Presentation to GTMC on GDPR

Slides:



Advertisements
Similar presentations
The EU General Data Protection Regulation Frank Rankin.
Advertisements

Information Governance Support Information Governance Services
General Data Protection Regulation (EU 2016/679)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Data Protection Officer’s Overview of the GDPR
Key changes with the GDPR
General Data Protection Regulations: The Key Changes
GDPR (General Data Protection Regulation)
Overview General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
GDPR – What’s it all about???
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Any impact on procurement? 16/11/2017.
KEY CHANGES TO THE DATA PROTECTION LANDSCAPE
International Regulatory Trends
Museums + Heritage webinar, 30 November 2017
The EU General Data Protection Regulation (GDPR)
GDPR Overview Gydeline – October 2017
Data Protection Update – GDPR or bust
GDPR Overview Gydeline – October 2017
The European Union General Data Protection Regulation (GDPR)
Data protection reform:
GDPR Road map to Compliance.
General Data Protection Regulation (GDPR)
Introducing GDPR: How the General Data Protection Regulation transforms the world Laura Mudd November 2016.
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
New Data Protection Legislation
Introducing the General Data Protection Regulation 2016
GDPR and Health and Safety
Headline notes UK data protection law will change on 25 May 2018, when the EU General Data Protection Regulation (“GDPR”) takes effect, replacing the.
State of the privacy union
The general data protection regulations practicalities for practice
G.D.P.R General Data Protection Regulations
GENERAL DATA PROTECTION REGULATIONS (GDPR)
The GDPR & Schools - An Introduction -

General Data Protection Regulations
General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR How does it apply to me?.
Guide to overview of changes under GDPR ww.ZAKSIT.com
GDPR For The Voluntary Sector
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations (GDPR) Training
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
The General Data Protection Regulation Six months on – What’s changed
Presentation privacy law
The General Data Protection Regulation: Are You Ready?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
#eaThinkData Get Ready for GDPR #eaThinkData.
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation (GDPR)
General Data Protection Regulation “11 months in”
General Data Protection Regulation
General Data Protection Regulation Community Councils
The EU General Data Protection Regulation
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Presentation to GTMC on GDPR

What is the GDPR? Harmonised Data Protection regulation across the EU ICO has indicated that Brexit will have no impact on adoption (one way or another…) Applies to organisations that hold data on EU citizens and residents Applies to Controllers (say how and why data is processed) and Processors (process data on behalf of controllers) Enhanced obligations over and above DPA, particularly on Processors

What data does GDPR apply to? Personal Data Broader definition of personal data Can include online identifiers (e.g. and IP address) Sensitive Personal Data Generally, sensitive information about an individual Again, broader definition applies (e.g. genetic and biometric data) Special rules for processing children’s data

Principles of the GDPR Similar to DPA. Data shall be… Lawful processing Data collected for a specific, legitimate purpose Adequate, relevant and limited to that purpose Accurate and kept up to date Kept for no longer than needed Kept secure Much enhanced principle of ACCOUNTABILITY

Accountability Critical new principle Organisations must DEMONSTRATE compliance This means… Documenting processing activities Appoint a DPO? Data Protection Impact Assessments DP “by design and by default” Maintain records of processing activities Must actively demonstrate compliance

Basis for Processing Have to demonstrate a legal basis for processing This can include: Consent Legitimate basis for processing (including performance of a contract) Public interest Importantly, consent is not the only acceptable basis for processing

Rights of Individuals Enhanced existing rights: Right to be informed Right of access Right of rectification Right to object Rights regarding automated processing New rights Right to restriction Right to erasure Right to data portability

Consent Important – consent is not the only acceptable legal basis for processing personal data But – consent MUST be sought for processing sensitive personal data Consent requires “clear, affirmative action” (i.e. not a pre-ticked box) It must be freely given, informed, specific, and verifiable. It can be withdrawn at any time

Breach notification & enforcement Breaches generally expected to be report within 72 hours (but also ‘without undue delay’) Extends mandatory breach reporting beyond ISPs and telcos to all controllers/processors Report to data controllers, regulators and – in some cases – affected data subjects FINES – up to €20m or 4% of global turnover for major breaches Up to €10m or 2% of global turnover for minor breaches

What are other companies doing? Mapping stored data for GDPR applicability Reviewing data processing processes and documenting what they have in place Appointing a DPO if not in place Considering record keeping and responses to GDPR requests (particularly erasure, data portability) Projects are very much in progress or planning, not complete

Thank you