The National Working Group

Slides:



Advertisements
Similar presentations
Auditing, Assurance and Governance in Local Government
Advertisements

NHS England & Customer Contact Centre FOI Introduction 2013.
Implementation of the FOI Law Mrs. Carole Excell FOI Coordinator Boards and Committees November 18, 2008.
The EU General Data Protection Regulation Frank Rankin.
Records management for the public sector 8 September 2016 Judith Jones - Group Manager Sue Markey - Senior Policy Officer Government and Society.
General Data Protection Regulation (EU 2016/679)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Preparing for the GDPR Helping us to help you.
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
EU Data Protection Reform: An ICO Perspective
The future of data protection: General Data Protection Regulation
Overview General Data Protection Regulation (GDPR)
Fair Go Rates System Dr Ron Ben-David Chairperson
WORLD OF CLOUD COMPUTING AFTER GDPR challenges, opportunities and the unknown Matjaž Drev, MA. National Supervisor for Personal Data Protection, Information.
General Data Protection Regulation (GDPR)
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
About the national data opt-out
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
Regulating new care models
GDPR Overview Gydeline – October 2017
INTRODUCTION TO GDPR 19/09/2018.
Data protection reform:
The session will commence at Please mute your microphone
Welcome to the Children’s Privacy GDPR Drop In
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
Introduction to GDPR 09/11/2018.
The session will commence at Please mute your microphone
The session will commence at Please mute your microphone
Data Security Protection Toolkit – Overview
The session will commence at Please mute your microphone
The session will commence at Please mute your microphone
Introducing the General Data Protection Regulation 2016
GDPR: getting your firm ready
Data protection reform – update from the ICO
Privacy: a work in progress
Appropriate Data Sharing in Health and Social Care
Information Governance
The GDPR and research data
The Public Sector Equality Duty
Data protection in the Education Sector - understanding the impact of GDPR Tuesday 23rd January 2018.
From DPA to GDPR: the key elements
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.
General Data Protection Regulation
PATIENT NOTICE Data Protection Legislation is Changing From the 25th May, the current UK Data Protection Act 1998 is being replaced by the EU General Data.
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
The session will commence at Please mute your microphone
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
Fair Go Rates System Dr Ron Ben-David Chairperson
How we’ll prepare for the General Data Protection Regulation (GDPR)
General Data Protection Regulations 2018
The General Data Protection Regulation Six months on – What’s changed
By The Data Protection Commissioner
GDPR & Accountability ISACA Ireland Annual Conference 2018
The Public Sector Equality Duty
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
The General Data Protection Regulations 2016
THE IMPACT OF DATA PROTECTION RULES ON CORPORATE INFO SECURITY AND INCIDENT RESPONSE MANAGEMENT – The Energy sector CEER Cybersecurity Workshop Massimo.
General Data Protection Regulation Community Councils
Data Security and Protection Toolkit Assurance 2018/19
About the national data opt-out
The National Data Guardian review & Government response
Information Governance
GDPR what do we need to do?
Presentation transcript:

Health, care and the new data protection regime David Evans Principal IG Advisor

The National Working Group Membership from 40+ organisations representing the wider health and social care system. Responsible for developing and drafting sector specific guidance regarding the new data protection regulation Robust approval and publication process to ensure relevant stakeholders are engaged. NHS England, Local Government Association, National Data Guardian, Information Commissioner’s Office etc i.e. Data Protector Officer, Lawful Processing etc. including guidance for independent contractors (i.e. GPs, Dentists etc.) and social care.

Data Protection Package General Data Protection Regulation (GDPR) Data Protection Bill EU Law Enforcement Directive Intel. services Non-EU matters Law enforcement

Where are we now? The GDPR comes into full effect on 25 May 2018. The DP Bill entered its third reading in the House of Lords on 17 January 2018. The likely conclusion will be late January 2018 at which point it will transfer then to the House of Commons. Fairly clear but not finalised!

IGA Publication Schedule Published:- CEO Briefing published FAQs Publishing February 2018*: What's new The data protection officer Transparency and subjects' rights Social care awareness guidance Data protection accountability and implementation priorities Pseudonymisation Lawful processing Publishing April 2018* Privacy by design and default Personal data breaches and notification Profiling and risk stratification GDPR overview GP Practice / primary care suite * Anticipated timeframe

Guidance from others NHS Digital - IG Toolkit Checklist Health Research Authority (HRA) - Implications for research including legal basis and safeguards for research

Further consideration A need for the health and social system to start considering other statutory responsibilities, i.e. Codes of Conduct Any codes cannot be significantly progressed until the ICO has published their overarching guidance. For example, confidentiality – currently new Code being drafted to replace the 2003 version. These will complement guidance under the data protection reform and support “the how” (i.e. organisation’s applicability) of legislation and responsibilities. This will develop over a period of time.

What should I be looking for? Should I be worried? Do you; meet your present obligations; follow good practice; know your assets; and communicate well? What should I be looking for? If so, you’re well on your way in meeting compliance with the new Data Protection reform. Remember, it’s about demonstrating that compliance. Review your own organisation; what are your assets and are these recorded sufficiently, how you can demonstrate your compliance and enhanced transparency for data subjects (including their increased rights). Also monitoring guidance from the ICO and those to be published to complement it; the IGA, NHS Digital etc. It is your responsibility to ensure compliance – don’t wait to act for system guidance – that published from the ICO is sufficient. (i.e. 12 steps to GDPR compliance).

Remember There are no experts in this field There are many shades of grey It’s about proportionality There will always be unresolved issues – it’s about how you respond and what you do.

Final thoughts “GDPR compliance will be an ongoing journey” and “ … if you can demonstrate that you have the appropriate systems and thinking in place you will find the ICO to be a proactive and pragmatic regulator aware of business needs and the real world.” Both quotes taken from Elizabeth Denham’s blog

Questions?