be removed from your systems once that purpose is no longer valid. The subject has a right to request what data you hold and to have it removed (provably) from your systems You must report any breach within 72 hours of the event.

What is a Breach A breach could be anything which causes an unauthorised person to access the data, or the data to be used or exist on a system which you have not explicitly informed the subject will occur. This would include Email of data to a staff personal email address. Accidental inclusion of users email address in CC instead of BCC when sending an email. Loss of a removable disk / laptop with data on it Ransomware / virus attack on your network Infection with a trojan to a user device or the network.

What are the penalties The penalties are harsh for non compliance with these regulations, They include a maximum fine of €20,000,000 or 4% of annual turnover whichever is greater. It is the case that reputational damage will also be considerable because the sanctions will be published The penalties will be on a sliding scale with the harshest for those organisations which do nothing to implement policy and practice to ensure their clients data is safe and understood.

How Does SharePoint Help? The Process of moving to SharePoint will involve going through and sanitising and disposing of data which you should not have, you should do this anyway but with the purpose of moving it is more likely to be successful. SharePoint includes a lot of data policies which allow you to manage what data is available, stored and who has access to it. Protecting the data which leaves the organisation is easier within office 365 because for example alerts and prevention strategies such as not allowing emails with NI numbers in or encryption of certain types of date before transmission. File systems on the servers the way they are mean a malicious software or person would have access to everything you have, a SharePoint site is a website, they would only have access to what you synced or were looking at. Office 365 and SharePoint can include MFA (multi factor authentication) allowing you to secure access with more than just a password Office 365 includes industry recognised security and 3rd party audit tools so you can prove to 3rd parties you take this seriously.