DPA – Complying in the digital transition Dawn Monaghan, Group Manager, Strategic Liaison ICO UK.

Slides:



Advertisements
Similar presentations
Local Government Pension Scheme November 2013 Auto-enrolment & the Local Government Pension Scheme Presented by Andy Cunningham.
Advertisements

Corporate Records Management (Practitioner) Information Governance Policy Team NHS Connecting for Health.
Corporate Records Management (Practitioner) Information Governance Policy Team NHS Connecting for Health.
In confidence Chair: Storm Westmaas Principal Legal Adviser, the Standards Board for England Speakers: Bernadette Livesey Chief Law and Administration.
International Telecommunication Union HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, TRAINING /DATA PROTECTION LAW.
ICO view of care.data Dawn Monaghan, Group Manager, Strategic Liaison ICO UK.
Big Data and data protection
Data Protection and the GRA. 1. Commentary on Data Protection 2. The GRA’s Role The Register Investigations, Mediation and Compensation Enforcement Notices.
© 2012 Morgan Cole LLPExpertise | Experience | Efficiency | Contribution 11th October 2012 Avoiding Data Protection pitfalls when collecting Equality Information.
Data Protection and Records Management
Delivering privacy and data protection messages in the world of drones Anne Russell Budapest Drones Conference 5 February 2015.
Information Governance in Commissioning Mental Health Commissioners Collaborative.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
How the Information Commissioner’s office operates as a regulator David Smith Deputy Information Commissioner.
1 HIPAA Security Overview Centers for Medicare & Medicaid Services (CMS)
The Information Commissioner’s Office David Evans.
Working together: Ensuring effective regulation Jonathan Bamford Head of Strategic Liaison.
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
Managing Software Quality
Compliance and Enforcement of the Privacy Rule. HHS/OCR February/March Compliance Date  April 14, 2003 – Compliance for all but small health plans.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
Concur Copyright © 2008 A Unified Invoicing Solution  Coding and allocations  Automated workflow  Data integrity/detail  New vendor requests  Audit.
Information sharing: the view from the ICO Vicky Cetinkaya, Senior Policy Officer, ICO One Staffordshire Information Sharing Protocol launch event Stafford,
Information Management in Retail: A Legal Perspective Chris Hill Barlow Lyde & Gilbert LLP 17 September 2009.
HIPAA A Sea of Confusion, A Wave of the future and A High Tide of Confidentiality.
HOW TO CREATE A THEORY OF CHANGE. OBJECTIVES To understand what a Theory of Change is and why it is so important To understand how to create one To understand.
Interfaces. Peripheral devices connect to the CPU, via slots on the back of the computer.
CONFIDENTIAL © Grandata, Inc. CROSS-INDUSTRY DATA MONETIZATION DTL 11/17/15 – Mat Travizano, CEO.
Data Protection and research Rachael Maguire Records Manager.
Workplace Fairness & advice for the SME Acas experiences in 2014/15.
DATA PROTECTION AND RUNNING A COMPLIANT PUB WATCH SCHEME Nigel Connor Head of Legal –JD Wetherspoon PLC.
Data protection for commissioners Vicky Cetinkaya, Senior Policy Officer, Strategic Liaison Katie Hanrahan, Lead Auditor, Good Practice 2 July 2015.
Information Security TechLink Seminar, 17 April 2013 James Knapton, Information Compliance Officer, Registrary’s Office.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Commissioning Services: with the DPA in mind South Yorkshire Information and Data Sharing Group Sheffield 14 th August 2014 Lynne Shackley Lead Policy.
Supporting staff to share appropriately Vikki Cochran May 2016 Empowering patients to share confidently.
Records management for the public sector 8 September 2016 Judith Jones - Group Manager Sue Markey - Senior Policy Officer Government and Society.
Political campaigning: data protection & electronic marketing
Data protection and data sharing
Accountability & Structured Privacy Management
Can Egosecure help with your GDPR Actions?
EU Data Protection Reform: An ICO Perspective
The future of data protection: General Data Protection Regulation
COMP3357 Managing Cyber Risk
The UK Information Commissioner’s Office (ICO)
Data protection headaches: GDPR, brexit AND perimeter risk
General Data Protection Regulations and the IoT
Monitoring the Funding of Political Parties & Electoral Campaigns
Museums + Heritage webinar, 30 November 2017
Data protection reform:
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
Data protection certification and cloud computing
Data Protection and Running a Compliant Pub Watch SCHeme
General Data Protection Regulation
GDPR How does it apply to me?.
COMP3357 Managing Cyber Risk
Data Mapping On the Journey to Accountability
Data protection and data sharing
The General Data Protection Regulation Six months on – What’s changed
General Data Protection regulation (GDPR)
DATA PROTECTION: LEGAL CONSEQUENCES OF A FAILURE TO COMPLY
Data Privacy and GDPR Jane Shvets
Unit 1 Fundamentals of IT
Getting Ready For GDPR Simon Marks Director
GDPR what do we need to do?
Presentation transcript:

DPA – Complying in the digital transition Dawn Monaghan, Group Manager, Strategic Liaison ICO UK

Contextual questions The digital age? DPA – Obligations Key pitfalls What happens if I get it wrong? Help to get it right

The digital age What do you mean by digital? More flexibility, quicker, easier, global Is it easier to loose information in a non digital or digital format? Can you find information easier on a non digital or digital format? What are the differences in the obligations?

Same 8 Principles Data Sharing protocols Who is the Data Controller/s When is a data processor not a data processor? Privacy, confidentiality, governance, assurance, quality Organisational responsibilities DPA - obligations

Key Pitfalls Thinking that 'digital' automatically simplifies Believing Digital = Technology = IT Lack of clarity about who has responsibility Not thinking 'Privacy by design' Failing to manage 'customer' expectations Monitor

Nature of the data Amount of people affected Distress/harm Track record Enforcement action Civil Monetary Penalties What happens if you get it wrong

Help to get it rights Guidance on the website Data Sharing Code of Practice Privacy Notice Code of Practice Annoymisation Code of Practice Helpline/e newsletter/ webinars/blogs etc.

In summary Obligations the same whatever the format Can become more complex try to simplify at each stage Build in privacy at the beginning Understand who does what when and where the responsibility lies Tell people what you are doing manage their expectations Use the ICO website and other tools