SlideShare a Scribd company logo
1 of 12
GDPR – Big Bang
or Data Evolution?
OVERVIEW
 Moore Law
• What’s the fuss?
• Big Bang Theory?
• Reality = Evolution?
• Accountability
• Compliance / Privacy by Design
• Demonstrating Consent
• ‘Appropriate’ Measures
• Opportunities (& Competitive Edge)
 Contacts
What’s the Fuss?
 “GDPR affects anyone holding data on EU citizens.
A survey of 1350 companies around the world by
cybersecurity firm NTT found that a lot of them
have no clue about this yet, even Europeans
seemed unaware. The Brits were the worst. 39% of
UK companies realised that they were subject to
the regulation.” TheRegister.co.uk
 ‘Personal Data' – Employees, clients, users / suppliers
 Presumption of application to businesses
 Enhanced enforcement / fines for data protection
breaches
 Deadline for implementation = 25 May 2018
Big Bang Theory?
 1995 EU Data Protection Directive –>DPA 98
 Applies broadly to the collection and processing of data able
to identify living individuals (filing system) = ‘Person Data”
 DPA 98 introduced 6 x Data Principles:
 Lawfulness, fairness and transparency
 Purpose limitation
 Data Minimisation
 Accuracy
 Storage Limitation
 Integrity & Confidentiality
 Definitions: ‘Data Controller’ / ‘Data Processor’ / ‘Sensitive
Personal Data’/ ‘Consent’
 Roles: Data Protection Officer (DPO)
Reality = Evolution
 GDPR = accepts the world has moved and extends the existing Principles:
• All EU-based businesses
• Any business targeting EU citizens (USA, Australia, etc)
• All EU citizens
 Regulation vs Directive
• GDPR = Direct Effect
• No domestic Member State law required
• Intended to promote greater harmonisation and consistency across EU in
terms of application and interpretation
 Reverses DPA 98 position
• Register with Information Commissioner’s Office (ICO) –> inference of
application
• DPA 98 -> Data Protection Bill (Post-Brexit)
Accountability
 Accountability
• Move away from mere lip service. Businesses have to demonstrate
(ongoing) compliance, often in written form:
• Internal policies and processes that are GDPR-compliant
• Implementation of the policies and processes
• Effective internal compliance measures.
• External controls & contracting (model clauses)
 Demonstrable protections for specific types of data / subjects:
• Sensitive Personal Data (genetic, biometric)
• Children (16+ / 13+)
 Introduces new concepts
• Data Protection Risk Assessment
• Pseudonymisation (vs anonymisation) to better protect data
Compliance/
Privacy by Design
 Day-to-day compliance –> Obligation to justify data position to Regulator (ICO)
• What is the purpose the data will be used for
• Retained solely to fulfil the stated purpose
• Where it will be stored (UK / EU / EEA)
• Not keep for longer than necessary (2 years?)
• Uphold data subjects rights (right of access / right to be forgotten / data
portability)
• Data Controllers and Data Processers are treated equally (previous focus on DCs)
• Data Controllers required to perform due diligence on Data Processers (supply chain)
• DPO requirement (or justify why not have one)
 Breaches – Obligation to Report
 Regulator will look at what has happened, why, and whether ‘appropriate’ measures
put in place to safeguard data.
 ICO extended powers £500,000 -> €20,000,000 / 4% Global Turnover (+ PR DAMAGE)
 Specific (6) justifications for collecting data: performance of
contract / compliance with legal obligation / vital interests / public
interest / legitimate interests of DC / consent
• Implied consent no longer valid – ICO / pre-checked boxes /
‘continue to use our site accept our Ts&Cs’
 Have to be able to prove actual consent: ‘freely given, specific,
informed & unambiguous’
 Children: must be able to demonstrate steps to show capability
• GDPR @ 16+
• Member State discretion @ 13+ (UK)
 Death of Data
• Reassess sign-up / consent processes -> compliant
• Death of data – can’t rely on past consent for post May 2018
Demonstrating Consent
 Must be able to demonstrate ‘appropriate technical and
organisational measures’ for data compliance / protection
• Demonstrate how and why collect personal data
• ‘Consent’ / Privacy Policy / Terms & Conditions / Terms of Use
 Internal processes
• Data risk Impact Assessment / Data Use Policy / Data Retention
Policy / Employment Contracts
 Awareness of GDPR principles - Staff training / DPO (qualified)
 Contractual Relationships - GDPR model clauses incorporated
 Breach Obligations
• Requirement to log breaches
• Report to the Regulator (and potentially data subjects) within 72
hours of a notifiable breach
‘Appropriate’ Measures
 GDPR is a reality
 Brexit – GDPR continue to apply if businesses target EU will apply
• -> Data Protection Bill
• -> UK require an ‘equivalent’ regime
 Businesses need to assess own situation / audit
• how & why collect data (consent, etc) / how protect data / enforcement
policies (internal & external) / supplier terms.
 Case Studies
• Clients wanting to get their house in order – Compliance = Biz Dev
• Breach = costly (£££) + PR / Reputational risk
 Bigger businesses doing GDPR due diligence:
• expect their supply chains to have ‘adequate’ measures in place
• want to see policies (privacy / data protection / data retention)
• expect awareness of GDPR implications
• practical importance of new concepts – i.e. pseudonymisation
Opportunities
(& Competitive Edge)
 Scott Appleton
 scottappleton@moore-law.co.uk
 T 01237 704789
 M 07557 447054
 @TalkingLawyer

More Related Content

What's hot

GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
Stephanie Vasey
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
GrittyCC
 

What's hot (20)

GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshell
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
 

Similar to Scott Appleton: GDPR - Big Bang or Data Evolution?

Similar to Scott Appleton: GDPR - Big Bang or Data Evolution? (20)

GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 

Recently uploaded

一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
Airst S
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
bd2c5966a56d
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
PoojaGadiya1
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
Airst S
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
bd2c5966a56d
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 

Recently uploaded (20)

IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentation
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
 

Scott Appleton: GDPR - Big Bang or Data Evolution?

  • 1. GDPR – Big Bang or Data Evolution?
  • 2.
  • 3. OVERVIEW  Moore Law • What’s the fuss? • Big Bang Theory? • Reality = Evolution? • Accountability • Compliance / Privacy by Design • Demonstrating Consent • ‘Appropriate’ Measures • Opportunities (& Competitive Edge)  Contacts
  • 4. What’s the Fuss?  “GDPR affects anyone holding data on EU citizens. A survey of 1350 companies around the world by cybersecurity firm NTT found that a lot of them have no clue about this yet, even Europeans seemed unaware. The Brits were the worst. 39% of UK companies realised that they were subject to the regulation.” TheRegister.co.uk  ‘Personal Data' – Employees, clients, users / suppliers  Presumption of application to businesses  Enhanced enforcement / fines for data protection breaches  Deadline for implementation = 25 May 2018
  • 5. Big Bang Theory?  1995 EU Data Protection Directive –>DPA 98  Applies broadly to the collection and processing of data able to identify living individuals (filing system) = ‘Person Data”  DPA 98 introduced 6 x Data Principles:  Lawfulness, fairness and transparency  Purpose limitation  Data Minimisation  Accuracy  Storage Limitation  Integrity & Confidentiality  Definitions: ‘Data Controller’ / ‘Data Processor’ / ‘Sensitive Personal Data’/ ‘Consent’  Roles: Data Protection Officer (DPO)
  • 6. Reality = Evolution  GDPR = accepts the world has moved and extends the existing Principles: • All EU-based businesses • Any business targeting EU citizens (USA, Australia, etc) • All EU citizens  Regulation vs Directive • GDPR = Direct Effect • No domestic Member State law required • Intended to promote greater harmonisation and consistency across EU in terms of application and interpretation  Reverses DPA 98 position • Register with Information Commissioner’s Office (ICO) –> inference of application • DPA 98 -> Data Protection Bill (Post-Brexit)
  • 7. Accountability  Accountability • Move away from mere lip service. Businesses have to demonstrate (ongoing) compliance, often in written form: • Internal policies and processes that are GDPR-compliant • Implementation of the policies and processes • Effective internal compliance measures. • External controls & contracting (model clauses)  Demonstrable protections for specific types of data / subjects: • Sensitive Personal Data (genetic, biometric) • Children (16+ / 13+)  Introduces new concepts • Data Protection Risk Assessment • Pseudonymisation (vs anonymisation) to better protect data
  • 8. Compliance/ Privacy by Design  Day-to-day compliance –> Obligation to justify data position to Regulator (ICO) • What is the purpose the data will be used for • Retained solely to fulfil the stated purpose • Where it will be stored (UK / EU / EEA) • Not keep for longer than necessary (2 years?) • Uphold data subjects rights (right of access / right to be forgotten / data portability) • Data Controllers and Data Processers are treated equally (previous focus on DCs) • Data Controllers required to perform due diligence on Data Processers (supply chain) • DPO requirement (or justify why not have one)  Breaches – Obligation to Report  Regulator will look at what has happened, why, and whether ‘appropriate’ measures put in place to safeguard data.  ICO extended powers £500,000 -> €20,000,000 / 4% Global Turnover (+ PR DAMAGE)
  • 9.  Specific (6) justifications for collecting data: performance of contract / compliance with legal obligation / vital interests / public interest / legitimate interests of DC / consent • Implied consent no longer valid – ICO / pre-checked boxes / ‘continue to use our site accept our Ts&Cs’  Have to be able to prove actual consent: ‘freely given, specific, informed & unambiguous’  Children: must be able to demonstrate steps to show capability • GDPR @ 16+ • Member State discretion @ 13+ (UK)  Death of Data • Reassess sign-up / consent processes -> compliant • Death of data – can’t rely on past consent for post May 2018 Demonstrating Consent
  • 10.  Must be able to demonstrate ‘appropriate technical and organisational measures’ for data compliance / protection • Demonstrate how and why collect personal data • ‘Consent’ / Privacy Policy / Terms & Conditions / Terms of Use  Internal processes • Data risk Impact Assessment / Data Use Policy / Data Retention Policy / Employment Contracts  Awareness of GDPR principles - Staff training / DPO (qualified)  Contractual Relationships - GDPR model clauses incorporated  Breach Obligations • Requirement to log breaches • Report to the Regulator (and potentially data subjects) within 72 hours of a notifiable breach ‘Appropriate’ Measures
  • 11.  GDPR is a reality  Brexit – GDPR continue to apply if businesses target EU will apply • -> Data Protection Bill • -> UK require an ‘equivalent’ regime  Businesses need to assess own situation / audit • how & why collect data (consent, etc) / how protect data / enforcement policies (internal & external) / supplier terms.  Case Studies • Clients wanting to get their house in order – Compliance = Biz Dev • Breach = costly (£££) + PR / Reputational risk  Bigger businesses doing GDPR due diligence: • expect their supply chains to have ‘adequate’ measures in place • want to see policies (privacy / data protection / data retention) • expect awareness of GDPR implications • practical importance of new concepts – i.e. pseudonymisation Opportunities (& Competitive Edge)
  • 12.  Scott Appleton  scottappleton@moore-law.co.uk  T 01237 704789  M 07557 447054  @TalkingLawyer

Editor's Notes

  1. DPO – scale of collection / processing / size / dealing with sensitive data / public body (+ adequately qualified -> reporting to Senior Management). Justify why not.
  2. CONSIDER IF THERE IS SCOPE OR TIME TO EXPLORE REVOCATION, INVALIDITY AND GROUNDS FOR OPPOSITION. THIS WILL LIKELY FALL UNDER THE DUE DILIGENCE CATEGORY ABOVE. IT IS IMPORTANT FOR CLIENTS TO APPRECIATE THAT TRADEMARK APPLICATIONS CAN SOMETIMES DRAW ATTENTION FROM MUCH LARGER RIGHTS HOLDERS WITH DEEPER POCKETS WHO ARE AGGRESSIVE ABOUT PURSUING INFRINGERS. SMALLER ORGANISATIONS OPERATING UNDER THE RADAR MAY HAVE HITHERTO GONE UNNOTICED BUT APPLYING FOR A REGISTERED TRADEMARK MAY BRING YOU TO THEIR ATTENTION. ALSO THE POINT SHOULD BE MADE THAT IT IS NOT UNUSUAL TO BE SURPRISED BY A CAUTIOUS EXAMINER’S VIEW WHICH MIGHT INCLUDE NOTIFICATION WHERE IT WOULD NOT SEEM TO BE MERITED.
  3. Ketchup – more sales / bigger bottles = easier to use 112 iteration 1991 – 95 $13m Licensing NASA / HEINZ etc Patent Box - JCL (80% sales on patented driver)