GDPR
T
- wards Compliance – 25 May 2018
GDPR T owards Compliance 25 May 2018 Wha hat t is GDPR? EU Data - - PowerPoint PPT Presentation
GDPR T owards Compliance 25 May 2018 Wha hat t is GDPR? EU Data Protection Directive EU General Data Protection 1995 Regulation 2016 Data Protection Act 1998 Data Protection Bill 2017-19 Fines DPA GDPR Maximum Fine 500k Two
EU Data Protection Directive 1995 Data Protection Act 1998 EU General Data Protection Regulation 2016 Data Protection Bill 2017-19
repeated breaches
depending on type of breach, the higher of:
6 Principles 1. Lawfulness, transparency and fairness 2. Purpose limitation 3. Data minimisation 4. Accuracy 5. Storage limitation 6. Integrity and confidentiality
New requirement for Data Controllers to be able to demonstrate, compliance with the principles including:
Assessments where high risk processing takes place
Result = Extensive added record keeping burden
individual
added controls
identifying an individual directly or indirectly, includes images
special categories of data includes genetic and biometric data
inaction
not valid unless separate consents for each activity
needed to be fair
transparent
provided at the time of collection of personal data
indirectly, have to provide at first contact or within one month
Subject Access Request
Subject Access Request
any time
marketing
decision making
ICO
hours
subjects
includes accidental loss, alteration or destruction
liability for fines
processor have direct liability for fines
damages
as ‘vulnerable individuals’
addressed to a child should be ‘child friendly’
mechanisms must be implemented
Discover Identify personal data & where it resides Manage Governance of how personal data is used Protect Security controls to prevent breaches Report Compliance documentation & reports
category?
passing data to third parties
British Rowing
British Rowing 6 Lower Mall, Hammersmith London W6 9DJ
Scope: Whole Company
Complies with the requirements of the Cyber Essentials Scheme
Date of Certification: 15th January 2018 Recertification Due: Jan 2019 Certificate Number: IASME-A-04961 Profile Published: February 2017
This Certificate certifies that the organisation nam ed was assessed as m eeting the Cyber Essentials im plem entation profile published in February 2017 and thus that, at the tim e of testing, the
m
However, this Certificate does not in any way guarantee that the organisations defences will rem ain satisfactory against cyber attack.
Certification Body: Assessor: Marcus Dempsey Accreditation Body: