General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.

Slides:



Advertisements
Similar presentations
Data Protection.
Advertisements

© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
The EU General Data Protection Regulation Frank Rankin.
General Data Protection Regulation (EU 2016/679)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Tony Sheppard Mobile Guardian
General Data Protection Regulation (GDPR)
Accountability & Structured Privacy Management
The future of data protection: General Data Protection Regulation
Presentation to GTMC on GDPR
Information Destruction; 2017 and beyond!
GDPR – What’s it all about???
GDPR Awareness and Training Workshop
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
The EU General Data Protection Regulation (GDPR)
GDPR Overview Gydeline – October 2017
GDPR support January GDPR support January 2018.
GDPR Overview Gydeline – October 2017
INTRODUCTION TO GDPR 19/09/2018.
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
General Data Protection Regulation (GDPR)
Introducing GDPR: How the General Data Protection Regulation transforms the world Laura Mudd November 2016.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
Data Protection Reform in Local Government
GDPR is There, Are you Ready?
GDPR - New Data Protection Regulation
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
GDPR and Health and Safety
Data protection reform – update from the ICO
Information Governance
G.D.P.R General Data Protection Regulations
Data protection in the Education Sector - understanding the impact of GDPR Tuesday 23rd January 2018.
The GDPR & Schools - An Introduction -
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR (General Data Protection Regulation)
How we’ll prepare for the General Data Protection Regulation (GDPR)
GDPR For The Voluntary Sector
IMPLICATIONS OF GDPR ROBERT BELL.
Data Protection in a Tutorial Context
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
GDPR enforcement begins
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
The General Data Protection Regulation: Are You Ready?
General Data Protection regulation (GDPR)
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
What Governors need to know about GDPR
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The General Data Protection Regulations 2016
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation (GDPR)
GDPR: Understanding your obligations and the ongoing challenges
GDPR – One Year On School Business Managers Forum 4 July 2019
Information Governance
GDPR is here – are you ready?
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams

Hillyer McKeown LLP Commercial Law Firm Chester, North Wales, Wirral, Liverpool Over 100 staff Diverse UK-wide client base Legal 500 The team have been praised for the “first-class clarity and quality” of their advice.

What are the GDPR? Replace current EU legislation on the processing and handling of data (including the Data Protection Act 1998) Effective from 25th May 2018 Aim to harmonise and strengthen the data rights of EU citizens Will apply to all EU member states, including the U.K. The changes introduced substantially increase the responsibility of the data controllers and processors regarding the handling of individuals’ personal data.

What is data? Personal Data Sensitive Personal Data Data Subject Data which relates to a living individual who can be identified from that data Sensitive Personal Data Data relating to a living individual’s racial / ethnic origin; religious beliefs; criminal offences; physical / mental health. Data Subject An individual who is the subject of personal data Data Controller A person who determines how personal data is to be processed Data Processor Any person who processes the data on behalf of the Data Controller

Why are the GDPR important? Five key changes: Stricter rules on consent Enhanced rights for data subjects Accountability measures increased Data breach notifications Fines

Case Examples GDPR is high profile following a number of recent data breaches:- NHS Equifax

Legitimate grounds for processing Contractual necessity Legitimate interests Compliance with a legal obligation Protection of vital interests Public Interest / Official Authority Consent

How do you ensure compliance? Raise awareness of GDPR Discuss the potential impact of GDPR at board level and throughout the business. Roles and responsibilities Find out who is accountable for the day to day control of collecting, storing and processing any personal data. Appoint a data protection officer (DPO) and supporting team Appoint a DPO and representatives from responsible departments to coordinate the organisational changes needed to comply with the new law.

How do you ensure compliance? Data Protection Impact Assessment (DPIA) for personal data Perform a risk assessment for each department, including the lawful basis for handling someone’s data. Review consent Define how you seek, record and manage consent for collecting, storing and processing types of personal data. Audit trail Review the processes and mechanisms in place to ensure security, accountability and transparency.

How do you ensure compliance? Review legal documentation Update individuals’ rights and privacy information such as privacy notices to make compliant with the new law. Subject access requests Define how your business plans to handle quests from people to access their data according to the new GDPR. Update policies and procedures with third parties Is the data you hold shared outside your organisation? If so, who? How? Where?

How do you ensure compliance? Testing and review ready for 25th May 2018 Complete final staff training on updates to new policies, processes and procedures for aspect of personal data management. Review and test personal data handling across the business, within departments and for key individuals who have responsibility for data. Plan for ongoing GDPR compliance via comprehensive auditing and reporting. Ensure accurate, compliant and transparent data management.

Don’t panic! 5 steps to ensure compliance Start the discussion and gather information Decide who will be responsible (consider DPOs) Training and Policies Evidence and Accountability Preparing for potential breaches

Five key questions businesses should be asking themselves now Where do we currently store personal data, and is it secure? Who has control of personal data at present? What authority do we have to use and process personal data? What are the current IT systems and processes relating to the data we hold? Is there a process of erasure? Is the data we hold shared with any external contacts or third parties, and it is shared anywhere outside the European Economic Area (EEA)?

Contact Details David Jones Tel: (0151) 666 0747 Email: dbj@law.uk.com Angharad Williams Tel: (01244) 357 284 Email: aww@law.uk.com

Thank you, do you have any questions?