Revisited under the GDPR Hugh Jones - Sytorus

Slides:



Advertisements
Similar presentations
Specification Writing Presentation Training & Development.
Advertisements

Policy Development – Helpful Hints School Councils
Reporting to Parents’ Presentation for Primary Schools
Policy Overview Policy Management Practices: A How to Guide & Best Practices.
GCSE UNIT 1 EXAM June Timing Section A is 1hr 15mins 15mins reading time to be spread equally across the 4 questions Q1/2/3- 15mins each (inc reading)
APEC Privacy Framework “The lack of consumer trust and confidence in the privacy and security of online transactions and information networks is one element.
7 C’s of Effective Communication. The seven C’s 4 When We talk about “ Effective Communication” one thing that comes in mind, what are the basic principles.
General Data Protection Regulation (EU 2016/679)
Data Protection Regulation
GDPR 12 POINTS 679/2016 DATA LEX 2016.
UNHCR‘s Policy on the Protection of Personal Data of Persons of Concern - An introduction (October 2016)
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
EU Data Protection Reform: An ICO Perspective
INTERNAL AUDIT REPORTS
Preparing for a data protection audit 28 September 2017
9 tips for writing a school policy
Viewing the GDPR Through a De-Identification Lens
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
KEY CHANGES TO THE DATA PROTECTION LANDSCAPE
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
Cover Letter Writing.
GDPR support January GDPR support January 2018.
GDPR Overview Gydeline – October 2017
Data protection reform:
GDPR Security: How to do IT? IT reediness for competitive advantage
Public Sector Organisations - are you GDPR ready?
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
Data Protection Reform in Local Government
The General Data Protection Regulation (GDPR)
GDPR in schools and academies
Are you processing personal data lawfully?
EU Data Protection Legislation Managing The Security of Medical Data
Data protection reform – update from the ICO
State of the privacy union
G.D.P.R General Data Protection Regulations
From DPA to GDPR: the key elements
The GDPR & Schools - An Introduction -

General Data Protection Regulations
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
GDPR (General Data Protection Regulation)
Guide to overview of changes under GDPR ww.ZAKSIT.com
Data Mapping On the Journey to Accountability
Data Protection and Audit
The General Data Protection Regulation Six months on – What’s changed
Governing the risk of GDPR compliance
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
#eaThinkData Get Ready for GDPR #eaThinkData.
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
Neopay Practical Guides #2 PSD2 (Should I be worried?)
The General Data Protection Regulations 2016
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation (GDPR)
GDPR: Understanding your obligations and the ongoing challenges
GDPR Session
Office of Research Integrity and Protections
General Data Protection Regulation “11 months in”
ISSUE MANAGEMENT PROCESS MONTH DAY, YEAR
Data Privacy by Design Expanding Security for bepress Users
GCSE.
Is your medico-legal practice GDPR compliant?
THE TECHNICAL WRITING PROCESS
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

Revisited under the GDPR Hugh Jones - Sytorus Transparency Revisited under the GDPR Hugh Jones - Sytorus

Principle of Transparency Not just at the point of data acquisition Applies throughout the data life cycle Fundamental to the Principles of Fairness and Accountability Challenges the expectations being set with Data Subjects Controller must be able to demonstrate transparency of processing Information must be accessible and understandable

Entire Life Cycle before or at the start of the data processing cycle i.e. when the personal data is being collected either from the data subject or otherwise obtained; throughout the whole processing period i.e. when communicating with data subjects about their rights; and at specific points while processing is ongoing, for example: when data breaches occur, or when information is requested, or in the case of material changes to the processing.

Transparency Defined? Not specifically defined in the articles of the GDPR Recital 39, however, provides some clarification Information in relation to the data processing should be: easily accessible and easy to understand, that clear and plain language be used. Clarity in relation to the identity of the controller Explanation of the purposes of the processing Information to ensure fairness in respect of the natural persons concerned Clarity on the Subject’s right to obtain confirmation and communication of processing

Transparency inferred GDPR Articles in relation to Subject Rights indicate characteristics Information in relation to processing: must be concise, transparent, intelligible and easily accessible (Article 12.1); clear and plain language must be used (Article 12.1); particularly when providing information to children (Article 12.1); it must be in writing “or by other means, including ….by electronic means” (Article 12.1); where requested by the data subject it may be provided orally (Article 12.1) ; and it must be provided free of charge (Article 12.5).

Transparency Tips – what to do Avoid language qualifiers (“may”, “might”, “some”, “often”, “possible”) Short, structured sentences and paragraphs Active, rather than passive language Should not be technical or legalistic Any translations should be consistent with the original Vocabulary, tone and style should suit the intended audience Provided clearly in writing, or using standardised icons and images

Transparency Tips – What to avoid Imprecise, not easily understood by the intended audience “Words of two syllables or less” – avoid complex language Information is overly technical, avoid ‘information fatigue’ Not mixed in with contract T&C’s No Privacy Statement / Fair Processing Notice / FAQ’s Unclear scope and consequences of processing Failure to provide Article 13 and 14 explanations Explanation is hidden or difficult to navigate

Data Protection Consultancy and Assessments Tailored training courses Privacy Engine portal DPIA, PAL Capability Tracks Risks, SAR’s, Breach Reporting Repository for contracts, policies, training Full suite of DPO Reporting templates Contact us at info@Sytorus.com