Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.

Slides:



Advertisements
Similar presentations
The Data Protection (Jersey) Law 2005.
Advertisements

Getting data sharing right for every child
Data Protection.
Data Protection Overview
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
Data Protection for Church of Scotland Congregations
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
General Data Protection Regulation (EU 2016/679)
Key changes with the GDPR
The future of data protection: General Data Protection Regulation
Data Protection: The Law
Data Protection – The Essentials Alison Johnston Lead Policy Officer - Scotland Information Commissioner’s Office.
Issues of personal data protection in scientific research
General Data Protection Regulation (GDPR)
Presentation to GTMC on GDPR
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
Data protection reform:
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
General Data Protection Regulation (GDPR)
Public Sector Organisations - are you GDPR ready?
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulation
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
New Data Protection Legislation
Data protection reform – update from the ICO
General Data Protection Regulation
State of the privacy union
Privacy: a work in progress
Appropriate Data Sharing in Health and Social Care
G.D.P.R General Data Protection Regulations

GDPR Overview and Use Cases.
General Data Protection Regulation
Data Protection principles
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations (GDPR) Training
The General Data Protection Regulation Six months on – What’s changed
Information Handling Research Student Induction Day
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Data Protection in Law Enforcement Area Chapter 9a of the draft law
A Framework for Compliance
Understanding Data Protection
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
General Data Protection Regulation (GDPR)
GDPR Session
GDPR Workshop – Partnerships for Jewish Schools
Presentation transcript:

Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office

The Strands of Data Protection Law GDPR 25th May 2018 Data Protection Act 2018 23rd May 2018 Law Enforcement Directive 6th May 2018 E-Privacy TBC

Key Definitions Data Controller – the organisation that makes the decisions Data Processor – an organisation instructed to process personal data on behalf of a Data Controller Data Processing – anything which a Data Controller does with personal data, including storing it Data Breach – anything that happens to personal data which shouldn’t Data Subject – an individual identifiable from the personal data that you hold on them

The Accountability Principle The controller shall be responsible for, and be able to demonstrate compliance It is currently good practice to keep a record of your data processing as evidence of compliance. GDPR makes this a requirement.

What is Personal Data?

Personal Data is… Any information relating, directly or indirectly, to an identified or identifiable natural person

Not all data is the same… Race or ethnicity Political opinions Religious or philosophical beliefs Trade union membership Physical or mental health Sexual life or orientation Genetic or biometric The Data Protection Act has two types of personal data, normal personal data and sensitive personal data. Sensitive personal data is separated out from ordinary personal data as worthy of more consideration and security following conflicts in Europe. Under GDPR sensitive personal data is referred to as special categories of data. Genetic and biometric data is added as a new class of special category data. Data about criminal convictions and offences is dealt with separately but still regarded as sensitive and to be used in limited circumstances. There is one piece of information missing which most people assume would be classed as sensitive personal data and that is financial data. Although Financial data is not classed as sensitive personal data by the DPA or the GDPR the ICO treats a breach of this data as if it were sensitive data because of the impact a breach can have on an individual.

Personal Data isn’t Always Obvious! We need to be aware of what other information is out there that people can piece together to identify an individual. GDPR makes reference to this by stating that personal data is data which allows someone to be identified either directly or indirectly. If you are using anonymisation or pseudonyms to protect an individual’s identity think carefully about how they are created. If they use initials or dates of birth then it’s possible people could identify an individual from them. For example, your driving licence number is made up of your name and date of birth. Likewise pseudonyms or locations may make an individual identifiable. It is about common sense and you have to consider what is reasonably likely in regards to the risk of individuals being identified. Someone would have to want to identify a person and actively search out the additional information. The likelihood of this happening will depend on who you work with, with some people more likely to be at risk than others. Some examples of data which can be used to identify individuals include locations, medication, the car you drive, work you’ve undertaken, in particular research work, even the name of your pet. Personal Data isn’t Always Obvious!

Recorded data Electronic Manual Processed by automated equipment Notes which will be automated Filing systems Official records Public authorities The GDPR applies to the processing (which is anything you can thing of doing) of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system. The new UK Data Protection Act will apply similar rules to health, education and social work records, as well as any other personal data held in manual form by a public authority. MF

Who is responsible? Data controllers Data processors A data controller is “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data”. Data processors are engaged by data controllers to process personal data but only on the controller’s instructions. They shouldn’t be making decisions.

I must get consent to process personal data under GDPR TRUE FALSE FALSE Consent is just one of the lawful basis for processing personal data

Conditions for processing Personal data Special category data Consent Contract with the individual Comply with a legal obligation Protecting vital interests Public function in the public interest Exercise of official authority Legitimate interests of the data controller, but not prejudicial to the person Explicit consent Employment, social security, social protection law Vital interests Not for profit religious, political or trade union bodies Put in public domain by the person Legal proceedings/advice Substantial public interest based on law Health, medical, social care Public health Archiving, research, statistical Additional conditions are in the new UK Data Protection Act 2018 In order to use personal data lawfully, you need to be able to rely on at least one condition for processing from the personal data column. If it is sensitive personal data, you need to be able to rely on at least one condition for processing from each column. Other than consent, the conditions require that the processing is necessary. Consent has its own particular requirements. All conditions have equal weighting: one does not carry any more status than any other. It is for the data controller to be satisfied that they are relying on the appropriate condition for each activity and document that in the record of processing activities. This is especially important when not relying on consent. Lawful Basis Tool

Accuracy/ Rectification Erasure Restrict Processing Object To be Informed Access Accuracy/ Rectification Erasure Restrict Processing Object Data Portability Fundamentally, the DPA is about establishing rights for individuals and placing obligations on organisations using personal data. Individuals get all the rights: organisations have all the responsibility!!

Data Sharing

Data Processing

Data Breaches Data Breach Guidance Report to the ICO if it is likely to result in a risk to the rights and freedoms of individuals Without undue delay; No later than 72 hours. Will need to provide specific details including: nature of data involved; contact point details; measures taken as a result of the breach May need to notify individuals affected This is a new requirement and organisations must get good processes in place to ensure they are able to comply with the very short timescales. Remember, the ICO can fine an organisation for the breach but also for not reporting the breach – a double whammy!! Some examples of action we have taken recently include… Data Breach Guidance

Useful Links Guide to the GDPR ICO Resources and Support Self Assessment Toolkit ICO Guidance

Keep in touch ICO Scotland 45 Melville Street Edinburgh EH3 7HL T: 0330 123 1115 E: Scotland@ico.org.uk Subscribe to our e-newsletter at www.ico.org.uk or find us on… @iconews