General Data Protection Regulation – what the future holds
Zach Thornton, External Affairs Manager, DMA
@DMA_UK #dma
what the future holds Zach Thornton, External Affairs Manager, DMA - - PowerPoint PPT Presentation
@DMA_UK #dma General Data Protection Regulation what the future holds Zach Thornton, External Affairs Manager, DMA EU Data Protection reform where are we? Dec 2015 Political agreement reached on text Apr 2016 Justice and Home
@DMA_UK #dma
Political agreement reached on text
Justice and Home Ministers sign off
European Parliament signs off
What kind of UK- EU trade deal?
legislation
countries will require equivalent data protection legislation
EU
therefore at minimum would need to have equivalent data protection laws to EU in order for Brussels to grant UK at minimum Adequacy Status under GDPR
consistency around data protection laws and individual rights is crucial. Need to comply with GDPR
appropriately
Member States) will issue Guidance Notes – ICO published draft timetable
have GDPR change management unit
protection throughout the EU a reality. This is a great success for the European Parliament and a fierce European 'yes' to strong consumer rights and competition in the digital age. Citizens will be able to decide for themselves which personal information they want to share".
law across the EU. The new law creates confidence, legal certainty and fairer competition"
Consent: Current Position (1995 Directive) Consent: GDPR Position
informed indication of the data subject’s wishes
for sensitive personal data only
and unambiguous indication of data subject’s wishes
clear affirmative action
relationship to be taken into account
demonstrate consent
marketing
Directive remain the same for first party and third party marketing
not a third party
through a re-permissioning exercise.
requirements
rights of organisations
direct marketing activities
customers and registered prospects will receive
use
and cookies as “online identifiers” (Article 4 (1)
general
addresses, cookies, online identifiers
exceptions?
personal data
new rules on profiling.
legal effects concerning the individual or similarly significantly affects the individual. The right to unsubscribe/opt-out does not apply if the decision
individual and the data controller – an example of this would be credit-scoring if an individual applied for a new credit card or an increase in their credit limit
marketing
decision
right to object principle
individuals
rights and freedoms of individuals
individuals within timescale is agreed
any charge
frivolous or vexatious requests
individual requests hard copy (Article 15.3)
management firms
laundering
allows and cost not prohibitive.
request information (Data Subject Access Requests, Right to erasure)
Regulation or acted outside or contrary to lawful instructions of controller
monitoring of individuals on a large scale or large scale processing of sensitive personal data (Articles 37-39)
data on EU citizens
in respect of