GDPR - Individual’s Rights

Slides:



Advertisements
Similar presentations
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
Advertisements

Implementation of Security and Confidentiality in GP Practices.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Session 12 Information management and security. 1 Contents Part 1: Introduction Part 2: Legal and regulatory responsibilities Part 3: Our Procedures Part.
The EU General Data Protection Regulation Frank Rankin.
Data protection—training materials [Name and details of speaker]
1 Information Governance (For Dental Practices) Norman Pottinger Information Governance Manager NHS Suffolk.
Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Information Governance Support Information Governance Services
General Data Protection Regulation (EU 2016/679)
The Data Protection Act 1998
Data protection and data sharing
Data Protection Regulation
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Tony Sheppard Mobile Guardian
General Data Protection Regulation (GDPR)
Accountability & Structured Privacy Management
Preparing for a data protection audit 28 September 2017
CISI – Financial Products, Markets & Services
GDPR Module 3: Accountability and Governance
Presentation to GTMC on GDPR
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
The EU General Data Protection Regulation (GDPR)
The Data Protection Act 1998
GDPR Overview GDPR - General Data Protection Regulations
GDPR Road map to Compliance.
Public Sector Organisations - are you GDPR ready?
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
General Data Protection Regulation
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
Introducing the General Data Protection Regulation 2016
Headline notes UK data protection law will change on 25 May 2018, when the EU General Data Protection Regulation (“GDPR”) takes effect, replacing the.
Data protection reform – update from the ICO
State of the privacy union
The general data protection regulations practicalities for practice
G.D.P.R General Data Protection Regulations
The GDPR and research data
Presented by Trevor Butler
The new data protection rules
The GDPR & Schools - An Introduction -
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.
General Data Protection Regulation
Data Protection principles
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
A whistle stop tour of GDPR
How we use Your Health Records
How we’ll prepare for the General Data Protection Regulation (GDPR)
Data Protection Impact Assessments How do we carry out a DPIA?
Data protection and data sharing
Data Protection and Audit
Welcome!.
General Data Protection Regulations 2018
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
Governing the risk of GDPR compliance
The General Data Protection Regulation: Are You Ready?
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
General Data Protection regulations – Pathway to Compliance
What Governors need to know about GDPR
Session 4: Data Mapping and Data Subject Rights
Data Protection What can I do? GDPR Principles General Data Protection
Session 4: Data Mapping and Data Subject Rights
GDPR Session
The GDPR & Schools - A Guide for Governors and Trustees -
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

GDPR - Individual’s Rights To be informed Access Rectification Erasure Limited Processing Data Portability Objections Profiling

Accountability & Governance •Implement appropriate technical and organisational measures that ensure and demonstrate that you comply. This may include internal data protection policies such as staff training, internal audits of processing activities, and reviews of internal HR policies. •Maintain relevant documentation on processing activities. •Where appropriate, appoint a data protection officer.

Information Held Document what personal data we hold, where that data came from and who it is shared with. Conduct an information audit across the organisation to map data flows. Maintain internal records of processing activities. Document what personal data we hold, where it came from and who we share it with.

Data Protection By Design Implement appropriate technical and organisational measures to show considered and integrated data protection into all processing activities. · A description of the processing operations and the purposes including, where applicable, the legitimate interests pursued by the controller. · An assessment of the necessity and proportionality of the processing in relation to the purpose.

Lawful Basis / Consent Document what personal data is held, where that data came from and who it is shared with. Conduct an information audit across the organisation to map data flows. Review how Consent is sought, recorded and managed.  Consent means offering people genuine choice and control over how their data is used.

Subject Access Requests Review procedures and have plans in place on how to handle requests from individuals for access to their personal data within 30 days. In most cases you are not able to charge for complying with a request. You can refuse or charge for requests that are manifestly unfounded. Excessive requests can also be charged for or refused. Where you refuse to respond to a request, you must explain why to the individual, informing them of their right to complain to the supervisory authority. .

Data Breaches The GDPR introduces a duty on all organisations to report certain types of data breach to the ICO and in some cases to individuals. You have to notify the ICO of a breach where it is likely to result in a risk to the rights and freedoms of individuals. If unaddressed, such a breach is likely to have a significant detrimental effect on individuals – for example, it could result in discrimination, damage to reputation, financial loss, loss of confidentiality or any other significant economic or social disadvantage.

Transfer of Data Outside of Organisation You may transfer personal data where the organisation receiving the personal data has provided adequate safeguards. Individuals’ rights must be enforceable and effective legal remedies for individuals must be available following the transfer.