Download presentation
Presentation is loading. Please wait.
Published byFanny Susanto Modified over 6 years ago
2
Ground Rules
7
Technology We can provide details of all data electronically
All data is securely stored We can fulfil the ‘right to be forgotten’ All new technology has privacy by design built-in
8
Processes and Systems We know the source of all data
We know what data we are holding We are transparent about the use and sharing of data We can clearly demonstrate that we have consent to use this data We have systems in place to manage a data breach We can comply with an individual’s right to portability
9
Information and rights of access
Individuals can easily find out what information we hold on them We have developed template responses We have updated all our permission statements and they are ready for GDPR Individuals can access their own data and update their preferences We can put it right when we’ve got it wrong
13
Unbundled Consent requests must be separate from other terms and conditions Consent should not be a precondition of signing up to a service unless necessary for that service
14
Pre-ticked opt-in boxes are invalid – use unticked opt-in boxes or similar active opt-in methods (eg a binary choice given equal prominence) Active opt-in
15
Granular Give granular options to consent separately for different types of processing wherever appropriate
16
Name your organization and any third parties who will be relying on consent – even precisely defined categories of third-party organizations will not be acceptable under the GDPR Named
17
Easy to withdraw Tell people they have the right to withdraw their consent at any time, and how to do this It must be as easy to withdraw as it was to give consent This means you will need to have simple and effective withdrawal mechanisms in place
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.