General Data Protection Regulations (GDPR) Training

Slides:



Advertisements
Similar presentations
The Data Protection (Jersey) Law 2005.
Advertisements

Data Protection.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
Data Protection for Church of Scotland Congregations
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
The Data Protection Act 1998 The Eight Principles.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION AND RUNNING A COMPLIANT PUB WATCH SCHEME Nigel Connor Head of Legal –JD Wetherspoon PLC.
The EU General Data Protection Regulation Frank Rankin.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
General Data Protection Regulation (EU 2016/679)
The Data Protection Act 1998
Education Update Data Protection
The Data Protection Act 1998
Making the Connection ISO Master Class An Overview.
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Issues of personal data protection in scientific research
Presentation to GTMC on GDPR
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
The Data Protection Act 1998
Data Protection Update – GDPR or bust
Data Protection Legislation
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
The General Data Protection Regulation (GDPR)
New Data Protection Legislation
GDPR and Health and Safety
G.D.P.R General Data Protection Regulations
From DPA to GDPR: the key elements

Data Protection and Running a Compliant Pub Watch SCHeme
General Data Protection Regulation
Data Protection principles
Data Protection and You
Identify the laws and guidelines that affect day-to-day use of IT.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
A whistle stop tour of GDPR
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR For The Voluntary Sector
GDPR Please don’t panic!
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations 2018
GDPR enforcement begins
The General Data Protection Regulation Six months on – What’s changed
The General Data Protection Regulation: Are You Ready?
#eaThinkData Get Ready for GDPR #eaThinkData.
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation (GDPR)
GDPR Session
General Data Protection Regulation Community Councils
Information Governance
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

General Data Protection Regulations (GDPR) Training Clergy Training 25th May 2018 Park Royal Hotel Warrington

Why All The Fuss? Data security and processing out of control, increased incidents of farming data (Facebook), lack of transparency (purchasing goods) and increasing number of serious incidents (Morrisons). Concern about protecting personal data is a global issue. Regulations are European and will survive Brexit. New Data Protection Commissioner taking a firm approach, fines have increased dramatically. Compensation payments to affected Individuals. Breaches may result in bad publicity and damage reputation as well as complaints.

Data Protection Principles GDPR requires that personal data be: Processed lawfully, fairly and in a transparent manner. Collected for specified legitimate purposes and not further processed in a manner which is incompatible with those purposes. Adequate, relevant and not excessive. Accurate and kept up to data. Not kept for longer than is necessary for the purposes of which it was obtained. Processed in a manner that ensures appropriate security e.g. not accidently lost, damaged etc.

Know the Terminology You will understand GDPR better if you know key terminology: Data is any information collected wholly or partly by automated mean. Personal Data is information about a living individual. Special Categories of Personal Data (formerly Sensitive Personal Data) is information about racial or ethnic origin, religious, political or philosophical beliefs. Processing is anything that you do with or how we use the data. Data Subject is the individual to whom the data relates Data Controller is a legal person who decides the purpose and manner in which the data is to be used or processed Data Processors are third parties who process (manage or use the data)

Individual Rights The GDPR is aimed at protecting the rights of living individuals and the regulations focus on how Personal Data is collected, stored and used. Individuals have the following rights: The right to be informed The right of access The right of rectification The right to erase The right to restrict processing The right to data portability The right to object Rights in relation to automated decision making and profiling

Compliance All organisations must be GDPR compliant from 25th May, there is no transition period. The most common question being asked at the moment is what must we do? How do we comply with the regulations? Compliance is easy do not overcomplicate GDPR. Don’t over analyse the regulations and use common sense.

Four Steps to Compliance Step 1 – Data Audit Step 2 – Consider why the Personal Data is being collected and processed Step 3 – Be Clear and Explain Step 4 – Secure Storage

Mistakes Happen Mistakes occur and when they do, there is no need to panic and contact the Curial Office. If Personal Data is wrongly disclosed to a third party then under new regulations the following steps must be taken: Contact third party and ask them to delete or destroy the Personal Data that was disclosed in error. Contact the individual whose Personal Data has been disclosed and tell them who the information was disclosed to and explain the corrective action that has been taken. Complete a Data Breach Form and send it to the Data Protection Officer at the Curial Office. If a serious Data Breach or Serious Data Incident occurs, then the Curial Office must be notified immediately. Under the regulations a serious Data Breach or incident must be reported to the Data Protection Commissioners, within 72 hours.

A couple of Final Points Subject Access Requests If an individual makes a request to see information that they believe is held about them, then we must comply and disclose the Personal Data, within 30 days. Children The GDPR recognises that children who are sufficiently mature may exercise their own data protection rights. In many cases, it is reasonable to assume that a child will have sufficient maturity from and including the age of 12.