General Data Protection Regulation “11 months in”

Slides:



Advertisements
Similar presentations
1 Role of the Data Protection Officer Donald Henderson Information Compliance Manager 30 September 2010.
Advertisements

Presentation Title Data Protection The new EU Regulation Insert your logo here.
The EU General Data Protection Regulation Frank Rankin.
Key Points for a Privacy Programme for Multinationals Steve Coope.
General Data Protection Regulation (EU 2016/679)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Tony Sheppard Mobile Guardian
Data Protection Officer’s Overview of the GDPR
Key changes with the GDPR
Accountability & Structured Privacy Management
The future of data protection: General Data Protection Regulation
Unpacking the European Commission General Data Protection Regulation
Overview of Structure General Data Protection Regulation (GDPR)
Preparing for a data protection audit 28 September 2017
Presentation to GTMC on GDPR
Operationele blik op GDPR
GDPR – What’s it all about???
General Data Protection Regulations: what you really need to know
General Data Protection Regulation (GDPR
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Any impact on procurement? 16/11/2017.
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
GDPR Overview Gydeline – October 2017
Data protection reform:
GDPR Road map to Compliance.
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
GDPR - New Data Protection Regulation
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
Introducing the General Data Protection Regulation 2016
GDPR and Health and Safety
Headline notes UK data protection law will change on 25 May 2018, when the EU General Data Protection Regulation (“GDPR”) takes effect, replacing the.
Data protection reform – update from the ICO
State of the privacy union
G.D.P.R General Data Protection Regulations
GENERAL DATA PROTECTION REGULATIONS (GDPR)
The GDPR & Schools - An Introduction -

GDPR Overview and Use Cases.
General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
GDPR (General Data Protection Regulation)
Data Mapping On the Journey to Accountability
Project Start-up This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No
Data Protection and Audit
GDPR Workshop MEU Symposium Prague 2018
Welcome!.
Data transfers to non-EU countries under the new GDPR
GDPR enforcement begins
The General Data Protection Regulation Six months on – What’s changed
By The Data Protection Commissioner
GDPR & Accountability ISACA Ireland Annual Conference 2018
General Data Protection regulations – Pathway to Compliance
Project Start-up This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No
Data Protection: The new EU Regulation
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
GDPR: Understanding your obligations and the ongoing challenges
Data Privacy by Design Expanding Security for bepress Users
THE IMPACT OF DATA PROTECTION RULES ON CORPORATE INFO SECURITY AND INCIDENT RESPONSE MANAGEMENT – The Energy sector CEER Cybersecurity Workshop Massimo.
Getting Ready For GDPR Simon Marks Director
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

General Data Protection Regulation “11 months in” Donna Creaven Head of Supervision – Multinationals & Technology

Our report in numbers

Some statistics….

Recap: Focus of the GDPR Accountability – demonstrating compliance Transparency – providing information pre-processing Risk-based mandatory data breach reporting (72 hours) Strengthened ‘Consent’ obligations Data protection by design and default New and enhanced Data Subject rights Administrative Fines Data Protection Officer (DPO) for certain organisations

Administrative Fines Article 83 Up to €20m or 4% of global turnover

Governance Transparency Accountability

Demonstrating Accountability Maintaining up-to-date inventories of processing (Article 30) Completing data protection impact assessments (Article 35) Ensuring the security of processing (Article 32) Adhering to the principles of data protection by design and by default (Article 25) Appointing and empowering a Data Protection Officer (Article 37 and 38) Strong foundation of governance - Practical approach Transparency Record Keeping Codes of Conduct Certification Impact Assessment Governance and Data Protection By Design & Default Contract, transfers, agreements, BCRs User rights Data Protection Officer Article 25 – Pbd&d Start to finish – business case to end-of-life Design and NFR factor from the start Whole organisation to engage – not just dev, QA, Ops Governance, policy, practice Throughout lifecycle – “time of determination”, “time of processing” Data Minimisation Pseudonymisation Effective risk management Default settings observing principles must be used Article 32 Art 32(1)(d) - testing Software engineering – standards? Essential for accountability, quality, security, protection Document, record, change control Unit, integration, UAT, feature, static and dynamic analysis, coverage reporting, automated build, continuous integration? Fixture data? Staging – consent? Secure servers, network? Patching? War games, network intrusion detection, leaks, error tolerance Incident Response plan, training Risk management, “function creep” Design and test not just for security - but for access-control, subject access, portability, deletion, purpose limitation

Accountability – the controller & processor relationship Monitoring this relationship is an ongoing task, for example: Undertaking external and internal audits Inspections Follow-up actions Spot checks Regular reviews

Transparency requirements Identity of controller and DPO Purpose of processing and legal basis Recipients of the data Data transfer arrangements Retention period Right of access Right to withdraw consent Right to lodge complaint with SA Details of the contractual or statutory basis Details of automated decision-making At the time when personal data is obtained provide the data subject with information on the:

Consent - Article 4.11 Unambiguous Freely given Informed by a clear affirmative action

Breach Notification to the Supervisory Authority Notification to SA within 72 hours Unless “unlikely to result in a risk to the rights and freedoms of natural persons” ‘Risk’ e.g. a risk of identity theft or anything likely to lead to a financial loss for the data subject

Breach Communication to Data Subject “when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons” “the data controller shall communicate the personal data breach to the data subject without undue delay” ‘High Risk’ – higher threshold than report to Supervisory Authority

Key deliverables Identify and document legal basis for processing Review and remediate storage and retention practices Article 30 Records of data processing Privacy Notices Review and refresh of databases, mailing lists   Review of organisational data security practices Identify and review third party processors Embed Privacy by Design and Privacy by Default practices & procedures Re-assess breach notification procedures

Some 2019 priorities Progressing Inquiries – first decisions Summer 2019 Supervising and engaging with big-tech (multi-faceted) Children’s Consultation DPC five year Regulatory Strategy DPC DPO Network Issuing Guidance

Thank You www.dataprotection.ie