State of the privacy union

Slides:



Advertisements
Similar presentations
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Advertisements

Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
The EU General Data Protection Regulation Frank Rankin.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Brussels Privacy Symposium on Identifiability
Data Protection Officer’s Overview of the GDPR
Key changes with the GDPR
Accountability & Structured Privacy Management
The future of data protection: General Data Protection Regulation
Brussels Privacy Symposium on Identifiability
Data Protection – The Essentials Alison Johnston Lead Policy Officer - Scotland Information Commissioner’s Office.
Understanding EU GDPR from an Office 365 perspective
Issues of personal data protection in scientific research
The General Data Protection Regulation act (GDPR)
Presentation to GTMC on GDPR
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation (GDPR
General Data Protection Regulation
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
Data Protection Update – GDPR or bust
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
Data protection reform:
General Data Protection Regulation (GDPR)
Public Sector Organisations - are you GDPR ready?
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection Reform in Local Government
Cyberforum 2018 March 8, 2018 Los Angeles GDPR & SECURITY
Introduction to GDPR 09/11/2018.
The Rise of Privacy: Complying with GDPR in the United States
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Security measures Introducing Risk Assessment in GDPR
Headline notes UK data protection law will change on 25 May 2018, when the EU General Data Protection Regulation (“GDPR”) takes effect, replacing the.
Data protection reform – update from the ICO
G.D.P.R General Data Protection Regulations
The GDPR and research data
GENERAL DATA PROTECTION REGULATIONS (GDPR)
From DPA to GDPR: the key elements
GDPR Overview and Use Cases.
General Data Protection Regulation
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
GDPR How does it apply to me?.
IMPLICATIONS OF GDPR ROBERT BELL.
Data Protection and Audit
GDPR Workshop MEU Symposium Prague 2018
Data Protection in a Tutorial Context
Welcome!.
Detecting, reporting & investigating data breaches under GDPR
The General Data Protection Regulation Six months on – What’s changed
Governing the risk of GDPR compliance
Is Data Protection a Fundamental Right Protecting the Individual?
Information Handling Research Student Induction Day
The General Data Protection Regulation: Are You Ready?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
General Data Protection regulation (GDPR)
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Fines, Sanctions and Compensation The teeth in the GDPR & Data Protection Act 2018 by Simon McGarr, CIPP/E Data Compliance Europe.
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation (GDPR)
General Data Protection Regulation “11 months in”
Information Governance
Presentation transcript:

State of the privacy union GDPR State of the privacy union

DOOM’s day

Ready?

Problem?

Problem?

Media Attention

Organisations vs. Data subjects We are not ready! Just a bit longer and we will be. I will exercise my rights, ready or not!

Problem?

Problem?

What’s missing still? Guidelines on certification Clarity on exception for journalists (press freedom) Sectorial codes of conduct Transformation of the rules into criminal law Transformation of the privacy commission into DPA Framework law

Framework law

GDPR In a nutshell

GDPR principles Personal Data Principles Lawfulness, fairness & transparency Purpose Limitation Data Minimisation Accuracy Storage Limitation Respect Data Subject Rights Secured Additional guarantees with data transfers out of EU

Key concepts and definitions Personal Data Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Personal data can be divided into 2 categories: Standard personal data First name, last name, street names, telephone numbers, ip-adresses,… Sensitive personal data Certain data must have extra protection because they can harm the personality or physical integrity of an individual.

Key concepts and definitions Controller The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Processor A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Processing Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Accountability & Transparency Accountable The controller shall be responsible for, and be able to demonstrate compliance with the GDPR legislation Transparency The controller shall take appropriate measures to provide any information and communication relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language. Adherence to approved codes of conduct or approved certification mechanisms may be used as an element by which to demonstrate compliance Key documents: Register of Processing activities (a.k.a. dataregister) Data Protection Impact Assessments (DPIA) Privacy Policy & Privacy Notice

Data breach notification Art 33 §1 In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons (…) Art 33 §5 The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. (…) Take mitigating measures Information to data subject in some circumstances

Rights of the Data Subject Right to transparantie (verstrengd) Right to access Right to rectification Right to erasure a.k.a. ‘Right to be forgotten’ (new) Right to restriction of processing (new) Right to portability (new)

GDPR So what to do?

Help!

Most urgent?