SlideShare uma empresa Scribd logo
1 de 40
Baixar para ler offline
Public sector breakfast club
October 2017, Exeter
Introduction to the
General Data Protection Regulation
Patrick O’Connell
Date
25 May 2018
Outcomes for this session
• Basic understanding of GDPR
• Basic understanding of the role of Data Protection
Officer
• Know the steps organisations should take now
Outcomes for this session
Please ask questions at any point
Main features of the GDPR
• Same basic principles as DPA, but strengthened
• Accountability
• New rights for individuals
• Strengthening of existing rights
• Breach reporting
• Data protection impact assessments
• Higher penalties for non-compliance
Main features of GDPR
New definition of personal data
An identifiable person who can be identified directly or indirectly, in
particular by reference to an identifier such as name, identification
number, location data, online identifier or to one or more factors
specific to the physical, cultural, physiological, genetic, mental,
economic, cultural or social identity.
Main features of GDPR
Special categories of data
• Race or ethnic origin
• Political Opinions
• Religious or Philosophical Beliefs
• Trade Union Membership
• Health or Sex Life and Sexual Orientation
• Genetic or Biometric data in order to uniquely identify a person
Main features of GDPR
New definition of processing
Any operation or set of operations which is performed on personal
data whether or not automated including collecting, recording,
organising, structuring, storing, adapting, altering, disclosure,
erasure or destruction.
Main features of GDPR
New data protection principles
1. Data must be processed lawfully, fairly and in a transparent manner
2. Data must only be collected for a specified, explicit and legitimate
purpose
3. Data must only be processed to the extent that it is adequate,
relevant and limited to what is necessary in relation to the purpose
for which they are processed
4. Data must be accurate and up to date. Data which is inaccurate
should be erased or rectified without delay
5. Identifiable data should not be kept longer than is necessary
6. Ensure appropriate security of the data
• Demonstrate compliance with the Regulations
Main features of the GDPR
Conditions for processing personal data
• Consent (new provisions for consent)
• Contractual necessity
• Legal obligation
• Vital Interests of the data subject or of another natural person
• Public Interest or exercise of official authority
• Legitimate interests of data controller or third party to whom data is
disclosed (but not to a public authority)
Main features of GDPR
Conditions for processing special categories of data
• Explicit consent of the data subject, unless reliance on consent is
prohibited by EU or Member State law
• Processing is necessary for carrying out obligations under employment,
social security or social protection law, or a collective agreement
• Processing is necessary to protect the vital interests of a data subject
or another individual where the data subject is physically or legally
incapable of giving consent
Main features of the GDPR
Conditions for processing special categories of data (contd)
• Processing carried out by a not-for-profit body with a political,
philosophical, religious or trade union aim provided the processing
relates only to members or former members (or those who have
regular contact with it in connection with those purposes) and
provided there is no disclosure to a third party without consent
• Processing relates to personal data manifestly made public by the data
subject
• Processing is necessary for the establishment, exercise or defence of
legal claims or where courts are acting in their judicial capacity
Main features of the GDPR
Conditions for processing special categories of data (contd)
• Processing is necessary for reasons of substantial public interest on the
basis of Union or Member State law which is proportionate to the aim
pursued and which contains appropriate safeguards
• Processing is necessary for the purposes of preventative or
occupational medicine, for assessing the working capacity of the
employee, medical diagnosis, the provision of health or social care or
treatment or management of health or social care systems and
services on the basis of Union or Member State law or a contract with
a health professional
Main features of the GDPR
Conditions for processing special categories of data (contd)
• Processing is necessary for reasons of public interest in the
area of public health, such as protecting against serious cross-
border threats to health or ensuring high standards of
healthcare and of medicinal products or medical devices
• Processing is necessary for archiving purposes in the public
interest, or scientific and historical research purposes or
statistical purposes in accordance with Article 89(1)
Demonstrate compliance
Organisations will need to be able to show compliance in
• Requirement to implement appropriate technical and
organisational measures
• Maintaining records on processing activities
• Data protection impact assessments
• Requirement to appoint a data protection officer
• Data protection by design and default
• Codes of conduct and certification schemes
Information asset audit
If you are concerned about compliance, you should carry out an
information audit
• What data do you process?
• For what purposes?
• What legal basis do you use?
• Who do you share data with?
• Can you identify a specific individual’s data and provide it
within one month?
New rules for data processors
Who are data processors?
Third parties who process data on your behalf
• Contractors
• IT providers
• Payroll processors
• Archiving companies
New rules for data processors
New GDPR obligations on data processors
• Appoint a DPO?
• Consent needed from controller for subcontracting
• Maintain records of processing activity
• Notify data controller of any breach
• Liability for claims
• May also be subject to fines
New rules for data processors
What do you need to do?
• Review existing contracts to ensure they include GDPR clauses
• Review clauses relating to limitation of liability, insurance,
indemnities, warranties
• Update standard contracts
• Update procurement processes to include GDPR due diligence
The ICO’s key steps to take now
1. Awareness
Make sure decision makers aware of change and impact
• Nominate a responsible member of the senior management
team
• Organise a working group (IT, HR) and get meetings in the diary
• Add data protection to your risk register
The ICO’s key steps to take now
2. Information you hold
Document the information you hold
• Where it came from
• Who you share it with
• Do you need to carry out an information audit? (invariably - yes!)
The ICO’s key steps to take now
3. Communicating privacy notices
Review privacy notices and put in place changes for the GDPR
• New notices must include:
• Legal basis for processing
• Data retention periods
• Complaints
• Concise and easy to understand language
• ICO privacy notice code of practice reflects changes
The ICO’s key steps to take now
4. Individuals’ rights
Check your procedures to make sure they cover all new rights
• Subject access
• Inaccuracies corrected
• Information erased (‘right to be forgotten’)
• Prevent direct marketing
• Prevent automated decision-making and profiling
• Data portability
The ICO’s key steps to take now
4. Individuals’ rights (contd)
Data controllers must provide the following to data subjects on request:
• Identity and contact details of data controller and data protection
officer
• Intended purpose of processing and period for which data will be
stored
• Existence of rights: access, rectification, object and erasure
• Right to lodge a complaint internally and to a supervisory authority
The ICO’s key steps to take now
4. Individuals’ rights (contd)
Data controllers must provide the following on request (contd):
• Recipient or categories of recipients to whom data will be
disclosed
• Intention to transfer to another country or international
organisation
• Information must be concise, transparent, intelligible and
easily accessible
• Must be provided in writing unless otherwise requested.
The ICO’s key steps to take now
5.Subject access requests
• Must respond within one month but can extend for complex
requests
• No fee
• Requestor can ask for electronic format
• Manifestly unfounded or excessive requests may be charged for
or refused
• Train staff to recognise a subject access request
• Develop template response letters
• Online portal for accessing information?
The ICO’s key steps to take now
6. Legal basis for processing data
• Review the types of processing you are carrying out
• Identify legal basis for each type
• Document the legal basis
The ICO’s key steps to take now
7. Consent
• Review how you are seeking, obtaining and recording consent
and whether you need to make changes
• Consent must be freely given, specific, informed and
unambiguous, and a positive affirmation of the individual’s
agreement
• Burden on data controller to show consent freely given
• Withdrawal of consent should be as easy as grant of consent
• Purpose limited
The ICO’s key steps to take now
8. Children
• Where you do not have a different legal basis for processing,
parents will need to give consent
• Special protection for children’s data:
• Stronger ‘right to be forgotten’
• Limitations on legitimate interests condition for processing
• If you ask children to sign up to apps or online services think
about how you are going to get consent from parents
• Where services are offered directly to a child, you must ensure
privacy notice is written in a clear, plain way that a child will
understand
The ICO’s key steps to take now
9. Data breaches
Make sure you have procedures in place to detect, report and investigate
a personal data breach
• You have 72 hours to report a breach
• Only need to report breach where the individual is likely to suffer
some form of damage – such as identity theft or confidentiality breach
• Notify the affected data subjects
• Fines will be based on:
• nature gravity and duration of breach
• Whether intentional or negligent
• Previous breaches
• Technical and organisation measures in place
The ICO’s key steps to take now
10. Data protection by design and data protection impact
assessments (privacy impact assessments)
At the outset of every project think about personal data
• Consider how you can minimise personal data use and risk
• Legal requirement to carry out a privacy impact assessment
• ICO guidance on privacy impact assessments
The ICO’s key steps to take now
11. Data protection officers
You should designate a DPO
• Responsible for data protection compliance
• Inform and advise the organisation
• Monitor the implementation and application of the Regulations
and the data protection policies
• Monitor privacy impact assessments and breaches
• Point of contact for ICO
The ICO’s key steps to take now
11. Data protection officers (contd)
• Can allocate to role of existing employee as long as duties are
compatible with the duties of the DPO and do not lead to
conflict of interests
• Can appoint the role externally
• Can share a DPO over a number of data controllers
• No specified qualifications but must have experience and
knowledge of data protection law
The ICO’s key steps to take now
11. Data protection officers (contd)
You must ensure that:
• The DPO reports to the highest management level of your
organisation – ie board level
• The DPO operates independently and is not dismissed or
penalised for performing their task
• Adequate resources are provided to enable DPOs to
meet their GDPR obligations
The ICO’s key steps to take now
12. International
• Trips outside the EU?
• Subcontractors processing information outside the EU?
Other points
• ICO overview of the GDPR
• Some personal information not covered by the GDPR (policing and national
security). These areas are covered by the Data Protection Bill.
• Data Protection Bill also covers areas where the UK is given discretion and
exemptions by the GDPR.
Any questions?
Happy to discuss further
Patrick O’Connell | 0330 045 2149 | patrick.oconnell@brownejacobson.com
All information correct at time of production.
The information and opinions expressed within this document are no
substitute for full legal advice. It is for guidance only and illustrates
the law as at the published date. If in doubt, please telephone us on
0370 270 6000.
© Browne Jacobson LLP 2017 – The information contained within this
document is and shall remain the property of Browne Jacobson. This
document may not be reproduced without the prior consent of
Browne Jacobson.

Mais conteúdo relacionado

Mais procurados

ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson LLP
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Michael Adamberry
 
EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016Erik Vollebregt
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection RegulationGrittyCC
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminarBrowne Jacobson LLP
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR OverviewGydeline Ltd
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 

Mais procurados (20)

ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 

Semelhante a Public sector breakfast club - October 2017, Exeter

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?TAG Alliances
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMichelleSaver
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...CharityComms
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRRotary International
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareWinston & Strawn LLP
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...m-hance
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillSymptai Consulting Limited
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Forums financiers de Wallonie
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterBrowne Jacobson LLP
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPRMarketo
 

Semelhante a Public sector breakfast club - October 2017, Exeter (20)

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To Prepare
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 

Mais de Browne Jacobson LLP

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Browne Jacobson LLP
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed Browne Jacobson LLP
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionBrowne Jacobson LLP
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Browne Jacobson LLP
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Browne Jacobson LLP
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Browne Jacobson LLP
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Browne Jacobson LLP
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Browne Jacobson LLP
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Browne Jacobson LLP
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamBrowne Jacobson LLP
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London Browne Jacobson LLP
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Browne Jacobson LLP
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 Browne Jacobson LLP
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Browne Jacobson LLP
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterBrowne Jacobson LLP
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Browne Jacobson LLP
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamBrowne Jacobson LLP
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Browne Jacobson LLP
 

Mais de Browne Jacobson LLP (20)

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham session
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019
 
Health tech slides 12 june 2019
Health tech slides   12 june 2019Health tech slides   12 june 2019
Health tech slides 12 june 2019
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - Birmingham
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019
 
In House Lawyers, March 2019
In House Lawyers, March 2019In House Lawyers, March 2019
In House Lawyers, March 2019
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, Manchester
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, Nottingham
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...
 

Último

如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书Fir L
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx2020000445musaib
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...James Watkins, III JD CFP®
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书Fir sss
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxPKrishna18
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaBridgeWest.eu
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGPRAKHARGUPTA419620
 
Understanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesUnderstanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesFinlaw Associates
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 

Último (20)

如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptx
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad Visa
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKING
 
Understanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesUnderstanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and Challenges
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 

Public sector breakfast club - October 2017, Exeter

  • 1. Public sector breakfast club October 2017, Exeter
  • 2. Introduction to the General Data Protection Regulation Patrick O’Connell
  • 4. Outcomes for this session • Basic understanding of GDPR • Basic understanding of the role of Data Protection Officer • Know the steps organisations should take now
  • 5. Outcomes for this session Please ask questions at any point
  • 6. Main features of the GDPR • Same basic principles as DPA, but strengthened • Accountability • New rights for individuals • Strengthening of existing rights • Breach reporting • Data protection impact assessments • Higher penalties for non-compliance
  • 7. Main features of GDPR New definition of personal data An identifiable person who can be identified directly or indirectly, in particular by reference to an identifier such as name, identification number, location data, online identifier or to one or more factors specific to the physical, cultural, physiological, genetic, mental, economic, cultural or social identity.
  • 8. Main features of GDPR Special categories of data • Race or ethnic origin • Political Opinions • Religious or Philosophical Beliefs • Trade Union Membership • Health or Sex Life and Sexual Orientation • Genetic or Biometric data in order to uniquely identify a person
  • 9. Main features of GDPR New definition of processing Any operation or set of operations which is performed on personal data whether or not automated including collecting, recording, organising, structuring, storing, adapting, altering, disclosure, erasure or destruction.
  • 10. Main features of GDPR New data protection principles 1. Data must be processed lawfully, fairly and in a transparent manner 2. Data must only be collected for a specified, explicit and legitimate purpose 3. Data must only be processed to the extent that it is adequate, relevant and limited to what is necessary in relation to the purpose for which they are processed 4. Data must be accurate and up to date. Data which is inaccurate should be erased or rectified without delay 5. Identifiable data should not be kept longer than is necessary 6. Ensure appropriate security of the data • Demonstrate compliance with the Regulations
  • 11. Main features of the GDPR Conditions for processing personal data • Consent (new provisions for consent) • Contractual necessity • Legal obligation • Vital Interests of the data subject or of another natural person • Public Interest or exercise of official authority • Legitimate interests of data controller or third party to whom data is disclosed (but not to a public authority)
  • 12. Main features of GDPR Conditions for processing special categories of data • Explicit consent of the data subject, unless reliance on consent is prohibited by EU or Member State law • Processing is necessary for carrying out obligations under employment, social security or social protection law, or a collective agreement • Processing is necessary to protect the vital interests of a data subject or another individual where the data subject is physically or legally incapable of giving consent
  • 13. Main features of the GDPR Conditions for processing special categories of data (contd) • Processing carried out by a not-for-profit body with a political, philosophical, religious or trade union aim provided the processing relates only to members or former members (or those who have regular contact with it in connection with those purposes) and provided there is no disclosure to a third party without consent • Processing relates to personal data manifestly made public by the data subject • Processing is necessary for the establishment, exercise or defence of legal claims or where courts are acting in their judicial capacity
  • 14. Main features of the GDPR Conditions for processing special categories of data (contd) • Processing is necessary for reasons of substantial public interest on the basis of Union or Member State law which is proportionate to the aim pursued and which contains appropriate safeguards • Processing is necessary for the purposes of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
  • 15. Main features of the GDPR Conditions for processing special categories of data (contd) • Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross- border threats to health or ensuring high standards of healthcare and of medicinal products or medical devices • Processing is necessary for archiving purposes in the public interest, or scientific and historical research purposes or statistical purposes in accordance with Article 89(1)
  • 16. Demonstrate compliance Organisations will need to be able to show compliance in • Requirement to implement appropriate technical and organisational measures • Maintaining records on processing activities • Data protection impact assessments • Requirement to appoint a data protection officer • Data protection by design and default • Codes of conduct and certification schemes
  • 17. Information asset audit If you are concerned about compliance, you should carry out an information audit • What data do you process? • For what purposes? • What legal basis do you use? • Who do you share data with? • Can you identify a specific individual’s data and provide it within one month?
  • 18. New rules for data processors Who are data processors? Third parties who process data on your behalf • Contractors • IT providers • Payroll processors • Archiving companies
  • 19. New rules for data processors New GDPR obligations on data processors • Appoint a DPO? • Consent needed from controller for subcontracting • Maintain records of processing activity • Notify data controller of any breach • Liability for claims • May also be subject to fines
  • 20. New rules for data processors What do you need to do? • Review existing contracts to ensure they include GDPR clauses • Review clauses relating to limitation of liability, insurance, indemnities, warranties • Update standard contracts • Update procurement processes to include GDPR due diligence
  • 21. The ICO’s key steps to take now 1. Awareness Make sure decision makers aware of change and impact • Nominate a responsible member of the senior management team • Organise a working group (IT, HR) and get meetings in the diary • Add data protection to your risk register
  • 22. The ICO’s key steps to take now 2. Information you hold Document the information you hold • Where it came from • Who you share it with • Do you need to carry out an information audit? (invariably - yes!)
  • 23. The ICO’s key steps to take now 3. Communicating privacy notices Review privacy notices and put in place changes for the GDPR • New notices must include: • Legal basis for processing • Data retention periods • Complaints • Concise and easy to understand language • ICO privacy notice code of practice reflects changes
  • 24. The ICO’s key steps to take now 4. Individuals’ rights Check your procedures to make sure they cover all new rights • Subject access • Inaccuracies corrected • Information erased (‘right to be forgotten’) • Prevent direct marketing • Prevent automated decision-making and profiling • Data portability
  • 25. The ICO’s key steps to take now 4. Individuals’ rights (contd) Data controllers must provide the following to data subjects on request: • Identity and contact details of data controller and data protection officer • Intended purpose of processing and period for which data will be stored • Existence of rights: access, rectification, object and erasure • Right to lodge a complaint internally and to a supervisory authority
  • 26. The ICO’s key steps to take now 4. Individuals’ rights (contd) Data controllers must provide the following on request (contd): • Recipient or categories of recipients to whom data will be disclosed • Intention to transfer to another country or international organisation • Information must be concise, transparent, intelligible and easily accessible • Must be provided in writing unless otherwise requested.
  • 27. The ICO’s key steps to take now 5.Subject access requests • Must respond within one month but can extend for complex requests • No fee • Requestor can ask for electronic format • Manifestly unfounded or excessive requests may be charged for or refused • Train staff to recognise a subject access request • Develop template response letters • Online portal for accessing information?
  • 28. The ICO’s key steps to take now 6. Legal basis for processing data • Review the types of processing you are carrying out • Identify legal basis for each type • Document the legal basis
  • 29. The ICO’s key steps to take now 7. Consent • Review how you are seeking, obtaining and recording consent and whether you need to make changes • Consent must be freely given, specific, informed and unambiguous, and a positive affirmation of the individual’s agreement • Burden on data controller to show consent freely given • Withdrawal of consent should be as easy as grant of consent • Purpose limited
  • 30. The ICO’s key steps to take now 8. Children • Where you do not have a different legal basis for processing, parents will need to give consent • Special protection for children’s data: • Stronger ‘right to be forgotten’ • Limitations on legitimate interests condition for processing • If you ask children to sign up to apps or online services think about how you are going to get consent from parents • Where services are offered directly to a child, you must ensure privacy notice is written in a clear, plain way that a child will understand
  • 31. The ICO’s key steps to take now 9. Data breaches Make sure you have procedures in place to detect, report and investigate a personal data breach • You have 72 hours to report a breach • Only need to report breach where the individual is likely to suffer some form of damage – such as identity theft or confidentiality breach • Notify the affected data subjects • Fines will be based on: • nature gravity and duration of breach • Whether intentional or negligent • Previous breaches • Technical and organisation measures in place
  • 32. The ICO’s key steps to take now 10. Data protection by design and data protection impact assessments (privacy impact assessments) At the outset of every project think about personal data • Consider how you can minimise personal data use and risk • Legal requirement to carry out a privacy impact assessment • ICO guidance on privacy impact assessments
  • 33. The ICO’s key steps to take now 11. Data protection officers You should designate a DPO • Responsible for data protection compliance • Inform and advise the organisation • Monitor the implementation and application of the Regulations and the data protection policies • Monitor privacy impact assessments and breaches • Point of contact for ICO
  • 34. The ICO’s key steps to take now 11. Data protection officers (contd) • Can allocate to role of existing employee as long as duties are compatible with the duties of the DPO and do not lead to conflict of interests • Can appoint the role externally • Can share a DPO over a number of data controllers • No specified qualifications but must have experience and knowledge of data protection law
  • 35. The ICO’s key steps to take now 11. Data protection officers (contd) You must ensure that: • The DPO reports to the highest management level of your organisation – ie board level • The DPO operates independently and is not dismissed or penalised for performing their task • Adequate resources are provided to enable DPOs to meet their GDPR obligations
  • 36. The ICO’s key steps to take now 12. International • Trips outside the EU? • Subcontractors processing information outside the EU?
  • 37. Other points • ICO overview of the GDPR • Some personal information not covered by the GDPR (policing and national security). These areas are covered by the Data Protection Bill. • Data Protection Bill also covers areas where the UK is given discretion and exemptions by the GDPR.
  • 39. Happy to discuss further Patrick O’Connell | 0330 045 2149 | patrick.oconnell@brownejacobson.com
  • 40. All information correct at time of production. The information and opinions expressed within this document are no substitute for full legal advice. It is for guidance only and illustrates the law as at the published date. If in doubt, please telephone us on 0370 270 6000. © Browne Jacobson LLP 2017 – The information contained within this document is and shall remain the property of Browne Jacobson. This document may not be reproduced without the prior consent of Browne Jacobson.