General Data Protection Regulation (GDPR)

Slides:



Advertisements
Similar presentations
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
Advertisements

The EU General Data Protection Regulation Frank Rankin.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
General Data Protection Regulation (EU 2016/679)
Data Protection Regulation
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Tony Sheppard Mobile Guardian
General Data Protection Regulation (GDPR)
Accountability & Structured Privacy Management
Ireland’s transition towards the GDPR
Presentation to GTMC on GDPR
Information Destruction; 2017 and beyond!
GDPR Awareness and Training Workshop
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
Getting Ready for the GDPR
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
GDPR support January GDPR support January 2018.
Getting Ready for the GDPR
Getting Ready for the GDPR
GDPR Overview Gydeline – October 2017
Getting Ready for the GDPR
INTRODUCTION TO GDPR 19/09/2018.
Getting Ready for the GDPR
Data protection reform:
Getting Ready for the GDPR
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
Data Protection Reform in Local Government
GDPR - Practical Steps for Researchers
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
General Data Protection Regulation: Opportunity, Threat, Vulnerability
Data protection reform – update from the ICO
Appropriate Data Sharing in Health and Social Care
G.D.P.R General Data Protection Regulations
Presented by Trevor Butler
Getting Ready for the GDPR
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR - New Data Protection Regulation
How we’ll prepare for the General Data Protection Regulation (GDPR)
GDPR For The Voluntary Sector
General Data Protection Regulations 2018
The General Data Protection Regulation Six months on – What’s changed
By The Data Protection Commissioner
GDPR & Accountability ISACA Ireland Annual Conference 2018
Is Data Protection a Fundamental Right Protecting the Individual?
General Data Protection regulations – Pathway to Compliance
#eaThinkData Get Ready for GDPR #eaThinkData.
General Data Protection regulation (GDPR)
PRIVACY PRESENTATION TO THE SPRING 2013 CONFERENCE BY HANK MOORLAG
Product Manager, RM Integris
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Getting Ready for the GDPR
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The General Data Protection Regulations 2016
GDPR: Understanding your obligations and the ongoing challenges
GDPR Session
General Data Protection Regulation “11 months in”
GDPR Workshop – Partnerships for Jewish Schools
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

General Data Protection Regulation (GDPR) Kate Belinis CDA Herts East Herts Village Halls Conference 05 December 2017 Little Hadham Village Hall

What is it? New European Legislation (replacing existing European Directive 95/46/EC) It will apply from 25 May 2018! Overview: Same basic principles as current Data Protection Law Accountability New rights for individuals and strengthening of existing rights Breach reporting Data Protection Impact Assessments Higher penalties for non-compliance

Preparing for this: 12 steps Awareness: ensure decision makers and key people are aware. Need to appreciate the impact Information you hold: document what personal data you hold, where it came from and who you share it with. You will need an information audit Communicating privacy information: review your current privacy notices and put a plan in place for making any necessary changes in time for implementation Individual’s rights: check procedures to ensure rights are covered, including how you would delete personal data or provide data electronically and in a commonly used format Subject access requests: update your procedures and play how you will handle requests within the new timescales and provide any additional information Legal basis for processing personal data: look at the various types of data processing you carry out, identify your legal basis for doing this and record it.

Preparing for this 7. Consent: review how you are seeking, obtaining and recording consent and whether you need to make any changes. Children: start thinking now about putting systems in place to verify individuals’ ages and to gather parental/guardian consent Data breaches: ensure you have right procedures to detect, report and investigate a personal data breach Data Protection by Design & Impact Assessments: familiarise yourself now with guidance from ICO and work out how and when to implement them Data Protection Officer: designate someone to take responsibility and assess where this role will sit within structure and governance International: if you do then determine which is the protection supervisory authority

Where do I start? Governing body and management team Responsibility of designated Officer What personal information is held? Carry out Information Audit: Overview How is it collected? Where is it stored? Who has access? How is it shared?

Legal basis for processing ICO due to issue guidance: GDPR lawful Processing (Article 6, Section 1) Consent Contractual Obligation Legal Obligation Protect a person In the public interest Legitimate interests of the controller But currently it is either: Consent or Legitimate interests NOTE: when personal data is SHARED or Sensitive Personal Data is COLLECTED, the Individual must explicitly CONSENT to processing of Personal

Review of Consent processes Fair Processing Notices People must opt in Recording and managing consent Fair Processing Notice for children under 16 Individual’s Rights Right to Access Accountability principle – YOU need to show Maintaining relevant documentation Privacy Impact Assessments Breach notification

References Overview of GDPR: https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr Fair Processing Notices Guidance: https://ico.org.uk/for-organisations/guide-to-data-protection/privacy-notices-transparency-and-control/privacy-notices-under-the-eu-general-data-protection-regulation/ Consent Guidance (includes checklist): https://ico.org.uk/media/about-the-ico/consultations/2013551/draft-gdpr-consent-guidance-for-consultation-201703.pdf Conducting Privacy Impact Assessments Code of Practice: https://ico.org.uk/media/for-organisations/documents/1595/pia-code-of-practice.pdf

Resources Information Commissioners Office: Guidance and templates: https://ico.org.uk GDPR myth-busting blogs: https://iconewsblog.org.uk/tag/gdprmyths/ Thanks to Sefton CVS for this information and presentation 