Presentation privacy law

Slides:



Advertisements
Similar presentations
The Data Protection (Jersey) Law 2005.
Advertisements

The Data Protection Act 1998 The Eight Principles.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
The EU General Data Protection Regulation Frank Rankin.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
General Data Protection Regulation (EU 2016/679)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
GDPR (General Data Protection Regulation)
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Issues of personal data protection in scientific research
General Data Protection Regulation (GDPR)
Viewing the GDPR Through a De-Identification Lens
The General Data Protection Regulation act (GDPR)
Presentation to GTMC on GDPR
Operationele blik op GDPR
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
Data Protection The Current Regime
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
International Regulatory Trends
Museums + Heritage webinar, 30 November 2017
GDPR Readiness Project
GDPR Overview Gydeline – October 2017
Data Protection Update – GDPR or bust
GDPR Overview Gydeline – October 2017
The European Union General Data Protection Regulation (GDPR)
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
GDPR 101 and ucsb’s response
General Data Protection Regulation
The General Data Protection Regulation (GDPR)
State of the privacy union
G.D.P.R General Data Protection Regulations
The GDPR and research data
From DPA to GDPR: the key elements
GDPR Overview and Use Cases.
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR How does it apply to me?.
Guide to overview of changes under GDPR ww.ZAKSIT.com
GDPR For The Voluntary Sector
GDPR (Patrix interpretation)
GDPR (679/2016) and Monitoring
GDPR Workshop MEU Symposium Prague 2018
Welcome!.
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
The General Data Protection Regulation Six months on – What’s changed
The General Data Protection Regulation: Are You Ready?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
General Data Protection regulation (GDPR)
Data Protection in Law Enforcement Area Chapter 9a of the draft law
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
Session 4: Data Mapping and Data Subject Rights
The General Data Protection Regulations 2016
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation (GDPR)
Session 4: Data Mapping and Data Subject Rights
Data Privacy by Design Expanding Security for bepress Users
Data Privacy and GDPR Jane Shvets
The EU General Data Protection Regulation
Getting Ready For GDPR Simon Marks Director
EU Data Privacy: What US Orgs Need to Do Now to Prepare for the GDPR
Presentation transcript:

Presentation privacy law Regulation (EU) 2016/679 Jop Fellinger

Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) Will come into effect on May 25, 2018 and replaces all national legislation in the EU. This, together with a system to appoint a single supervisor for multinationals, is a great step forward. Threats: huge implementation and mindset change, even larger fines Opportunities: ongoing and great reason to engage with your customers.

Purpose of this presentation What do we want to achieve with this brief presentation? We will have a global understanding of what personal data are; We will be able to understand the principles behind GDPR; We will be able to see why GDPR has an impact outside the EU.

Definitions Personal Data means any information relating to an identified or identifiable natural person “data subject.” This can be directly or indirectly by reference to an identifier specific to that natural person. Processing means any operation or set of operations which is performed in personal data. Controller means the natural or legal person which alone or jointly determines the purposes and means of the processing. Processor means a natural or legal person which processes personal data on behalf of the controller.

Obligations under GDPR Process personal data taking into account due diligence, transparency and accountability towards the data subjects. Not only via an easy to read privacy statement, but also with a clear reference to lawfulness such as consent, performance under a contract or necessary for the purposes of the legitimate interest pursued by the controller. Maintain a record of processing activities under your responsibility. Be clear about the purpose of the processing. Data minimization: Only process the data necessary for the purpose. Make sure the personal data are not processed longer than necessary.

Accurate. The processed data have to be correct or else be corrected. Integrity and security. Take appropriate technical and organizational measures against unauthorized or unlawful processing use.

New rights of data subjects The right to erasure; The right to rectification; The right of access The right to restriction of processing; The right to data portability; The right to object to direct marketing and automated decison making;

Controllers and Processors will have to be able to respond within 4 weeks to a request based on these rights.

Impact of GDPR outside the EU GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the EU, regardless of whether the processing takes place in the EU or not. GDPR applies to the processing of personal data of data subjects in the EU by a controller or processor not established in the EU, where the processing activities are related to the offering of goods or services irrespective of whether a payment from the data subject is required, to such data subjects in the EU or monitoring of their behavior as far as the behavior takes place in the EU.

Transfer of personal data to third countries: Privacy Shield: www.privacyshield.gov EU Model Clauses as means of processor agreement with controller: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en

Disclaimer: Although utmost care has been taken to provide correct information, this presentation cannot replace legal advice. Neither Fruytier Lawyers in Business B.V. nor Mr. J.H. Fellinger can be held liable in anyway or form on the basis of this presentation or the discussion that has taken place in the presentation.

Thank you for your attention! Jop Fellinger Tel: +31(0)6 513 272 11 E-mail: jfellinger@flib.nl