SlideShare uma empresa Scribd logo
1 de 17
EU GDPR
E Baker Law Firm Pllc
 Prior to the EU GDPR, the US had entered into the
EU-US Mutual Legal Assistance Treaty (MLAT)
2003
 Then there was the Safe Harbor Agreement which
set minimum requirements for US-EU
transactions, but…
 The Court of Justice of the European Union (CJEU)
declared in Schrems that the Safe Harbor
Agreement was invalid because it failed to meet
the standards set forth by the EU. The level of
protection in the US was “inadequate” to protect
privacy because US public authorities had access
to the data on a generalized basis for any EU
citizen who’s data was transmitted to the US. This
“generalized, mass, and unlimited” surveillance
was contrary to EU’s privacy and data protection
requirements.
 So on April 14, 2016, the EU GDPR became law
with an effective date of May 25, 2018.
https://www.eugdpr.org/
E Baker Law Firm Pllc
 On July 12, 2016, the EU-US and Swiss-US (on January 12, 2017) entered into the
Privacy Shield Frameworks. This was enforced by the FTC and DOT under the False
Statements Act and or as a violation of 49 USC 41712, but ONLY if the US companies
voluntarily participated in the program.
 In December 2016, the EU-US Umbrella Agreement was entered into with an
effective date of February 1, 2017. This transatlantic agreement set privacy and data
protection safeguards for personal information transferred between the EU and US
for prevention, investigation, detection and prosecution of criminal offenses.
VOLUNTARY AGREEMENTS / FRAMEWORKS
E Baker Law Firm Pllc
 Identify workflow process / data
flow for personal information/data
subject to the EU GDPR
 How data comes in,
 How data is retained/stored,
 How data is transmitted,
 How data is transferred to third party?
 Identify where the data is,
 Who has access to the data,
 Can / How do you retrieve data,
 Can you delete the data upon request?
E Baker Law Firm Pllc
 “personal data”
 “processing”
 “controller”
 “processor”
 “recipient”
 “third party”
 “consent”
 “cross-border processing”
 “international organisation”
E Baker Law Firm Pllc
 Lawful, fairly, transparent
 Collected for specified, explicit,
legitimate purpose
 Adequate, relevant, limited to
what is necessary
 Accurate, up-to-date
 Kept in form where identification
of data subjects is not longer than
necessary
 Secure
 Ability to demonstrate compliance
E Baker Law Firm Pllc
1. Consent
a. Controller must be able to
demonstrate
b. If written consent, must be
“clearly distinguishable” from
other matters, intelligible, easily
accessible, clear and plain
language
c. Prior to consent, must be given
notice of right to withdraw
consent at any time
d. Freely given (e.g. was it
contingent upon performance of
contract or provision of service
and not necessary for that)
2. Necessary
3. Children – 15 years or
younger – must have consent
of holder of parental
responsibility (member states
may require younger age but
not cannot go below age 13)
E Baker Law Firm Pllc
Processing personal data prohibited for data:
 related to race,
 ethnic origin,
 political opinion,
 religious or philosophical beliefs,
 trade union membership,
 genetic data, biometric data for the purpose of
uniquely identifying a natural person,
 health,
 Sex life or sexual orientation
UNLESS
1. Explicit consent for specified purpose (except if
EU member state does not allow consent by
natural person)
2. Necessary
a. for employment, social protection law
b. To protect vital interests of data subject or another
natural person (when data subject not physically or
legally capable of consenting)
c. For establishment, exercise or legal defense or by
courts
d. Substantial public interest
e. Preventive or occupational medicine
f. Public interest in public health
g. Archiving purposes
3. Carried out in course of legitimate activities
with safeguards by not-for profit body
4. Data made public by data subject
E Baker Law Firm Pllc
Controller shall provide notice to
data subject in reference to Articles
13, 14, 15-22, 34:
 concise
 transparent
 intelligible
 easily accessible form
 clear and plain language
 in writing including
electronic means
 without undue delay,
within 1 month of receipt of
request (or inform as to why will
not)
 free of charge
 may request additional
information to substantial identify
of data subject/requestor
E Baker Law Firm Pllc
 Period for which the data will be stored
 Existence of right to request from controller access to,
rectification of, or erasure of data or restriction of
processing concerning data or to object to processing as
well as right to data portability
 Existence of right to withdraw consent at any time
(Article 6(1)(a), 9(2)(a))
 Right to lodge complaint with supervisory authority
 Whether the provision of personal data is statutory or
contractual, etc.
 Existence of automated decision making (profiling,
meaningful information about logic involved,
significance, and envisaged consequences of processing)
If controller intends to further process the data for
purpose other than for which it was collected, controller
shall provide the data subject PRIOR to the further
processing with information on other purpose and the
above information.
E Baker Law Firm Pllc
 Identify and contact details of controller
 Contact details of data protection officer
 Purpose for processing the data and legal basis
 Categories of personal data concerned
 Recipients or categories of recipients
 If applicable, the fact that they data will be transferred to third party or international organization,
existence (or absence) of adequacy decision by Commission, reference to the appropriate or suitable
safeguards and means to obtain copy of them (or where they are available)
 Period for which the data will be stored
 Where the processing is based, legitimate interests pursued by controller or third party
 Existence of right to request from controller access to, rectification of, or erasure of data or restriction
of processing concerning data or to object to processing as well as right to data portability
 Existence of right to withdraw consent at any time (Article 6(1)(a), 9(2)(a))
 Right to lodge complaint with supervisory authority
 Where the personal data (what source) originated, whether it was from publicly accessible sources
 Existence of automated decision making (profiling, meaningful information about logic involved,
significance, and envisaged consequences of processing)
E Baker Law Firm Pllc
Implement appropriate technical and
organisational measures to ensure
processing is performed in
compliance with GDPR
Implement policies
Adhere approved code of conduct or
certification mechanisms
Implement appropriate technical and
organisational methods such as
pseudonymisation designed to
implement data protection principles
(data minimisation) to protect the
rights of the data subject (1) at time
of determination of the means for
processing and (2) at the time of
processing
Maintain written (electronic) records
of processing activities (see Act for
details) (*not applicable to
companies with less than 250
employees unless high risk)
E Baker Law Firm Pllc
Designate DPO where processing is
by public authority,
Core activities are
 regular and systematic monitoring of data
subjects on large scale
 Processing on large scale special categories
of data and personal data relating to criminal
convictions or offences
Group may appoint one DPO if easily
accessible by each office
All other cases, unless required by
Member State law, “may” appoint
DPO
DPO shall have expert knowledge of
GDPR, practices, and have ability to
fulfill tasks (Art. 39)
May be staff member of Controller or
Processor or under contract
Contact details of DPO shall be
published and communicated to
supervisory authority
Responsibilities
 Inform and advise controller, processor,
employees
 Monitor compliance
 Provide advice re data protection impact
assessment, monitor performance
 Act as contact point for and cooperate with
supervisory authorityE Baker Law Firm Pllc
1. Pseudonymisation, encryption of personal data
2. Ensure ongoing confidentiality, integrity,
availability, resilience of processing systems and
services
3. Ability to restore availability and access to data
in timely manner
4. Process for regular testing, assessing, evaluation
of effectiveness of technical and organisational
measure ensuring security
5. Code of Conduct or Approved Certification
Mechanism (Article 40, 42 respectively)
E Baker Law Firm Pllc
1. Controller shall (without undue delay, where
feasible) within 72 hours after becoming aware of
breach notify the supervisory authority
2. Required notice provisions:
a. Nature of breach, categories, number affected
b. Name and contact of data protection officer
c. Consequences of breach
d. Measures to be taken (or taken) to address, mitigate
3. Controller shall document every breach
4. Notify* data subject if “high risk to rights and
freedoms”
No Notice required if data encrypted, subsequent
measures taken which make it likely there is no
high risk, or disproportionate effort required
(public communication instead)
E Baker Law Firm Pllc
Only processors providing sufficient guarantees to
implement appropriate technical and organisational
measures in such a manner that processing will meet
requirements of GDPR
No sub-processors without controller’s prior written
authorization
Shall be governed by contract (see details required) or law
Adherence to approved code of conduct or approved
certification mechanism
Maintain written (electronic) record of all categories of
processing activities carried out for controller (see Act for
details) (*not applicable to companies with less than 250
employees unless high risk)
E Baker Law Firm Pllc
For more information on how to bring your organisation into compliance with
the EU GDPR, data privacy, regulatory compliance, risk management, and or
setting up your workflow processes, policies, procedures. Please contact:
Elizabeth Baker, JD, CRCMP
Internationally certified Risk and Compliance Management Professional (EU, US)
ebakerjd@ebakerjdlaw.com
E Baker Law Firm Pllc

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
What does GDPR mean for your charity?
What does GDPR mean for your charity?What does GDPR mean for your charity?
What does GDPR mean for your charity?
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to Opportunity
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 

Semelhante a EU GDPR (training)

Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
rtjbond
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
N N
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
Yizi
 

Semelhante a EU GDPR (training) (20)

Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
EFA Skillshare - Jitty van Doodewaerd
EFA Skillshare - Jitty van DoodewaerdEFA Skillshare - Jitty van Doodewaerd
EFA Skillshare - Jitty van Doodewaerd
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPR
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
GDPR
GDPRGDPR
GDPR
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization
 
GDPR compliance process and maturity/readiness assessment checklist
GDPR compliance process and maturity/readiness assessment checklistGDPR compliance process and maturity/readiness assessment checklist
GDPR compliance process and maturity/readiness assessment checklist
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
 

Mais de Elizabeth Baker, JD, CRCMP

Mais de Elizabeth Baker, JD, CRCMP (12)

AML BSA - GAMING INDUSTRY
AML BSA - GAMING INDUSTRYAML BSA - GAMING INDUSTRY
AML BSA - GAMING INDUSTRY
 
The intersection of the practice of law and compliance
The intersection of the practice of law and complianceThe intersection of the practice of law and compliance
The intersection of the practice of law and compliance
 
Identifying critical security controls
Identifying critical security controlsIdentifying critical security controls
Identifying critical security controls
 
MiFID II – 2018 compliance deadline looms
MiFID II – 2018 compliance deadline loomsMiFID II – 2018 compliance deadline looms
MiFID II – 2018 compliance deadline looms
 
Complying with HIPAA Privacy Rule
Complying with HIPAA Privacy RuleComplying with HIPAA Privacy Rule
Complying with HIPAA Privacy Rule
 
HOA Liens – Washington
HOA Liens – WashingtonHOA Liens – Washington
HOA Liens – Washington
 
Corporate Workflow Process - Complaints and Legal Matters (illustration)
Corporate Workflow Process - Complaints and Legal Matters (illustration)Corporate Workflow Process - Complaints and Legal Matters (illustration)
Corporate Workflow Process - Complaints and Legal Matters (illustration)
 
BSA/AML in the USA and AML/CTF in the Caymans
BSA/AML in the USA and AML/CTF in the CaymansBSA/AML in the USA and AML/CTF in the Caymans
BSA/AML in the USA and AML/CTF in the Caymans
 
Third Party Vendor Contract – Risk Management
Third Party Vendor Contract – Risk ManagementThird Party Vendor Contract – Risk Management
Third Party Vendor Contract – Risk Management
 
Banking regulations – risk management
Banking regulations – risk managementBanking regulations – risk management
Banking regulations – risk management
 
Managing employee risk
Managing employee riskManaging employee risk
Managing employee risk
 
3 Step Contract Management System
3 Step Contract Management System 3 Step Contract Management System
3 Step Contract Management System
 

Último

一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
F La
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
Airst S
 
Interpretation of statute topics for project
Interpretation of statute topics for projectInterpretation of statute topics for project
Interpretation of statute topics for project
VarshRR
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
Airst S
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
mahikaanand16
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
e9733fc35af6
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
bd2c5966a56d
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
ss
 

Último (20)

WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
Interpretation of statute topics for project
Interpretation of statute topics for projectInterpretation of statute topics for project
Interpretation of statute topics for project
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statute
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. Steering
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 

EU GDPR (training)

  • 1. EU GDPR E Baker Law Firm Pllc
  • 2.  Prior to the EU GDPR, the US had entered into the EU-US Mutual Legal Assistance Treaty (MLAT) 2003  Then there was the Safe Harbor Agreement which set minimum requirements for US-EU transactions, but…  The Court of Justice of the European Union (CJEU) declared in Schrems that the Safe Harbor Agreement was invalid because it failed to meet the standards set forth by the EU. The level of protection in the US was “inadequate” to protect privacy because US public authorities had access to the data on a generalized basis for any EU citizen who’s data was transmitted to the US. This “generalized, mass, and unlimited” surveillance was contrary to EU’s privacy and data protection requirements.  So on April 14, 2016, the EU GDPR became law with an effective date of May 25, 2018. https://www.eugdpr.org/ E Baker Law Firm Pllc
  • 3.  On July 12, 2016, the EU-US and Swiss-US (on January 12, 2017) entered into the Privacy Shield Frameworks. This was enforced by the FTC and DOT under the False Statements Act and or as a violation of 49 USC 41712, but ONLY if the US companies voluntarily participated in the program.  In December 2016, the EU-US Umbrella Agreement was entered into with an effective date of February 1, 2017. This transatlantic agreement set privacy and data protection safeguards for personal information transferred between the EU and US for prevention, investigation, detection and prosecution of criminal offenses. VOLUNTARY AGREEMENTS / FRAMEWORKS E Baker Law Firm Pllc
  • 4.  Identify workflow process / data flow for personal information/data subject to the EU GDPR  How data comes in,  How data is retained/stored,  How data is transmitted,  How data is transferred to third party?  Identify where the data is,  Who has access to the data,  Can / How do you retrieve data,  Can you delete the data upon request? E Baker Law Firm Pllc
  • 5.  “personal data”  “processing”  “controller”  “processor”  “recipient”  “third party”  “consent”  “cross-border processing”  “international organisation” E Baker Law Firm Pllc
  • 6.  Lawful, fairly, transparent  Collected for specified, explicit, legitimate purpose  Adequate, relevant, limited to what is necessary  Accurate, up-to-date  Kept in form where identification of data subjects is not longer than necessary  Secure  Ability to demonstrate compliance E Baker Law Firm Pllc
  • 7. 1. Consent a. Controller must be able to demonstrate b. If written consent, must be “clearly distinguishable” from other matters, intelligible, easily accessible, clear and plain language c. Prior to consent, must be given notice of right to withdraw consent at any time d. Freely given (e.g. was it contingent upon performance of contract or provision of service and not necessary for that) 2. Necessary 3. Children – 15 years or younger – must have consent of holder of parental responsibility (member states may require younger age but not cannot go below age 13) E Baker Law Firm Pllc
  • 8. Processing personal data prohibited for data:  related to race,  ethnic origin,  political opinion,  religious or philosophical beliefs,  trade union membership,  genetic data, biometric data for the purpose of uniquely identifying a natural person,  health,  Sex life or sexual orientation UNLESS 1. Explicit consent for specified purpose (except if EU member state does not allow consent by natural person) 2. Necessary a. for employment, social protection law b. To protect vital interests of data subject or another natural person (when data subject not physically or legally capable of consenting) c. For establishment, exercise or legal defense or by courts d. Substantial public interest e. Preventive or occupational medicine f. Public interest in public health g. Archiving purposes 3. Carried out in course of legitimate activities with safeguards by not-for profit body 4. Data made public by data subject E Baker Law Firm Pllc
  • 9. Controller shall provide notice to data subject in reference to Articles 13, 14, 15-22, 34:  concise  transparent  intelligible  easily accessible form  clear and plain language  in writing including electronic means  without undue delay, within 1 month of receipt of request (or inform as to why will not)  free of charge  may request additional information to substantial identify of data subject/requestor E Baker Law Firm Pllc
  • 10.  Period for which the data will be stored  Existence of right to request from controller access to, rectification of, or erasure of data or restriction of processing concerning data or to object to processing as well as right to data portability  Existence of right to withdraw consent at any time (Article 6(1)(a), 9(2)(a))  Right to lodge complaint with supervisory authority  Whether the provision of personal data is statutory or contractual, etc.  Existence of automated decision making (profiling, meaningful information about logic involved, significance, and envisaged consequences of processing) If controller intends to further process the data for purpose other than for which it was collected, controller shall provide the data subject PRIOR to the further processing with information on other purpose and the above information. E Baker Law Firm Pllc
  • 11.  Identify and contact details of controller  Contact details of data protection officer  Purpose for processing the data and legal basis  Categories of personal data concerned  Recipients or categories of recipients  If applicable, the fact that they data will be transferred to third party or international organization, existence (or absence) of adequacy decision by Commission, reference to the appropriate or suitable safeguards and means to obtain copy of them (or where they are available)  Period for which the data will be stored  Where the processing is based, legitimate interests pursued by controller or third party  Existence of right to request from controller access to, rectification of, or erasure of data or restriction of processing concerning data or to object to processing as well as right to data portability  Existence of right to withdraw consent at any time (Article 6(1)(a), 9(2)(a))  Right to lodge complaint with supervisory authority  Where the personal data (what source) originated, whether it was from publicly accessible sources  Existence of automated decision making (profiling, meaningful information about logic involved, significance, and envisaged consequences of processing) E Baker Law Firm Pllc
  • 12. Implement appropriate technical and organisational measures to ensure processing is performed in compliance with GDPR Implement policies Adhere approved code of conduct or certification mechanisms Implement appropriate technical and organisational methods such as pseudonymisation designed to implement data protection principles (data minimisation) to protect the rights of the data subject (1) at time of determination of the means for processing and (2) at the time of processing Maintain written (electronic) records of processing activities (see Act for details) (*not applicable to companies with less than 250 employees unless high risk) E Baker Law Firm Pllc
  • 13. Designate DPO where processing is by public authority, Core activities are  regular and systematic monitoring of data subjects on large scale  Processing on large scale special categories of data and personal data relating to criminal convictions or offences Group may appoint one DPO if easily accessible by each office All other cases, unless required by Member State law, “may” appoint DPO DPO shall have expert knowledge of GDPR, practices, and have ability to fulfill tasks (Art. 39) May be staff member of Controller or Processor or under contract Contact details of DPO shall be published and communicated to supervisory authority Responsibilities  Inform and advise controller, processor, employees  Monitor compliance  Provide advice re data protection impact assessment, monitor performance  Act as contact point for and cooperate with supervisory authorityE Baker Law Firm Pllc
  • 14. 1. Pseudonymisation, encryption of personal data 2. Ensure ongoing confidentiality, integrity, availability, resilience of processing systems and services 3. Ability to restore availability and access to data in timely manner 4. Process for regular testing, assessing, evaluation of effectiveness of technical and organisational measure ensuring security 5. Code of Conduct or Approved Certification Mechanism (Article 40, 42 respectively) E Baker Law Firm Pllc
  • 15. 1. Controller shall (without undue delay, where feasible) within 72 hours after becoming aware of breach notify the supervisory authority 2. Required notice provisions: a. Nature of breach, categories, number affected b. Name and contact of data protection officer c. Consequences of breach d. Measures to be taken (or taken) to address, mitigate 3. Controller shall document every breach 4. Notify* data subject if “high risk to rights and freedoms” No Notice required if data encrypted, subsequent measures taken which make it likely there is no high risk, or disproportionate effort required (public communication instead) E Baker Law Firm Pllc
  • 16. Only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet requirements of GDPR No sub-processors without controller’s prior written authorization Shall be governed by contract (see details required) or law Adherence to approved code of conduct or approved certification mechanism Maintain written (electronic) record of all categories of processing activities carried out for controller (see Act for details) (*not applicable to companies with less than 250 employees unless high risk) E Baker Law Firm Pllc
  • 17. For more information on how to bring your organisation into compliance with the EU GDPR, data privacy, regulatory compliance, risk management, and or setting up your workflow processes, policies, procedures. Please contact: Elizabeth Baker, JD, CRCMP Internationally certified Risk and Compliance Management Professional (EU, US) ebakerjd@ebakerjdlaw.com E Baker Law Firm Pllc