SlideShare a Scribd company logo
1 of 25
GDPR and
The Company Secretary
Helen Dixon
Data Protection Commissioner
@DPCIreland
1
www.dataprotection.ie
2
CLEAR RATIONALE FOR NEW DATA
PROTECTION LAWS IN EUROPE
Article 8 :
Protection of
personal data
Charter of Fundamental Rights
3
4th Industrial Revolution
5
Revolution or Evolution ?
6
GDPR Text and EU Data Protection APP
7
173 Recitals
(not having
force of law)
11 Chapters
99 Articles
(having full
force of law)
8
Focus of the GDPR
Giving Data
Subjects more
control
Making Data
Controllers/Proce
ssors more
accountable
Making
personal data
processing
more
transparent
Reducing
personal data
security
vulnerabilities
Co-operation
between
Supervisory
Authorities on
cross-border
processing
9
The 8 Principles of Data Protection
Obtain and
process
information
fairly
Keep it
only for
one or
more
specified,
explicit
and lawful
purposes
Use and
disclose it
only in
ways
compatible
with these
purposes
Keep it
safe and
secure
Keep it
accurate,
complete
and up-
to-date
Ensure
that it is
adequate,
relevant
and not
excessive
Retain it
for no
longer
than is
necessary
for the
purpose
or
purposes
Give a
copy of
his/her
personal
data to
that
individual
on
request
Data Integrity
Pseudonymisation
Anonymization
Cryptography
Accountability
Data Protection
Officer
Data Protection
Impact
Assessments
Data minimisation
Notification of
Personal Data
Breaches
11
What’s new in GDPR?
Accountability
–
demonstrating
compliance
Transparency
– providing
information
pre-processing
Risk-based
mandatory
data breach
reporting (72
hours)
Strengthened
‘Consent’
obligations
New and
enhanced Data
Subject rights
Administrative
Fines
Data
Protection
Officer (DPO)
for certain
organisations
12
Article 24.1
“….the controller shall implement appropriate technical and
organizational measures to ensure and to be able to
demonstrate that processing is performed in accordance with
this Regulation”
Article 24.3
“Adherence to approved codes of conduct as referred to in
Article 40 or approved certification mechanisms as referred to
in Article 42 may be used as an element by which to
demonstrate compliance with the obligations of the controller”
13
Data Protection Officer (Articles 37, 38 & 39)
 Public Authority or Body
 Core activities consist of processing
operations which require regular
and systematic monitoring of data
subjects on a large scale
 Processing on a large scale of
special categories of data (Articles
9 and 10)
14
Demonstrating Accountability
Privacy by Design
Privacy by Default
Data Protection Impact
Assessment (DPIA)
Codes of Conduct
Certification
15
Notification to Supervising Authority
Notification to
Supervising
Authority
within 72 hours
Unless “unlikely to
result in a risk to the
rights and freedoms
of natural persons”
‘Risk’ might include, for
example, a risk of
identity theft or
anything likely to lead
to a financial loss for
the data subject
16
Breach Communication to Data Subject
 “when the personal data breach is likely
to result in a high risk to the rights and
freedoms of natural persons”
 “the data controller shall communicate
the personal data breach to the data
subject without undue delay”
 ‘High Risk’ – higher threshold than report
to SA
17
New and Enhanced Data Subject Rights
Right to data portability
Right to be informed
Right to rectification
Right of access
Right of erasure
Right to be forgotten (search engine de-indexing)
Right to restrict processing
Right to object to processing
18
Transparency Requirements
• Identity of controller and DPO
• Purpose of processing and legal basis
• Recipients of the data
• Data transfer arrangements
• Retention period
• Right of access
• Right to withdraw consent
• Right to lodge complaint with SA
• Details of the contractual or statutory
basis
• Details of automated decision-making
At the time
when
personal
data are
obtained
provide the
data subject
with
information
on; 19
Transparency
Article 12
“The controller shall take appropriate
measures to provide any
information……..relating to processing
to the data subject in a concise,
transparent, intelligible and easily
accessible form, using clear and plain
language, in particular for any
information addressed specifically to a
child”
20
Administrative Fines
Article 83
Up to €20m or
4% of global
turnover for
the preceding
financial year
21
A Resourced and Effective Regulator
22
Get
Data
Protection
Ready
Thank you
www.dataprotection.ie
Q&A – Guest Panel
• Helen Dixon, Data Protection Commissioner of Ireland
• Denis Kelleher, Senior Legal Counsel, the Central Bank of Ireland
• David Cullen, Partner and Head of Technology, William Fry
Closing Address
• Ruairí Cosgrove President of the Irish Council of ICSA

More Related Content

What's hot

What does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businessesWhat does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businessesiFactory Digital
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year onInsight Data
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Aoife Flynn
 
Revision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptxRevision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptxBreach_P
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?TAG Alliances
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityARDC
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!Fintan Swanton
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Data protection policy alex clapson 20-11-17
Data protection policy   alex clapson 20-11-17Data protection policy   alex clapson 20-11-17
Data protection policy alex clapson 20-11-17Alex Clapson
 
Gdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework ELGdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework ELEugene Lee
 

What's hot (20)

What does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businessesWhat does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businesses
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year on
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017
 
Revision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptxRevision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptx
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
SAP Business One
SAP Business OneSAP Business One
SAP Business One
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research community
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Data protection policy alex clapson 20-11-17
Data protection policy   alex clapson 20-11-17Data protection policy   alex clapson 20-11-17
Data protection policy alex clapson 20-11-17
 
Gdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework ELGdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework EL
 

Similar to ICSA Irish Region General Data Protection Regulation event, 10 October 2017

GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical OverviewErnest Staats
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018Surabhi Jain
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsPriyanka Aash
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness WorkshopPaul Jacobson
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4Wynthorpe
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationN N
 

Similar to ICSA Irish Region General Data Protection Regulation event, 10 October 2017 (20)

Transparency gdpr
Transparency    gdprTransparency    gdpr
Transparency gdpr
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
GDPR
GDPRGDPR
GDPR
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 

More from Institute of Chartered Secretaries and Administrators

More from Institute of Chartered Secretaries and Administrators (20)

Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
 
ICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slidesICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slides
 
ICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slidesICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slides
 
Risk Management and the Company Secretary
Risk Management and the Company Secretary Risk Management and the Company Secretary
Risk Management and the Company Secretary
 
Board effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluationBoard effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluation
 
ICSA qualifying programme update 2019
ICSA qualifying programme update 2019 ICSA qualifying programme update 2019
ICSA qualifying programme update 2019
 
ICSA CPD - Cyber breaches
ICSA CPD -   Cyber breachesICSA CPD -   Cyber breaches
ICSA CPD - Cyber breaches
 
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
 
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
 
ICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight TechnologiesICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight Technologies
 
ICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 MayICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 May
 
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
 
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
 
ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018
 
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
 
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
 
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
 
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
 
Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017
 
Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017 Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017
 

Recently uploaded

Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceCunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceHigh Profile Call Girls
 
13875446-Ballistic Missile Trajectories.ppt
13875446-Ballistic Missile Trajectories.ppt13875446-Ballistic Missile Trajectories.ppt
13875446-Ballistic Missile Trajectories.pptsilvialandin2
 
Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012
Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012
Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012rehmti665
 
Building the Commons: Community Archiving & Decentralized Storage
Building the Commons: Community Archiving & Decentralized StorageBuilding the Commons: Community Archiving & Decentralized Storage
Building the Commons: Community Archiving & Decentralized StorageTechSoup
 
Enhancing Indigenous Peoples' right to self-determination in the context of t...
Enhancing Indigenous Peoples' right to self-determination in the context of t...Enhancing Indigenous Peoples' right to self-determination in the context of t...
Enhancing Indigenous Peoples' right to self-determination in the context of t...Christina Parmionova
 
VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...
VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...
VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...Suhani Kapoor
 
Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...
Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...
Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...ankitnayak356677
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27JSchaus & Associates
 
No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...
No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...
No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...narwatsonia7
 
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up NumberMs Riya
 
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...narwatsonia7
 
How the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersHow the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersCongressional Budget Office
 
productionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptxproductionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptxHenryBriggs2
 
(怎样办)Sherbrooke毕业证本科/硕士学位证书
(怎样办)Sherbrooke毕业证本科/硕士学位证书(怎样办)Sherbrooke毕业证本科/硕士学位证书
(怎样办)Sherbrooke毕业证本科/硕士学位证书mbetknu
 
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best ServicesMadurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Servicesnajka9823
 
Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.Christina Parmionova
 
(官方原版办理)BU毕业证国外大学毕业证样本
(官方原版办理)BU毕业证国外大学毕业证样本(官方原版办理)BU毕业证国外大学毕业证样本
(官方原版办理)BU毕业证国外大学毕业证样本mbetknu
 

Recently uploaded (20)

Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceCunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
 
13875446-Ballistic Missile Trajectories.ppt
13875446-Ballistic Missile Trajectories.ppt13875446-Ballistic Missile Trajectories.ppt
13875446-Ballistic Missile Trajectories.ppt
 
Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012
Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012
Call Girls Connaught Place Delhi reach out to us at ☎ 9711199012
 
Building the Commons: Community Archiving & Decentralized Storage
Building the Commons: Community Archiving & Decentralized StorageBuilding the Commons: Community Archiving & Decentralized Storage
Building the Commons: Community Archiving & Decentralized Storage
 
Enhancing Indigenous Peoples' right to self-determination in the context of t...
Enhancing Indigenous Peoples' right to self-determination in the context of t...Enhancing Indigenous Peoples' right to self-determination in the context of t...
Enhancing Indigenous Peoples' right to self-determination in the context of t...
 
VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...
VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...
VIP High Profile Call Girls Gorakhpur Aarushi 8250192130 Independent Escort S...
 
Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...
Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...
Greater Noida Call Girls 9711199012 WhatsApp No 24x7 Vip Escorts in Greater N...
 
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCeCall Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27
 
No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...
No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...
No.1 Call Girls in Basavanagudi ! 7001305949 ₹2999 Only and Free Hotel Delive...
 
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
 
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
 
How the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersHow the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists Lawmakers
 
productionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptxproductionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptx
 
The Federal Budget and Health Care Policy
The Federal Budget and Health Care PolicyThe Federal Budget and Health Care Policy
The Federal Budget and Health Care Policy
 
(怎样办)Sherbrooke毕业证本科/硕士学位证书
(怎样办)Sherbrooke毕业证本科/硕士学位证书(怎样办)Sherbrooke毕业证本科/硕士学位证书
(怎样办)Sherbrooke毕业证本科/硕士学位证书
 
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best ServicesMadurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
 
Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.
 
(官方原版办理)BU毕业证国外大学毕业证样本
(官方原版办理)BU毕业证国外大学毕业证样本(官方原版办理)BU毕业证国外大学毕业证样本
(官方原版办理)BU毕业证国外大学毕业证样本
 
Hot Sexy call girls in Palam Vihar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Palam Vihar🔝 9953056974 🔝 escort ServiceHot Sexy call girls in Palam Vihar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Palam Vihar🔝 9953056974 🔝 escort Service
 

ICSA Irish Region General Data Protection Regulation event, 10 October 2017

  • 1. GDPR and The Company Secretary Helen Dixon Data Protection Commissioner @DPCIreland 1 www.dataprotection.ie
  • 2. 2
  • 3. CLEAR RATIONALE FOR NEW DATA PROTECTION LAWS IN EUROPE Article 8 : Protection of personal data Charter of Fundamental Rights 3
  • 5. 5
  • 7. GDPR Text and EU Data Protection APP 7
  • 8. 173 Recitals (not having force of law) 11 Chapters 99 Articles (having full force of law) 8
  • 9. Focus of the GDPR Giving Data Subjects more control Making Data Controllers/Proce ssors more accountable Making personal data processing more transparent Reducing personal data security vulnerabilities Co-operation between Supervisory Authorities on cross-border processing 9
  • 10. The 8 Principles of Data Protection Obtain and process information fairly Keep it only for one or more specified, explicit and lawful purposes Use and disclose it only in ways compatible with these purposes Keep it safe and secure Keep it accurate, complete and up- to-date Ensure that it is adequate, relevant and not excessive Retain it for no longer than is necessary for the purpose or purposes Give a copy of his/her personal data to that individual on request
  • 11. Data Integrity Pseudonymisation Anonymization Cryptography Accountability Data Protection Officer Data Protection Impact Assessments Data minimisation Notification of Personal Data Breaches 11
  • 12. What’s new in GDPR? Accountability – demonstrating compliance Transparency – providing information pre-processing Risk-based mandatory data breach reporting (72 hours) Strengthened ‘Consent’ obligations New and enhanced Data Subject rights Administrative Fines Data Protection Officer (DPO) for certain organisations 12
  • 13. Article 24.1 “….the controller shall implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation” Article 24.3 “Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller” 13
  • 14. Data Protection Officer (Articles 37, 38 & 39)  Public Authority or Body  Core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale  Processing on a large scale of special categories of data (Articles 9 and 10) 14
  • 15. Demonstrating Accountability Privacy by Design Privacy by Default Data Protection Impact Assessment (DPIA) Codes of Conduct Certification 15
  • 16. Notification to Supervising Authority Notification to Supervising Authority within 72 hours Unless “unlikely to result in a risk to the rights and freedoms of natural persons” ‘Risk’ might include, for example, a risk of identity theft or anything likely to lead to a financial loss for the data subject 16
  • 17. Breach Communication to Data Subject  “when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons”  “the data controller shall communicate the personal data breach to the data subject without undue delay”  ‘High Risk’ – higher threshold than report to SA 17
  • 18. New and Enhanced Data Subject Rights Right to data portability Right to be informed Right to rectification Right of access Right of erasure Right to be forgotten (search engine de-indexing) Right to restrict processing Right to object to processing 18
  • 19. Transparency Requirements • Identity of controller and DPO • Purpose of processing and legal basis • Recipients of the data • Data transfer arrangements • Retention period • Right of access • Right to withdraw consent • Right to lodge complaint with SA • Details of the contractual or statutory basis • Details of automated decision-making At the time when personal data are obtained provide the data subject with information on; 19
  • 20. Transparency Article 12 “The controller shall take appropriate measures to provide any information……..relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child” 20
  • 21. Administrative Fines Article 83 Up to €20m or 4% of global turnover for the preceding financial year 21
  • 22. A Resourced and Effective Regulator 22
  • 24. Q&A – Guest Panel • Helen Dixon, Data Protection Commissioner of Ireland • Denis Kelleher, Senior Legal Counsel, the Central Bank of Ireland • David Cullen, Partner and Head of Technology, William Fry
  • 25. Closing Address • Ruairí Cosgrove President of the Irish Council of ICSA