Data Protection Impact Assessments Drop-in advice session

Slides:



Advertisements
Similar presentations
Confidentiality, Consent and Data Protection Elizabeth M Robertson Deputy Medical Director Grampian University Hospitals Trust.
Advertisements

Use of Children as Research Subjects What information should be provided for an FP7 ethical review?
Internal Auditing and Outsourcing
Privacy Impact Assessments Iain Bourne, Group Manager, Policy Delivery Information Commissioner’s Office, UK Workshop on data protection and the internet:
Data Protection: Workplace, Health and Safety. Employers’ responsibilities Employer obliged to provide safe place of work. Health and Safety Act 2004.
Legal framework Look at the legal compliance and framework a business is subject to.
CMG Events 2016 Cybersecurity Briefing 24 February 2016 John Magee William Fry.
Business Challenges in the evolution of HOME AUTOMATION (IoT)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Preparing for the GDPR Helping us to help you.
Data Protection Officer’s Overview of the GDPR
Key changes with the GDPR
3-MINUTE READ WORKING TOGETHER TO SAFEGUARD CHILDREN.
Overview General Data Protection Regulation (GDPR)
GDPR Module 3: Accountability and Governance
Running a Privacy Impact Assessment (PIA)
Issues of personal data protection in scientific research
General Data Protection Regulation (GDPR)
Privacy Impact Assessments (PIAs)
3-MINUTE READ WORKING TOGETHER TO SAFEGUARD CHILDREN.
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
GDPR Awareness and Training Workshop
General Data Protection Regulation
GDPR Overview Gydeline – October 2017
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
Nina Barakzai November 2017
Welcome to the Children’s Privacy GDPR Drop In
Public Sector Organisations - are you GDPR ready?
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection Reform in Local Government
Cyberforum 2018 March 8, 2018 Los Angeles GDPR & SECURITY
GDPR - New Data Protection Regulation
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
Reporting personal data breaches to the ICO
The General Data Protection Regulation (GDPR)
Security measures Introducing Risk Assessment in GDPR
Headline notes UK data protection law will change on 25 May 2018, when the EU General Data Protection Regulation (“GDPR”) takes effect, replacing the.
Data protection reform – update from the ICO
State of the privacy union
Appropriate Data Sharing in Health and Social Care
Information Governance
G.D.P.R General Data Protection Regulations
The GDPR & Schools - An Introduction -

General Data Protection Regulation
Bid exclusion risks in Public Procurement Procedures With focus on Competition and new Data Protection rules related breaches 11 APRIL 2017.
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Relocation CARNIVAL come one…come all
Data Protection Impact Assessments How do we carry out a DPIA?
IMPLICATIONS OF GDPR ROBERT BELL.
Welcome!.
Management of a Data Breach under the GDPR
Detecting, reporting & investigating data breaches under GDPR
Governing the risk of GDPR compliance
New Data Innovation Projects: Data Privacy and Data Protection
Data Protection Impact Assessments
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Fines, Sanctions and Compensation The teeth in the GDPR & Data Protection Act 2018 by Simon McGarr, CIPP/E Data Compliance Europe.
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
Data Protection What you need to know
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Session 4: Data Mapping and Data Subject Rights
Legislative Response to Data Inferences
Session 4: Data Mapping and Data Subject Rights
EU Data Privacy: What US Orgs Need to Do Now to Prepare for the GDPR
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

Data Protection Impact Assessments Drop-in advice session Charter 4 Data Protection Practitioners’ Conference 2018 #DPPC2018

Tell us what you think Go to slido.com/#DPPC2018/DPIA #DPPC2018 Data Protection Practitioners’ Conference 2018 #DPPC2018

Data Protection Impact Assessments What are they & when are they required? Data Protection Practitioners’ Conference 2018 #DPPC2018

DPIA Awareness checklist DPIA Screening checklist Guide to the GDPR DPIA Awareness checklist DPIA Screening checklist DPIA Process checklist Data Protection Practitioners’ Conference 2018 #DPPC2018

DPIA consultation- closes Friday Tell us your thoughts @ ico.org.uk Data Protection Practitioners’ Conference 2018 #DPPC2018

#DPPC2018 A process for building and demonstrating compliance Can be used for; a single processing operation, a group of similar operations and evaluating the impact of a technology product. Data Protection Practitioners’ Conference 2018 #DPPC2018

#DPPC2018 Assess the impact of envisaged processing Describe processing Necessity/proportionality Assess level of risk Identify measures to address risk Data Protection Practitioners’ Conference 2018 #DPPC2018

#DPPC2018 Data Protection Practitioners’ Conference 2018 1: Identify need for a DPIA 2: Describe the processing 3: Consider consultation 4: Assess necessity and proportionality 5: Identify and assess risks 6: Identify measures to mitigate risk 7: Sign off and record outcomes 8: Integrate outcomes into plan 9: Keep under review Data Protection Practitioners’ Conference 2018 #DPPC2018

Article 35 Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Data Protection Practitioners’ Conference 2018 #DPPC2018

Article 35 Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Data Protection Practitioners’ Conference 2018 #DPPC2018

Article 35 Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Data Protection Practitioners’ Conference 2018 #DPPC2018

Part 3 – Law enforcement purposes Clause 64(1) – DP Bill Part 3 – Law enforcement purposes Where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, the controller must, prior to the processing, carry out a data protection impact assessment. Data Protection Practitioners’ Conference 2018 #DPPC2018

Recital 77 “The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data…”. Data Protection Practitioners’ Conference 2018 #DPPC2018

Article 35(4) Article 35(3) New Technologies Profiling/SPD access to services Profile individuals (large scale) Biometric data Genetic data Match/combine datasets Invisible processing Track location/behaviour Profile children/vulnerable Data which may endanger subjects in case of a breach Article 35(3) Systematic, extensive evaluation (ADM/profiling Large scale Art 9/10 processing Large scale monitoring, publically accessible area

ICO proposed list #DPPC2018 New technologies Denial of service Large-scale profiling Biometric data Genetic data Risk of physical harm Data matching Invisible processing Tracking Targeting of children/vulnerable individuals Data Protection Practitioners’ Conference 2018 #DPPC2018

1, New Technologies #DPPC2018 Processing involving the use of new technologies, or the novel application of existing technologies (including AI). Data Protection Practitioners’ Conference 2018 #DPPC2018

2, Denial of service #DPPC2018 Decisions about an individual’s access to a product, service, opportunity or benefit which is based to any extent on automated decision-making (including profiling) or involves the processing of special category data. Data Protection Practitioners’ Conference 2018 #DPPC2018

3, Large-scale profiling Any profiling of individuals on a large scale. Data Protection Practitioners’ Conference 2018 #DPPC2018

What does large scale mean? You should consider: Number of individuals Geographical extent Volume of data Variety of data Duration of the processing Data Protection Practitioners’ Conference 2018 #DPPC2018

#DPPC2018 Tracking individuals using a city’s public transport system Data Protection Practitioners’ Conference 2018 #DPPC2018

A hospital processing patient data (not an individual clinician) Data Protection Practitioners’ Conference 2018 #DPPC2018

Want to ask us a question? Go to slido.com/#DPPC2018/DPIA Data Protection Practitioners’ Conference 2018 #DPPC2018

4, Biometrics #DPPC2018 Any processing of biometric data. Data Protection Practitioners’ Conference 2018 #DPPC2018

5, Genetic data Any processing of genetic data other than that processed by an individual GP or health professional, for the provision of health care direct to the data subject. Data Protection Practitioners’ Conference 2018 #DPPC2018

6, Data matching Combining, comparing or matching personal data obtained from multiple sources. Data Protection Practitioners’ Conference 2018 #DPPC2018

7, Invisible processing #DPPC2018 Processing of personal data that has not been obtained direct from the data subject in circumstances where the controller considers that compliance with Article 14 would prove impossible or involve disproportionate effort. Data Protection Practitioners’ Conference 2018 #DPPC2018

8, Tracking Processing which involves tracking an individual’s geolocation or behaviour, including but not limited to the online environment. Data Protection Practitioners’ Conference 2018 #DPPC2018

9, Targeting of children or other vulnerable individuals The use of the personal data of children or other vulnerable individuals for marketing purposes, profiling or other automated decision-making, or if you intend to offer online services directly to children. Data Protection Practitioners’ Conference 2018 #DPPC2018

10, Risk of physical harm #DPPC2018 Where the processing is of such a nature that a personal data breach could jeopardise the [physical] health or safety of individuals. Data Protection Practitioners’ Conference 2018 #DPPC2018

Data Protection Practitioners’ Conference 2018 #DPPC2018

DPIA consultation- closes Friday Tell us your thoughts @ ico.org.uk Data Protection Practitioners’ Conference 2018 #DPPC2018

Guide to the GDPR DPIA Awareness checklist DPIA Screening checklist DPIA Process checklist Data Protection Practitioners’ Conference 2018 #DPPC2018