Digital Banking and Data Protection Achieving balance of compliance with customer experience and opportunity 30 September 2015 Paula Barrett Partner.

Slides:



Advertisements
Similar presentations
Public Administration use of Social Networks - Data Protection Implications European Public Administration Network, Dublin Castle, 5 April 2013 Billy Hawkes.
Advertisements

New Models for Planning & Affordable Housing – HBF conference Planning Agreements – use, abuse and some possible solutions Paul Winter, Eversheds LLP 14.
The Gathering Cloud computing - Legal considerations David Goodbrand, Partner 28 February 2013 Aberdeen Edinburgh Glasgow.
McCarthy Tétrault McCarthy Tétrault LLP An Act respecting the protection of personal information in the private sector (Quebec): « Particularities of the.
Data Protection and Records Management
Dino Tsibouris (614) Technology Contracting 101 What to watch out for in your contracts.
Class 13 Internet Privacy Law European Privacy.
Data Protection Overview
SROC Conference Data Sharing – The New Culture? Elaine Fletcher, Senior Associate, Eversheds LLP April 2008.
Eric J. Pritchard One Liberty Place, 46 th Floor 1650 Market Street Philadelphia, Pennsylvania (215)
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
Sharing Information With Affiliates and Third Parties F. Jay Meyer Vice President & Senior Counsel TD Bank, N.A. Portland, Maine.
Data Protection Act AS Module Heathcote Ch. 12.
Preparing Russian Companies for UK Bribery Act Enforcement - The Defence of “Adequate Procedures” Nicholas Munday 14 December 2010 Moscow.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Eversheds Digital Banking Seminar
Eversheds Digital Banking Seminar Delivering compliant digital products 30 September 2015 Clare Hughes Partner.
Eversheds Digital Banking Seminar Obtaining the right technology 30 September 2015 Eve England Principal Associate.
Information Management in Retail: A Legal Perspective Chris Hill Barlow Lyde & Gilbert LLP 17 September 2009.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
The EU General Data Protection Regulation Frank Rankin.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Data protection—training materials [Name and details of speaker]
Sharing Information Legally Lindsay Ould London Borough of Lewisham.
Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
[ Direct marketing – an introduction to data protection and privacy] For [insert name of organisation] presented by [insert name of presenter] on [date]
Business Challenges in the evolution of HOME AUTOMATION (IoT)
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
František Nonnemann Skopje, 10th October 2012 JHA Data protection and re-use of PSI as a tool for public control–CZ approach.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
General Data Protection Regulation (EU 2016/679)
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
Student Privacy in an Ever-Changing Digital World
GDPR (General Data Protection Regulation)
6 October 2016 Social media: do you have the right social media strategy that will impact your business’ growth? - Legal and Regulatory Issues William.
Presentation to GTMC on GDPR
INTERCONNECTION GUIDELINES
Data Protection The Current Regime
General Data Protection Regulation
KEY CHANGES TO THE DATA PROTECTION LANDSCAPE
Museums + Heritage webinar, 30 November 2017
Conducting Compliant Marketing & SARs Workshop - CMG Events
Data Protection Update – GDPR or bust
Data Protection Legislation
GDPR support January GDPR support January 2018.
The European Union General Data Protection Regulation (GDPR)
PERSONAL DATA PROTECTION ACT 2010
Data protection reform:
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Are you processing personal data lawfully?
G.D.P.R General Data Protection Regulations
General Data Protection Regulations
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Relocation CARNIVAL come one…come all
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR How does it apply to me?.
The General Data Protection Regulation Six months on – What’s changed
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Why are we processing data
EU Data Protection Legislation
Privacy Principles Melinda Clarke.
GDPR Workshop – Partnerships for Jewish Schools
GDPR what do we need to do?
Presentation transcript:

Digital Banking and Data Protection Achieving balance of compliance with customer experience and opportunity 30 September 2015 Paula Barrett Partner

Data protection compliance Recognizing what personal data/private information is processed Identifying the players - data controllers and data processors Work through application of principles, lawful reasons, fairness, transfers, filings, etc Give fair notice Gather permissions where needed Other relevant issues Other legislation/laws/torts Culture and expectations Political/regulatory stance

Personal data – can you spot it? “Personal Data” means data which relate to a living individual who can be identified: (a) from those data and other information which is in the possession of or is likely to come into the possession of, the data controller (b) includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual Not just names – other identifiers too Think about ability to combine with other data within business Can include twitter names, Mac address, Fixed IP address Current DPA Definition:

The players? −Spot the data controller(s)! Often more than one in digital platforms Within group? Third parties? Relevant for determining Applicable law Who carries DPA responsibility? Lawfulness requirement in transfers from DC to BC Limited exemptions −Who are the data processor? Contractual requirements under DPA to be met Under UK DPA no direct obligations Position may change under GDPR Geographic restrictions on transfers

Eversheds LLP | −Timing: When does data collection really commence? Bear in mind varying sources and channels – app, social media, other accounts, etc. Do you need a third party to provide notice/expand notices to specifically include us and our processing? −Scope – transparency is essential and becoming more so −Consistency across platforms (on and offline) Expanding digital processing may mean we have to expand the non digital notices and notices on other platforms e.g. facebook etc. −Technical constaints and customer experience Screen and text limitations Layering Links to website and other locations for further detail Fair Processing Notice must be given prior to or within a reasonable time of data being collected. When & how to deliver Notices and privacy policies

Eversheds LLP | −Start with working out what processing you are doing Need to understand the totality of processing including any sharing with other group companies and third parties −Treat consent as a last resort – not the first one It can be withdrawn at any time −Other lawful reasons: Consider statutory obligation Legitimate interest At request of individual Fulfilment of contract Anti-fraud Remember all qualified by “necessary for” test and proportionality −Transparency on consent obtained by or for third parties −How will marketing preference be exercised? tools within the digital product? −Operationally/technically need to be able to respond to consent changes from range of sources For each category of personal data you need a lawful reason for processing it When, what and how Collection of permissions

Questions?

eversheds.com ©2015 Eversheds LLP Eversheds LLP is a limited liability partnership Partner Paula Barrett Company Commercial Eversheds One Wood Street London EC2V 7WS