SlideShare a Scribd company logo
1 of 22
GDPR Summary
Article 9: Special categories of data
www.seersco.com
Special categories of data are the sensitive information about individual and need more
protection.
Individuals‘ rights and freedoms are at increased risk when this type of data is processing. It may
put them at risk of unlawful discrimination.
Article 10: Data of criminal convictions and offences
www.seersco.com
• Organisations must have both a lawful basis under Article 6 in the same way as for any
other personal data, and either legal authority or official authority for the processing under
Article 10.
• Organisations cannot keep a comprehensive register of criminal convictions unless they do
so in an official capacity.
Article 13, 14: Right to be informed
www.seersco.com
• The data controllers should actively inform individuals about the processing of their personal
information through a privacy notice.
Right of access Article 15
www.seersco.com
• The right of access allows individuals to confirm that their data is being processed, and verify the
lawfulness of the processing.
Right to rectification: Article 16
www.seersco.com
• Individuals have the right to have personal data rectified if the personal data is inaccurate or
incomplete.
Right to erasure: Article 17
www.seersco.com
• Also known as ‘the right to be forgotten’, this is most difficult to be provided.
• The data subjects can delete or remove personal data where there is no compelling reason
for its continued processing.
Right to restrict processing Article: 18
www.seersco.com
• Restriction of processing means being permitted to store the personal data, but not to
further process it.
• Individuals have the right to restrict the processing of personal data in certain circumstances:
Right to data portability: Article 20
www.seersco.com
• Right to data portability allows individuals to move, copy or transfer personal data
easily from one data controller to reuse their personal data for their own purposes
across different services.
Right to object: Article 21
www.seersco.com
• Individuals have the right to stop processing of their personal data unless the data controller has
some compelling grounds to continue the processing
• they can demonstrate compelling legitimate grounds for the processing, which override the
interests, rights and freedoms of the individual; or
• the processing is for the establishment, exercise or defence of legal claims.
Right to be Provided
www.seersco.com
Rights to be provided when automated decision making and profiling is involved:
• “The data subject shall have the right not to be subject to a decision based solely on automated
processing, including profiling, which produces legal effects concerning him or her or similarly
significantly affects him or her.” [Article 22(1)]
Contractual obligations for third-party processors
www.seersco.com
Contractual obligations for third-party processors: Article 28::
• Data controllers need to have a written contract in place if they want to outsource their
processing operation.
• The contract helps to understand the responsibilities and liabilities of both parties.
• They help them to comply with the GDPR, and;
• Help controllers to demonstrate their compliance with the GDPR.
Record of processing activities: Article 30
www.seersco.com
• Organisations are required to maintain records of their processing activities under Article 30 of
the GDPR, and make the records available to the supervisory authority on request.
• Records must be kept in writing, kept up to date, and reflect your current processing activities.
• Controllers and processors both have documentation obligations.
• Keeping the record will help organisations demonstrate compliance with the requirements of
the GDPR.
Security of processing: Article 32
www.seersco.com
• The GDPR requires the organisations to ensure the security of personal data by using
appropriate technical and organisational measures.
• Technical measures may include firewalls, antivirus, encryption, anonymisation,
pseudonymisation.
• Organisational measures may include introducing a privacy-oriented mindset and enforcing data
protection policy in the organisation, security of premises where the data processing and storing
equipment is located, restricted and limited access to data processing devices, assigning roles
and responsibilities of someone as a key person responsible for the security of personal data.
• Such measures should protect the personal data against unauthorised or unlawful processing
and against accidental loss, destruction or damage.
Data Breach
www.seersco.com
A personal data breach occurs when the security of processing is compromised, leading to:
1. Unauthorised disclosure of, or access to, personal data,
2. accidental or unlawful destruction, loss, alteration,
3. deliberate or accidental action (or inaction) by a controller or processor
Notification of personal data breach
www.seersco.com
Notification of personal data breach to the supervisory authority: Article 33:
• If there are high risks to the rights and freedom of data subjects as a result of the breach,
organisations must notify the supervisory authority 72 hours after becoming aware of it.
Notification of personal data breach to individuals
www.seersco.com
Notification of personal data breach to the individuals: Article 34::
• Notification of data breach to the individuals is mandatory only if a breach is likely to result in a
high risk to the rights and freedoms of individuals.
• GDPR requires that the organisations must inform those concerned individuals directly and
without undue delay.
Data protection officers Article 37
www.seersco.com
• Is a formal role mandatory appointment under GDPR
Cross-border data transfers
www.seersco.com
• GDPR prohibits the transfer of personal information to third countries or international
organisations which are based outside the European Union.
• However there are certain situations and conditions under which cross-border data transfers are
allowed.
Transfers on the basis of an adequacy decision by the Commission:
• According to Article 45 of the GDPR, transfers may be made where the Commission has decided
that a third country or an international organisation ensures an adequate level of protection.
The main advantage of this Adequacy Decision would be that personal data can flow outside the
EU without any further safeguards.
Transfers subject to appropriate safeguards:
• Article 46 of the GDPR says that organisations may transfer personal data where the receiving
organisation has provided adequate safeguards. They should provide individuals’ with the rights
and effective legal remedies after the transfer.
Binding Corporate Rules
www.seersco.com
• Binding Corporate Rules are internal rules for multinational companies to make intra-
organisational transfers of personal data across borders in compliance with EU Data Protection
Law. It ensures that all data transfer within a corporate group is safe. Article 47 of the GDPR
covers provisions for binding corporate rules.
Derogations
www.seersco.com
• Derogations are exemptions from the general prohibition on transfer of personal data outside
the EU for certain specific situations. Under Article 49 of the GDPR, a transfer can be
24 Holborn Viaduct,
London
EC1A 2BN
info@seersco.com www.seersco.com

More Related Content

What's hot

Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR OverviewGydeline Ltd
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data SecurityWilmerHale
 
Data protection regulation
Data protection regulationData protection regulation
Data protection regulationGreg Ezeilo
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Actmrmwood
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360DataStax
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in IndiaHome
 
India'a Proposed Privacy & Personal Data Protection Law
India'a Proposed Privacy & Personal Data Protection Law India'a Proposed Privacy & Personal Data Protection Law
India'a Proposed Privacy & Personal Data Protection Law Priyanka Aash
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulationFahad Ameen
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017isc2-hellenic
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Stephanie Vasey
 

What's hot (20)

Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Data protection regulation
Data protection regulationData protection regulation
Data protection regulation
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
What does GDPR mean for your charity?
What does GDPR mean for your charity?What does GDPR mean for your charity?
What does GDPR mean for your charity?
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in India
 
Data Protection and IDEA
Data Protection and IDEAData Protection and IDEA
Data Protection and IDEA
 
Privacy Needs to be Personal
Privacy Needs to be PersonalPrivacy Needs to be Personal
Privacy Needs to be Personal
 
India'a Proposed Privacy & Personal Data Protection Law
India'a Proposed Privacy & Personal Data Protection Law India'a Proposed Privacy & Personal Data Protection Law
India'a Proposed Privacy & Personal Data Protection Law
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 

Similar to GDPR Summary

DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADr. Oliver Massmann
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataRenato Monteiro
 
GDPR: Protecting Your Data
GDPR: Protecting Your DataGDPR: Protecting Your Data
GDPR: Protecting Your DataUlf Mattsson
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analyticsbrunomase
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxssuser36d167
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
20131008 agoria big data vs data protection
20131008 agoria big data vs data protection20131008 agoria big data vs data protection
20131008 agoria big data vs data protectionJos Dumortier
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Understanding GDPR: A Comprehensive Guide to Data Protection
Understanding GDPR: A Comprehensive Guide to Data ProtectionUnderstanding GDPR: A Comprehensive Guide to Data Protection
Understanding GDPR: A Comprehensive Guide to Data ProtectionShyamMishra72
 
GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)Erik Vollebregt
 

Similar to GDPR Summary (20)

DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal Data
 
Cyber safe lambeth | GDPR taster
Cyber safe lambeth | GDPR tasterCyber safe lambeth | GDPR taster
Cyber safe lambeth | GDPR taster
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
GDPR: Protecting Your Data
GDPR: Protecting Your DataGDPR: Protecting Your Data
GDPR: Protecting Your Data
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
GDPR
GDPRGDPR
GDPR
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
20131008 agoria big data vs data protection
20131008 agoria big data vs data protection20131008 agoria big data vs data protection
20131008 agoria big data vs data protection
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Understanding GDPR: A Comprehensive Guide to Data Protection
Understanding GDPR: A Comprehensive Guide to Data ProtectionUnderstanding GDPR: A Comprehensive Guide to Data Protection
Understanding GDPR: A Comprehensive Guide to Data Protection
 
GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)
 

More from Martyn Ripley

Consent Management Platform
Consent Management PlatformConsent Management Platform
Consent Management PlatformMartyn Ripley
 
Data Protection Institutions in EU
Data Protection Institutions in EUData Protection Institutions in EU
Data Protection Institutions in EUMartyn Ripley
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPRMartyn Ripley
 
Principles of Data Protection
Principles of Data ProtectionPrinciples of Data Protection
Principles of Data ProtectionMartyn Ripley
 
Privacy Laws in Europe
Privacy Laws in EuropePrivacy Laws in Europe
Privacy Laws in EuropeMartyn Ripley
 

More from Martyn Ripley (7)

Consent Management Platform
Consent Management PlatformConsent Management Platform
Consent Management Platform
 
Data Protection Institutions in EU
Data Protection Institutions in EUData Protection Institutions in EU
Data Protection Institutions in EU
 
DPIA
DPIADPIA
DPIA
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Legal Basis in GDPR
Legal Basis in GDPRLegal Basis in GDPR
Legal Basis in GDPR
 
Principles of Data Protection
Principles of Data ProtectionPrinciples of Data Protection
Principles of Data Protection
 
Privacy Laws in Europe
Privacy Laws in EuropePrivacy Laws in Europe
Privacy Laws in Europe
 

Recently uploaded

Ricky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in MidlothianRicky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in MidlothianRicky French
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书Fir L
 
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书Sir Lt
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhaiShashankKumar441258
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labourBhavikaGholap1
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULEsreeramsaipranitha
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptzainabbkhaleeq123
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...James Watkins, III JD CFP®
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书Fir L
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionAnuragMishra811030
 

Recently uploaded (20)

Ricky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in MidlothianRicky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in Midlothian
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
 
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labour
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .ppt
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 

GDPR Summary

  • 2. Article 9: Special categories of data www.seersco.com Special categories of data are the sensitive information about individual and need more protection. Individuals‘ rights and freedoms are at increased risk when this type of data is processing. It may put them at risk of unlawful discrimination.
  • 3. Article 10: Data of criminal convictions and offences www.seersco.com • Organisations must have both a lawful basis under Article 6 in the same way as for any other personal data, and either legal authority or official authority for the processing under Article 10. • Organisations cannot keep a comprehensive register of criminal convictions unless they do so in an official capacity.
  • 4. Article 13, 14: Right to be informed www.seersco.com • The data controllers should actively inform individuals about the processing of their personal information through a privacy notice.
  • 5. Right of access Article 15 www.seersco.com • The right of access allows individuals to confirm that their data is being processed, and verify the lawfulness of the processing.
  • 6. Right to rectification: Article 16 www.seersco.com • Individuals have the right to have personal data rectified if the personal data is inaccurate or incomplete.
  • 7. Right to erasure: Article 17 www.seersco.com • Also known as ‘the right to be forgotten’, this is most difficult to be provided. • The data subjects can delete or remove personal data where there is no compelling reason for its continued processing.
  • 8. Right to restrict processing Article: 18 www.seersco.com • Restriction of processing means being permitted to store the personal data, but not to further process it. • Individuals have the right to restrict the processing of personal data in certain circumstances:
  • 9. Right to data portability: Article 20 www.seersco.com • Right to data portability allows individuals to move, copy or transfer personal data easily from one data controller to reuse their personal data for their own purposes across different services.
  • 10. Right to object: Article 21 www.seersco.com • Individuals have the right to stop processing of their personal data unless the data controller has some compelling grounds to continue the processing • they can demonstrate compelling legitimate grounds for the processing, which override the interests, rights and freedoms of the individual; or • the processing is for the establishment, exercise or defence of legal claims.
  • 11. Right to be Provided www.seersco.com Rights to be provided when automated decision making and profiling is involved: • “The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.” [Article 22(1)]
  • 12. Contractual obligations for third-party processors www.seersco.com Contractual obligations for third-party processors: Article 28:: • Data controllers need to have a written contract in place if they want to outsource their processing operation. • The contract helps to understand the responsibilities and liabilities of both parties. • They help them to comply with the GDPR, and; • Help controllers to demonstrate their compliance with the GDPR.
  • 13. Record of processing activities: Article 30 www.seersco.com • Organisations are required to maintain records of their processing activities under Article 30 of the GDPR, and make the records available to the supervisory authority on request. • Records must be kept in writing, kept up to date, and reflect your current processing activities. • Controllers and processors both have documentation obligations. • Keeping the record will help organisations demonstrate compliance with the requirements of the GDPR.
  • 14. Security of processing: Article 32 www.seersco.com • The GDPR requires the organisations to ensure the security of personal data by using appropriate technical and organisational measures. • Technical measures may include firewalls, antivirus, encryption, anonymisation, pseudonymisation. • Organisational measures may include introducing a privacy-oriented mindset and enforcing data protection policy in the organisation, security of premises where the data processing and storing equipment is located, restricted and limited access to data processing devices, assigning roles and responsibilities of someone as a key person responsible for the security of personal data. • Such measures should protect the personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage.
  • 15. Data Breach www.seersco.com A personal data breach occurs when the security of processing is compromised, leading to: 1. Unauthorised disclosure of, or access to, personal data, 2. accidental or unlawful destruction, loss, alteration, 3. deliberate or accidental action (or inaction) by a controller or processor
  • 16. Notification of personal data breach www.seersco.com Notification of personal data breach to the supervisory authority: Article 33: • If there are high risks to the rights and freedom of data subjects as a result of the breach, organisations must notify the supervisory authority 72 hours after becoming aware of it.
  • 17. Notification of personal data breach to individuals www.seersco.com Notification of personal data breach to the individuals: Article 34:: • Notification of data breach to the individuals is mandatory only if a breach is likely to result in a high risk to the rights and freedoms of individuals. • GDPR requires that the organisations must inform those concerned individuals directly and without undue delay.
  • 18. Data protection officers Article 37 www.seersco.com • Is a formal role mandatory appointment under GDPR
  • 19. Cross-border data transfers www.seersco.com • GDPR prohibits the transfer of personal information to third countries or international organisations which are based outside the European Union. • However there are certain situations and conditions under which cross-border data transfers are allowed. Transfers on the basis of an adequacy decision by the Commission: • According to Article 45 of the GDPR, transfers may be made where the Commission has decided that a third country or an international organisation ensures an adequate level of protection. The main advantage of this Adequacy Decision would be that personal data can flow outside the EU without any further safeguards. Transfers subject to appropriate safeguards: • Article 46 of the GDPR says that organisations may transfer personal data where the receiving organisation has provided adequate safeguards. They should provide individuals’ with the rights and effective legal remedies after the transfer.
  • 20. Binding Corporate Rules www.seersco.com • Binding Corporate Rules are internal rules for multinational companies to make intra- organisational transfers of personal data across borders in compliance with EU Data Protection Law. It ensures that all data transfer within a corporate group is safe. Article 47 of the GDPR covers provisions for binding corporate rules.
  • 21. Derogations www.seersco.com • Derogations are exemptions from the general prohibition on transfer of personal data outside the EU for certain specific situations. Under Article 49 of the GDPR, a transfer can be
  • 22. 24 Holborn Viaduct, London EC1A 2BN info@seersco.com www.seersco.com