Dr Elizabeth Lomas e.lomas@ucl.ac.uk The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas e.lomas@ucl.ac.uk.

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
The Data Protection (Jersey) Law 2005.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection for Church of Scotland Congregations
The Data Protection Act 1998 The Eight Principles.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Computing, Ethics & The Law. The Law Copyright, Designs and Patents Act (1988) Computer Misuse Act (1990) Data Protection Act (1998) (8 Main Principles)
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
The EU General Data Protection Regulation Frank Rankin.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
General Data Protection Regulation (EU 2016/679)
The Data Protection Act 1998
Making the Connection ISO Master Class An Overview.
Processing for archiving purposes in the GDPR
Luca De Matteis Justice counsellor (criminal law, data protection)
Data Protection and Confidentiality
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Level 2 Diploma in Customer Service
Issues of personal data protection in scientific research
Data Protection The Current Regime
General Data Protection Regulation
Data Protection Act.
GDPR Overview Gydeline – October 2017
The Data Protection Act 1998
Data Protection Update – GDPR or bust
General Data Protection Regulation: Turning the black into white
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
6 Principles of the GDPR and SQL Provision
GDPR 101 and ucsb’s response
The General Data Protection Regulation (GDPR)
New Data Protection Legislation
G.D.P.R General Data Protection Regulations
The GDPR and research data
FEK årskonferanse 28. februar 2018.

General Data Protection Regulation
Data Protection principles
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
Big Data & the General Data Protection Regulation
Information Handling Research Student Induction Day
The General Data Protection Regulation: Are You Ready?
PERSONAL INFORMATION BILL
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Public Privacy: juridical & ethical perspective
General Data Protection regulation (GDPR)
Privacy and Cyber Security for Payroll Pros: A Global Perspective
Hot Topic 1: GDPR and Traffic Data Systems
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
General Data Protection Regulation Q & A Session
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
Legislative Response to Data Inferences
Data Protection What can I do? GDPR Principles General Data Protection
GDPR Session
Presentation transcript:

Dr Elizabeth Lomas e.lomas@ucl.ac.uk The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas e.lomas@ucl.ac.uk

GDPR Key links GDPR link http://ec.europa.eu/justice/data- protection/reform/files/regulation_oj_en.pdf EU Overview http://www.eugdpr.org/eugdpr.org.html UK Data Bill https://www.gov.uk/government/collections/data- protection-bill-2017 Key for archival derogation DLA Piper Comparisons across regimes https://www.dlapiperdataprotection.com/

GDPR terminology ‘personal data’ and ‘natural person’ ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;   processed lawfully, fairly and in a transparent manner in relation to individuals; collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes; adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; accurate and, where necessary, kept up to date; kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures; processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

GDPR principles 1. processed lawfully, fairly and in a transparent manner in relation to individuals; 2. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes; 3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; 4. accurate and, where necessary, kept up to date;   processed lawfully, fairly and in a transparent manner in relation to individuals; collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes; adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; accurate and, where necessary, kept up to date; kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures; processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

GDPR principles 5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures; 6. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

Sensitive personal data racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; data concerning health or sex life and sexual orientation; genetic data and biometric data where processed to uniquely identify a person.

“Privacy by Design” DP documentation of processes Privacy Impact Assessments Design systems to minimize DP risks Fair processing notices Consent - meaningful Right to be forgotten No subject access charges Breach processes Fines

GDPR Responsibilities Data Controller(s) A Data Protection Officer with ‘expert knowledge’ (whistleblower) is required for: - public authorities - core activities require regular and systematic monitoring on a large scale - processing personal data on a large scale or sensitive data Hospital example

GDPR consent Public authorities Private entities – ‘legitimate interests’ Hospital example

GDPR – consent and children Children under the age of 13 can never, themselves, give consent to the processing of their personal data in relation to online services. For children between the ages of 13 and 15 (inclusive), the general rule is that if an organisation seeks consent to process their personal data, then parental consent must be obtained, unless the relevant individual Member State legislates to reduce the age threshold – although the threshold can never drop below 13 years of age. Children aged 16 or older may give consent for the processing of their personal data themselves. a Processing of data relating to children is noted to carry certain risks, and further restrictions may be imposed as a result of codes of conduct. • The GDPR does not prescribe the age at which a person is considered to be a child. • Where online services are provided to a child and consent is relied on as the basis for the lawful processing of his or her data, consent must be given or authorised by a person with parental responsibility for the child. This requirement applies to children under the age of 16 (unless the Member State has made provision for a lower age limit -which may be no lower than 13).   processed lawfully, fairly and in a transparent manner in relation to individuals; collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes; adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; accurate and, where necessary, kept up to date; kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures; processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.