Raising Awareness
- f the
Raising Awareness of the General Data Protection Regulations - - PowerPoint PPT Presentation
Raising Awareness of the General Data Protection Regulations (GDPR) Workshop aims are to: Provide an introduction to the GDPR Explore how the GDPR will impact on Early Years settings Highlight resources available to support Early
www.images.google.com
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
https://virtual-college.typeform.com/to/YHmCIO GDPR quiz - are you prepared for the changes
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR quiz - are you prepared for the changes: https://virtual-college.typeform.com/to/YHmCIO
GDPR principles
They are:
and must do it in a fair and transparent way.
to keep it up to date.
These privacy principles are supported by a further principle – accountability.
thing with data but must also show that all the correct measures are in place to demonstrate how compliance is achieved.
training is going to be a key part of any effective compliance programme.
Data Protection Officers (DPO)
data protection obligations,
authority.
resourced, and report to the highest management level. However, can be an existing employee or externally appointed.
between them.
enhanced focus on accountability.
Data Controller
persons) determines the purposes for which and the manner in which any personal data are, or are to be processed Data Processor
employee of the data controller) who processes the data on behalf of the data controller. “Processing”, in relation to information or data means obtaining, recording or holding the information or data or carrying out any
…data which relate to a living individual who can be identified – (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller
transparently
legitimate purpose
limited to what is necessary
4. Accurate and, where necessary, kept up to date
taken
for the purpose 6. Appropriate technical and organisational measures
Privacy notice
collected?
ico.org.uk/for-organisations/guide-to-data- protection/privacy-notices-transparency-and- control/
look at how they gather, hold, and share any personally identifiable information, which includes anything that can be used to identify a specific person.
taking steps within your setting to make sure all data and information is secure.
www.images.google.com
appointing an individual who takes the lead on data compliance will be enough, although for larger early years provider chains may need to appoint a Data Protection Officer (DPO).
exactly how you are going to use it, who might you share it with, how long you will keep it as well as information on consent and complaint.
the collection, access and deletion of their data so you must ensure your setting has mechanisms to allow individuals to exercise these rights.
have a legitimate reason for processing any personal data. Where you rely on consent for processing data you must be able to demonstrate that the consent was freely given. Pre-ticked boxes or inactivity will no longer suffice. People will have to actively opt-in.
processing data for them. Providers must make sure that anyone processing data will meet GDPR requirements.
https://ico.org.uk/for-organisations/data-protection-reform/
ico.org.uk/for-organisations/education/