SlideShare a Scribd company logo
1 of 20
Fintan Swanton
Cygnus Consulting
15 December 2016
 The General Data Protection Regulation is
the most extensive change to EU data
protection law since the 1995 directive.
 In 1995, Mark Zuckerberg was eleven years
old . . .
GDPR passed by European
Parliament in April 2016.
To come into effect on
25 May, 2018 in all member
states.
REGULATION (EU) 2016/679 OF
THE EUROPEAN PARLIAMENT AND
OF THE COUNCIL of 27 April 2016
on the protection of natural
persons with regard to the
processing of personal data and on
the free movement of such data,
and repealing Directive 95/46/EC
Personal data must:
1. Be fairly obtained & processed
2. For specified, explicit &
legitimate purpose(s)
3. Not be processed in a manner
incompatible with those
purpose(s)
4. Be kept safe & secure
5. Be kept accurate, complete &
up-to-date
6. Be adequate, relevant & not
excessive
7. Not be retained for longer than
is necessary
8. Be provided on request to the
data subject
 Definition of personal
data
 Accountability
 Consent
 Access requests
 Joint data controllership
 Controller / Processor
relationship
 Breach notification
 Data Protection Impact
Assessments
 Mandatory Data
Protection Officers
 Right to compensation
and liability
 Financial penalties
Current definition:
Data relating to a
living individual who is
or can be identified
either from the data
or from the data in
conjunction with other
information that is in,
or is likely to come
into the possession of
the Data Controller.
S.1 Data Protection Act, 1988
GDPR redefinition:
any information
relating to ... an
identified natural
person or a natural
person who can be
identified, directly or
indirectly, by means
reasonably likely to be
used by the controller
or by any other natural
or legal person...
Art. 4(1), GDPR
The controller
shall be
responsible for
and be able to
demonstrate
compliance ...
Art. 5.2
“any freely given,
specific, informed and
unambiguous indication
of… wishes…”
Must be given “by a
statement or by a clear
affirmative action
signifying agreement”
Art. 4(11)
 No fee unless request “manifestly
unfounded or excessive”
 Requests can be made and must,
where appropriate, be responded
to electronically
 Standard time limit 1 month
 May take up to 3 months, but must
notify data subject within 1
month, giving reasoned
justification for delay
 As well as personal data, other
info. such as sources, processing
purposes & right to complain to
DPA must be provided.
Art. 12 & 15 Janet McKnight
Where two or more controllers jointly
determine the purposes and means of the
processing of personal data, they are joint
controllers.
They shall in a transparent manner
determine their respective responsibilities
for compliance with the obligations under
this Regulation.
Art. 26
The carrying out of processing by a
processor shall be governed by a contract
or other legal act under Union or Member
State law, binding the processor to the
controller, setting out the subject matter
and duration of the processing, the
nature and purpose of the processing,
the type of personal data and categories
of data subjects.
The processor and any person acting under
the authority of the controller or of the
processor who has access to personal data
shall not process them except on
instructions from the controller, unless
required to do so by Union or Member
State law.
Art. 28
11
In the case of a personal data breach, the controller
shall without undue delay and, where feasible, not
later than 72 hours after having become aware of it,
notify the personal data breach to the supervisory
authority, unless the personal data breach is unlikely
to result in a risk for the rights and freedoms of
individuals. The notification to the supervisory
authority shall be accompanied by a reasoned
justification in cases where it is not made within 72
hours.
When the personal data breach is likely to result in a
high risk for the rights and freedoms of individuals
the controller shall communicate the personal data
breach to the data subject without undue delay.
Art. 33
 DPIA is mandatory “where processing is likely to
result in a high risk”.
 DPIA must include at least:
 systematic description of envisaged processing and
the purposes of the processing, including where
applicable the legitimate interest pursued;
 assessment of necessity and proportionality of
processing;
 assessment of the risks to the rights and freedoms
of data subjects;
 measures envisaged to address the risks.
 Controller must consult DPA where processing would
result in high risk in absence of mitigating measures.
Art. 35
The controller or processor must designate a data protection officer in
any case where:
 the processing is carried out by a public authority or body; or
 the core activities of the controller or processor consist of
processing operations which because of their nature, scope or their
purposes, require regular and systematic monitoring of data
subjects on a large scale; or
 the core activities of the controller or the processor consist of
processing on a large scale of sensitive personal data.
 A group of undertakings may appoint a single data protection officer
provided that a data protection officer is easily accessible from each
establishment
 Where the controller or processor is a public authority or body, a
single data protection officer may be designated for several of them,
taking account of their organisational structure and size.
Art. 37, 38 & 39
 DPOs must have “expert” knowledge,
training and experience.
 DPOs must report directly to the
highest level of management.
 DPOs must be completely
independent in the performance of
their duties.
 DPOs may be directly employed staff
or external service providers.
 DPOs must be involved in a proper
and timely manner in all
organisational personal data
protection matters.Office of the Privacy Commissioner Canada
DPOs shall have at least these tasks:
 Informing and advising the
organisation and its staff on
compliance.
 Monitoring organisational data
protection compliance.
 Advising on data protection impact
assessments.
 Acting as the contact point for and
cooperating with the DPC.
 Acting as the contact point for data
subjects.
 May have other duties, provided they
aren’t incompatible with DPO role.Office of the Privacy Commissioner Canada
Current situation:
Collins v FBD Insurance
(Ireland)
Google v Vidal-Hall (UK)
In the GDPR:
Any person who has
suffered material or
non-material damage as
a result of an
infringement of this
Regulation shall have
the right to receive
compensation from the
controller or processor
for the damage
suffered.
Art 82.1
Where more than one controller or
processor or a controller and a processor
are involved in the same processing and,
where they are responsible for any
damage caused by the processing ... each
controller or processor shall be held
liable for the entire damage, in order to
ensure effective compensation of the
data subject.
Art 82.4
Two tier structure:
 Greater of €10m or 2% of turnover
 Greater of €20m or 4% of turnover
Each supervisory authority shall
ensure that the imposition of
administrative fines . . . shall in each
individual case be effective,
proportionate and dissuasive.
Art. 83
Most infringements in principle subject to
fines
Cygnus Consulting Limited
Data Protection Consultancy & Training
info@cygnus.ie
www.cygnus.ie
01 6854474 / 086 8271273

More Related Content

What's hot

Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findwise
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Stephanie Vasey
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance Tom Haynes
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017isc2-hellenic
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPRTripwire
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...eHealth Forum
 

What's hot (20)

Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPR
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 

Similar to GDPR - Fail to Prepare, Prepare to Fail!

General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary Compliance3
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfDaviesParker
 
Group 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptxGroup 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptxStephenQuijano3
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360DataStax
 
20131008 agoria big data vs data protection
20131008 agoria big data vs data protection20131008 agoria big data vs data protection
20131008 agoria big data vs data protectionJos Dumortier
 
Data protection regulation
Data protection regulationData protection regulation
Data protection regulationGreg Ezeilo
 
Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17Georges Ataya
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPRAfraAlZadjali
 

Similar to GDPR - Fail to Prepare, Prepare to Fail! (20)

General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
GDPR
GDPRGDPR
GDPR
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
Group 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptxGroup 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptx
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360
 
20131008 agoria big data vs data protection
20131008 agoria big data vs data protection20131008 agoria big data vs data protection
20131008 agoria big data vs data protection
 
Data protection regulation
Data protection regulationData protection regulation
Data protection regulation
 
Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPR
 

Recently uploaded

Real-Time AI Streaming - AI Max Princeton
Real-Time AI  Streaming - AI Max PrincetonReal-Time AI  Streaming - AI Max Princeton
Real-Time AI Streaming - AI Max PrincetonTimothy Spann
 
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDINTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDRafezzaman
 
Student profile product demonstration on grades, ability, well-being and mind...
Student profile product demonstration on grades, ability, well-being and mind...Student profile product demonstration on grades, ability, well-being and mind...
Student profile product demonstration on grades, ability, well-being and mind...Seán Kennedy
 
IMA MSN - Medical Students Network (2).pptx
IMA MSN - Medical Students Network (2).pptxIMA MSN - Medical Students Network (2).pptx
IMA MSN - Medical Students Network (2).pptxdolaknnilon
 
Predictive Analysis for Loan Default Presentation : Data Analysis Project PPT
Predictive Analysis for Loan Default  Presentation : Data Analysis Project PPTPredictive Analysis for Loan Default  Presentation : Data Analysis Project PPT
Predictive Analysis for Loan Default Presentation : Data Analysis Project PPTBoston Institute of Analytics
 
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort servicejennyeacort
 
Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...
Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...
Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...ssuserf63bd7
 
modul pembelajaran robotic Workshop _ by Slidesgo.pptx
modul pembelajaran robotic Workshop _ by Slidesgo.pptxmodul pembelajaran robotic Workshop _ by Slidesgo.pptx
modul pembelajaran robotic Workshop _ by Slidesgo.pptxaleedritatuxx
 
Heart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis ProjectHeart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis ProjectBoston Institute of Analytics
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Cantervoginip
 
Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...
Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...
Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...Thomas Poetter
 
LLMs, LMMs, their Improvement Suggestions and the Path towards AGI
LLMs, LMMs, their Improvement Suggestions and the Path towards AGILLMs, LMMs, their Improvement Suggestions and the Path towards AGI
LLMs, LMMs, their Improvement Suggestions and the Path towards AGIThomas Poetter
 
毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...
毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...
毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...ttt fff
 
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样vhwb25kk
 
How we prevented account sharing with MFA
How we prevented account sharing with MFAHow we prevented account sharing with MFA
How we prevented account sharing with MFAAndrei Kaleshka
 
毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree
毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree
毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degreeyuu sss
 
Top 5 Best Data Analytics Courses In Queens
Top 5 Best Data Analytics Courses In QueensTop 5 Best Data Analytics Courses In Queens
Top 5 Best Data Analytics Courses In Queensdataanalyticsqueen03
 
Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...
Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...
Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...Boston Institute of Analytics
 
Learn How Data Science Changes Our World
Learn How Data Science Changes Our WorldLearn How Data Science Changes Our World
Learn How Data Science Changes Our WorldEduminds Learning
 
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一F La
 

Recently uploaded (20)

Real-Time AI Streaming - AI Max Princeton
Real-Time AI  Streaming - AI Max PrincetonReal-Time AI  Streaming - AI Max Princeton
Real-Time AI Streaming - AI Max Princeton
 
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDINTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
 
Student profile product demonstration on grades, ability, well-being and mind...
Student profile product demonstration on grades, ability, well-being and mind...Student profile product demonstration on grades, ability, well-being and mind...
Student profile product demonstration on grades, ability, well-being and mind...
 
IMA MSN - Medical Students Network (2).pptx
IMA MSN - Medical Students Network (2).pptxIMA MSN - Medical Students Network (2).pptx
IMA MSN - Medical Students Network (2).pptx
 
Predictive Analysis for Loan Default Presentation : Data Analysis Project PPT
Predictive Analysis for Loan Default  Presentation : Data Analysis Project PPTPredictive Analysis for Loan Default  Presentation : Data Analysis Project PPT
Predictive Analysis for Loan Default Presentation : Data Analysis Project PPT
 
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
 
Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...
Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...
Statistics, Data Analysis, and Decision Modeling, 5th edition by James R. Eva...
 
modul pembelajaran robotic Workshop _ by Slidesgo.pptx
modul pembelajaran robotic Workshop _ by Slidesgo.pptxmodul pembelajaran robotic Workshop _ by Slidesgo.pptx
modul pembelajaran robotic Workshop _ by Slidesgo.pptx
 
Heart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis ProjectHeart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis Project
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Canter
 
Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...
Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...
Minimizing AI Hallucinations/Confabulations and the Path towards AGI with Exa...
 
LLMs, LMMs, their Improvement Suggestions and the Path towards AGI
LLMs, LMMs, their Improvement Suggestions and the Path towards AGILLMs, LMMs, their Improvement Suggestions and the Path towards AGI
LLMs, LMMs, their Improvement Suggestions and the Path towards AGI
 
毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...
毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...
毕业文凭制作#回国入职#diploma#degree美国加州州立大学北岭分校毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#de...
 
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
 
How we prevented account sharing with MFA
How we prevented account sharing with MFAHow we prevented account sharing with MFA
How we prevented account sharing with MFA
 
毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree
毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree
毕业文凭制作#回国入职#diploma#degree澳洲中央昆士兰大学毕业证成绩单pdf电子版制作修改#毕业文凭制作#回国入职#diploma#degree
 
Top 5 Best Data Analytics Courses In Queens
Top 5 Best Data Analytics Courses In QueensTop 5 Best Data Analytics Courses In Queens
Top 5 Best Data Analytics Courses In Queens
 
Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...
Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...
Data Analysis Project : Targeting the Right Customers, Presentation on Bank M...
 
Learn How Data Science Changes Our World
Learn How Data Science Changes Our WorldLearn How Data Science Changes Our World
Learn How Data Science Changes Our World
 
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
 

GDPR - Fail to Prepare, Prepare to Fail!

  • 2.  The General Data Protection Regulation is the most extensive change to EU data protection law since the 1995 directive.  In 1995, Mark Zuckerberg was eleven years old . . . GDPR passed by European Parliament in April 2016. To come into effect on 25 May, 2018 in all member states.
  • 3. REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
  • 4. Personal data must: 1. Be fairly obtained & processed 2. For specified, explicit & legitimate purpose(s) 3. Not be processed in a manner incompatible with those purpose(s) 4. Be kept safe & secure 5. Be kept accurate, complete & up-to-date 6. Be adequate, relevant & not excessive 7. Not be retained for longer than is necessary 8. Be provided on request to the data subject
  • 5.  Definition of personal data  Accountability  Consent  Access requests  Joint data controllership  Controller / Processor relationship  Breach notification  Data Protection Impact Assessments  Mandatory Data Protection Officers  Right to compensation and liability  Financial penalties
  • 6. Current definition: Data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into the possession of the Data Controller. S.1 Data Protection Act, 1988 GDPR redefinition: any information relating to ... an identified natural person or a natural person who can be identified, directly or indirectly, by means reasonably likely to be used by the controller or by any other natural or legal person... Art. 4(1), GDPR
  • 7. The controller shall be responsible for and be able to demonstrate compliance ... Art. 5.2
  • 8. “any freely given, specific, informed and unambiguous indication of… wishes…” Must be given “by a statement or by a clear affirmative action signifying agreement” Art. 4(11)
  • 9.  No fee unless request “manifestly unfounded or excessive”  Requests can be made and must, where appropriate, be responded to electronically  Standard time limit 1 month  May take up to 3 months, but must notify data subject within 1 month, giving reasoned justification for delay  As well as personal data, other info. such as sources, processing purposes & right to complain to DPA must be provided. Art. 12 & 15 Janet McKnight
  • 10. Where two or more controllers jointly determine the purposes and means of the processing of personal data, they are joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation. Art. 26
  • 11. The carrying out of processing by a processor shall be governed by a contract or other legal act under Union or Member State law, binding the processor to the controller, setting out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects. The processor and any person acting under the authority of the controller or of the processor who has access to personal data shall not process them except on instructions from the controller, unless required to do so by Union or Member State law. Art. 28 11
  • 12. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority, unless the personal data breach is unlikely to result in a risk for the rights and freedoms of individuals. The notification to the supervisory authority shall be accompanied by a reasoned justification in cases where it is not made within 72 hours. When the personal data breach is likely to result in a high risk for the rights and freedoms of individuals the controller shall communicate the personal data breach to the data subject without undue delay. Art. 33
  • 13.  DPIA is mandatory “where processing is likely to result in a high risk”.  DPIA must include at least:  systematic description of envisaged processing and the purposes of the processing, including where applicable the legitimate interest pursued;  assessment of necessity and proportionality of processing;  assessment of the risks to the rights and freedoms of data subjects;  measures envisaged to address the risks.  Controller must consult DPA where processing would result in high risk in absence of mitigating measures. Art. 35
  • 14. The controller or processor must designate a data protection officer in any case where:  the processing is carried out by a public authority or body; or  the core activities of the controller or processor consist of processing operations which because of their nature, scope or their purposes, require regular and systematic monitoring of data subjects on a large scale; or  the core activities of the controller or the processor consist of processing on a large scale of sensitive personal data.  A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment  Where the controller or processor is a public authority or body, a single data protection officer may be designated for several of them, taking account of their organisational structure and size. Art. 37, 38 & 39
  • 15.  DPOs must have “expert” knowledge, training and experience.  DPOs must report directly to the highest level of management.  DPOs must be completely independent in the performance of their duties.  DPOs may be directly employed staff or external service providers.  DPOs must be involved in a proper and timely manner in all organisational personal data protection matters.Office of the Privacy Commissioner Canada
  • 16. DPOs shall have at least these tasks:  Informing and advising the organisation and its staff on compliance.  Monitoring organisational data protection compliance.  Advising on data protection impact assessments.  Acting as the contact point for and cooperating with the DPC.  Acting as the contact point for data subjects.  May have other duties, provided they aren’t incompatible with DPO role.Office of the Privacy Commissioner Canada
  • 17. Current situation: Collins v FBD Insurance (Ireland) Google v Vidal-Hall (UK) In the GDPR: Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered. Art 82.1
  • 18. Where more than one controller or processor or a controller and a processor are involved in the same processing and, where they are responsible for any damage caused by the processing ... each controller or processor shall be held liable for the entire damage, in order to ensure effective compensation of the data subject. Art 82.4
  • 19. Two tier structure:  Greater of €10m or 2% of turnover  Greater of €20m or 4% of turnover Each supervisory authority shall ensure that the imposition of administrative fines . . . shall in each individual case be effective, proportionate and dissuasive. Art. 83 Most infringements in principle subject to fines
  • 20. Cygnus Consulting Limited Data Protection Consultancy & Training info@cygnus.ie www.cygnus.ie 01 6854474 / 086 8271273

Editor's Notes

  1. Bruno Gencarelli, Head of Data Protection Unit, DG Justice
  2. Not exhaustive - “edited highlights”
  3. Leap Card & Eircode
  4. Documented policies, standards & procedures, with evidence that they’re adhered to.
  5. Think about WhatsApp and Uber - no “opt out”
  6. Electronic response where electronic request, unless data subject indicates otherwise [HOLD!] Do exercise on p. 55 of Manual
  7. L/A & Gardai re CCTV.
  8. Other specific detail needed in contract, such as undertakings to follow instructions, assist with exercise by data subjects of rights, destruction of data on termination, etc
  9. Core activities - main revenue generating activities?
  10. DPO is not a mini DPA
  11. Bavaria and the IT Manager, HR, internal audit - IAPP estimate
  12. BTW, no personal liability in GDPR
  13. Emphasise main risk is not enforcement, e.g., TalkTalk.