Data Protection Mark Gleeson Todays focus Briefing on the new law - - PowerPoint PPT Presentation

data protection
SMART_READER_LITE
LIVE PREVIEW

Data Protection Mark Gleeson Todays focus Briefing on the new law - - PowerPoint PPT Presentation

Data Protection Mark Gleeson Todays focus Briefing on the new law Identify the practical impact on you Design your GDPR compliance programme #GenerationGDPR GDPR background What is it? Why is it coming in? What


slide-1
SLIDE 1

Data Protection

Mark Gleeson

slide-2
SLIDE 2

#GenerationGDPR

Today’s focus

  • Briefing on the new law
  • Identify the practical impact on you
  • Design your GDPR compliance programme
slide-3
SLIDE 3

#GenerationGDPR

GDPR background

  • What is it?
  • Why is it coming in?
  • What about Brexit?
slide-4
SLIDE 4

#GenerationGDPR

What is it?

  • Probably the most lobbied piece of EU law ever
  • Replaces the Data Protection Directive 1995 (DPD)
  • Will be enforced in Member S

tates from 25 May 2018

  • EU Member S

tate laws implementing the DPD will no longer apply

  • Creates a “ level-ish” playing field across EU
  • What is the Data Protection Bill?
slide-5
SLIDE 5

#GenerationGDPR

Why is it coming in?

Developments since 1995

  • Legal

– Case law – Regulatory triple whammy

  • Technological
  • S
  • cietal
slide-6
SLIDE 6

#GenerationGDPR

Who has to comply?

  • Controller or processor established in one or more

Member S tate

  • Controller or processor established outside the EU

and either – offering goods and services to individuals in the EU or – monitoring the behaviour of individuals taking place in the EU

slide-7
SLIDE 7

#GenerationGDPR

What about Brexit?

  • GDPR and the new Data Protection Act will apply from

May 2018 After Brexit – New Data Protection Act will apply – GDPR will apply to many UK organisations due to extra- territorial scope – GDPR will be swept up by the EU (Withdrawal) Bill 2017 – Government wishes to “ maint ain t he st abilit y of dat a t ransfer bet ween EU Member S t at es and t he UK”

slide-8
SLIDE 8

#GenerationGDPR

Key issues

  • S

cope

  • Key players

– Data subj ect – Controller – Processor – S upervisory authorities

  • What are personal data?
  • What are special categories of data?
slide-9
SLIDE 9

#GenerationGDPR

Key issues

  • Principles and accountability
  • Lawful basis for processing
  • Transparency
  • Responsibilities of controller and processors
  • International transfers
  • Rights of data subj ects
  • Breach notification
  • Enforcement and compensation
slide-10
SLIDE 10

#GenerationGDPR

Accountability

  • Compliant policies and procedures
  • Records of processing
  • DPO appointment

– Mandatory/ voluntary

  • Privacy by design/ by default
  • Data privacy impact assessments
slide-11
SLIDE 11

#GenerationGDPR

Principles

  • Principles

– Lawfulness, fairness and transparency – Purpose limitation – Data minimisation – Accuracy – S torage limitation – Integrity and confidentiality

slide-12
SLIDE 12

#GenerationGDPR

Lawful basis for processing

  • Consent
  • Necessary for the performance of a contract
  • Necessary for legal obligation
  • Necessary to protect vital interests
  • Task carried out in the public interest
  • Legitimate interests
slide-13
SLIDE 13

#GenerationGDPR

Lawful basis for processing special categories

  • Explicit consent
  • Obligat ions and right s in employment , social securit y and

social prot ect ion

  • Vit al int erest s
  • Manifest ly made public
  • Legal claims and court s
  • S

ubst ant ial public int erest

  • Medicine
  • Public healt h
  • Archiving
slide-14
SLIDE 14

#GenerationGDPR

Consent and explicit consent

  • Consent

Any freely given, specific, informed and unambiguous indicat ion of t he dat a subj ect ’ s wishes by which he or she, by a st at ement or by a clear affirmat ive act ion, signifies agreement t o t he processing of personal dat a relat ing t o him or her

  • Explicit consent
  • Re-papering consents - recital 171
  • Article 29 WP guidance
slide-15
SLIDE 15

#GenerationGDPR

Individual rights

  • Information
  • S

ubj ect access

  • Rectification
  • Erasure (Right to be forgotten)
  • Portability
  • Obj ecting
  • Compensation
  • Profiling
  • Restriction
slide-16
SLIDE 16

#GenerationGDPR

Right to information - transparency

  • Where personal data collected from data subj ect
  • Where personal data have not been obtained from

data subj ect

slide-17
SLIDE 17

#GenerationGDPR

Marketing

  • Lawful basis

– Consent – Legitimate interest

  • Re-using lists
  • Third party marketing
  • Privacy and Electronic Communications Regulations

2003

  • Draft e-Privacy Regulation
slide-18
SLIDE 18

#GenerationGDPR

Breach notification

  • Personal data breach
  • Controller breach notification

– S upervisory Authorities – Affected individuals

  • Processor breach notification

– Controller

slide-19
SLIDE 19

#GenerationGDPR

Sanctions for non-compliance

  • S

upervisory Authorities – Investigative powers – Corrective powers

  • Penalties

– 2% global turnover or €10m – 4% global turnover or €20m

  • Compensation
slide-20
SLIDE 20

#GenerationGDPR

Turning the law into practice

  • Map the law to your processing
  • Identify key data processing
  • Identify high-risk processing
  • Identify gaps
  • Mitigate the risks
slide-21
SLIDE 21

#GenerationGDPR

The team

  • Board oversight
  • Legal
  • Compliance
  • IT
  • HR
  • Marketing
  • Proj ect management
  • External advisers
slide-22
SLIDE 22

#GenerationGDPR

The plan

  • Initiation

– Awareness – Buy-in – Budget

  • Assessment

– Mapping – Gap analysis

  • Remedy
slide-23
SLIDE 23

#GenerationGDPR

Data mapping

  • Review and record in writing all processing

activities

  • Record international transfers and mechanism
slide-24
SLIDE 24

#GenerationGDPR

Data mapping

  • The 5 Ws

– Why is personal data processed? – Whose personal data is processed? – What personal data is processed? – When is personal data processed? – Where is personal data processed?

  • Questionnaire
  • Produce a risk based report
slide-25
SLIDE 25

#GenerationGDPR

Secure data and information

  • Assess security risk
  • Update information security and policy
  • Maintain security measures
slide-26
SLIDE 26

#GenerationGDPR

Third party relationships

  • Assess third party relationships

– Group – Customers – Partners – Processors

  • Appropriate contracts and controls
  • Undertake due diligence and audits
slide-27
SLIDE 27

#GenerationGDPR

Compliance culture

  • Board level issue
  • Accountability
  • Training and awareness
slide-28
SLIDE 28

#GenerationGDPR

How Browne Jacobson is supporting clients?

  • End to end GDPR reviews
  • S

coped assistance

  • Menu service
  • Ad hoc adviser
  • S

teering group member

slide-29
SLIDE 29

#GenerationGDPR

Thank you

Mark Gleeson mark.gleeson@ brownej acobson.com 020 7871 8534