Data Privacy and GDPR Jane Shvets jshvets@debevoise.com.

Slides:



Advertisements
Similar presentations
The Gathering Cloud computing - Legal considerations David Goodbrand, Partner 28 February 2013 Aberdeen Edinburgh Glasgow.
Advertisements

Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
APEC Privacy Framework “The lack of consumer trust and confidence in the privacy and security of online transactions and information networks is one element.
The EU General Data Protection Regulation Frank Rankin.
Data protection—training materials [Name and details of speaker]
Key Points for a Privacy Programme for Multinationals Steve Coope.
Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
General Data Protection Regulation (EU 2016/679)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
Industry 4.0 – New ways of cooperative working – are we prepared?
The future of data protection: General Data Protection Regulation
GDPR (General Data Protection Regulation)
Speaker: Jane Burns (Anthony Collins Solicitors LLP)
Operationele blik op GDPR
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
International Regulatory Trends
Museums + Heritage webinar, 30 November 2017
GDPR Readiness Project
GDPR Overview Gydeline – October 2017
Conducting Compliant Marketing & SARs Workshop - CMG Events
Information Governance and Data Privacy: A World of Risk
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
The European Union General Data Protection Regulation (GDPR)
INTRODUCTION TO GDPR 19/09/2018.
GDPR Road map to Compliance.
General Data Protection Regulation (GDPR)
DP BILL: DIFFERENCES AND DEROGATIONS
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulations
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Are you processing personal data lawfully?
GDPR and Health and Safety
Preparing for the EU General Data Protection Regulation
Headline notes UK data protection law will change on 25 May 2018, when the EU General Data Protection Regulation (“GDPR”) takes effect, replacing the.
State of the privacy union
Privacy: a work in progress
Information Governance
G.D.P.R General Data Protection Regulations
The GDPR and research data
GDPR Overview and Use Cases.
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
GDPR How does it apply to me?.
IMPLICATIONS OF GDPR ROBERT BELL.
Welcome!.
Data transfers to non-EU countries under the new GDPR
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
The General Data Protection Regulation Six months on – What’s changed
Presentation privacy law
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Session 4: Data Mapping and Data Subject Rights
General Data Protection Regulation (GDPR)
Session 4: Data Mapping and Data Subject Rights
GDPR: Understanding your obligations and the ongoing challenges
Is your medico-legal practice GDPR compliant?
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Data Privacy and GDPR Jane Shvets jshvets@debevoise.com

GDPR Highlights Came into force on 25 May 2018 Strict obligations on businesses “processing” individuals’ “personal data” Personal data: any information relating to an identifiable natural person that directly or indirectly identifies them Processing: any activity involving personal data Can apply throughout the EEA and extraterritorially Processing anywhere in the world when “in the context of” an EEA establishment Offering goods or services to individuals in the EEA Monitoring individuals in the EEA Creates risk of large fines, individual complaints, litigation, reputational harm

GDPR Highlights (cont.) Obligations tied to seven core principles: Lawfulness, fairness and transparency Purpose limitation Data minimisation Accuracy Storage limitation Integrity and confidentiality Accountability Prohibits transfers to “Third Countries” subject to exceptions: EU Commission adequacy decision (e.g., Japan, Privacy Shield) Adequate safeguards (e.g., Standard Contractual Clauses) Derogations for specific situations (e.g., necessity for the “establishment, exercise or defense of legal claims”)

Impact on Compliance / Investigations Due diligence / KYC Criminal conviction data: differing local laws cause difficulties Document review and witness interviews Lawful basis: “legitimate interests” but need to be carefully assessed and recorded Transparency: need for privacy notice explaining how data used Minimisation: restrict review to data strictly necessary for aims Cross-border transfers To vendors: think about SCCs and need for GDPR compliant terms of service To authorities: consent or establishment, exercise or defense of legal claims Minimisation: limit to data truly necessary (redact if needed)

UK ICO Enforcement Broad range of enforcement powers Information notices to obtain information from controllers Assessment notices to gain access to documents, systems and people Enforcement notices requiring specific actions Monetary penalties up to greater of £ 17 million or 4% of turnover Many enforcement actions still coming through under pre-GDPR law so fines constrained to £ 500,000 cap (e.g., for Facebook, now being appealed including allegations of bias) Recent enforcement under GDPR (e.g., against HMRC for lack of consent to Voice ID service)