Overview General Data Protection Regulation (GDPR)

Slides:



Advertisements
Similar presentations
Big Data and data protection
Advertisements

The Information Commissioner’s Office David Evans.
The EU General Data Protection Regulation Frank Rankin.
Information Governance Support Information Governance Services
General Data Protection Regulation (EU 2016/679)
Data Protection Regulation
Tony Sheppard Mobile Guardian
General Data Protection Regulation (GDPR)
Data Protection Officer’s Overview of the GDPR
Key changes with the GDPR
The future of data protection: General Data Protection Regulation
Ian De Freitas, Partner, Farrer & Co 6 September 2017
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Ireland’s transition towards the GDPR
Presentation to GTMC on GDPR
General Data Protection Regulation (GDPR)
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
GDPR Awareness and Training Workshop
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
KEY CHANGES TO THE DATA PROTECTION LANDSCAPE
International Regulatory Trends
Museums + Heritage webinar, 30 November 2017
GDPR Readiness Project
GDPR Overview Gydeline – October 2017
GDPR support January GDPR support January 2018.
GDPR Overview Gydeline – October 2017
The European Union General Data Protection Regulation (GDPR)
INTRODUCTION TO GDPR 19/09/2018.
Data protection reform:
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
Introducing GDPR: How the General Data Protection Regulation transforms the world Laura Mudd November 2016.
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
Introducing the General Data Protection Regulation 2016
Are you processing personal data lawfully?
GDPR: getting your firm ready
Data protection reform – update from the ICO
State of the privacy union
Privacy: a work in progress
Information Governance
G.D.P.R General Data Protection Regulations

General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
LORDSHILL HEALTH CENTRE GDPR Information
GDPR How does it apply to me?.
How we’ll prepare for the General Data Protection Regulation (GDPR)
General Data Protection Regulation
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
General Data Protection regulation (GDPR)
Fines, Sanctions and Compensation The teeth in the GDPR & Data Protection Act 2018 by Simon McGarr, CIPP/E Data Compliance Europe.
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
What Governors need to know about GDPR
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Data Protection What can I do? GDPR Principles General Data Protection
GDPR: Understanding your obligations and the ongoing challenges
Information Governance
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Overview General Data Protection Regulation (GDPR) 26th September 2017 Indi Viknaraja

GDPR So what is it?

The Data Protection Bill was introduced into the House of Lords on 13 September 2017. It will replace the Data Protection Act 1998 and implement the EU General Data Protection Regulation (GDPR).  

So who regulates the GDPR in this country?

The Information Commissioner’s Office The UK’s independent body set up to uphold information rights Enforce and regulate freedom of information and data protection laws Provide information and advice Promote good practice

Regulation Applies across the EU Directive Implemented locally

Do Governors work with personal data? Examples: Pupil learning and progress -pupil applications, admissions, attendance, and exclusions Staff deployment, absence, recruitment, retention, morale, and performance The quality of teaching

DEFINITIONS

personal & special categories data Any information relating to an identified or identifiable natural person ‘data subject’ = identifiable person who can be identified by an identifier such as a name, address, an identification number, location data, online identifier or To one or more factors specific to a person’s physical, health, psychological, genetic, mental, economic, cultural or social identity personal & special categories data

Principles The 8 DPA principles are replaced by 6 GDPR principles which are broadly similar but more detailed and include the addition of the ‘Accountability’.

RIGHTS

Data Subjects rights have been broadened

GDPR Data Controller Data Processor Decides how and why data processed Does as required under contract with controller

Other Key Changes Data Protection Privacy Impact Assessments Privacy by Design Data Protection Officer

Breaches A new requirement to report ‘High risk’ breaches: to the ICO and the relevant data subjects within 72 hours failure to notify a breach can result in a significant fine of up to 10 million euros Medium breaches of data protection are subject to administrative fines: whichever is higher of the following: up to 10,000,000 EUR up to 2 % of the total worldwide annual turnover of the preceding financial year (in the case of an undertaking) Major breaches of data protection are subject to administrative fines: up to 20,000,000 EUR up to 4 % of the total worldwide annual turnover of the preceding financial year (in the case of an undertaking) The Data Subject is at the centre of claims for compensation. The Data Controller must pay up front and then recoup from Data Processor where appropriate

Breaches £20,000,000 or 4% of turnover % applies only to private sector £10,000,000 or 2% of turnover AMONG OTHER THINGS Consent & other conditions Rights inc. subject access and fair processing International transfers Failure to have DPO Failure to report breaches Failure to do impact assessment

So what we need to do now! Increase awareness Training As a starting point we suggest governors:          Visit the GDPR section on the ICO website         Look at the  ICO’s overview of the GDPR - a good place to start Look at the 12 steps to take towards compliance which the ICO has published Raise awareness of GDPR at all levels within their school At this moment in time the GDPR is still undergoing ‘change’. So we suggest Governors and Head teachers read the information to familiarise themselves with the requirements.