SlideShare a Scribd company logo
1 of 26
Download to read offline
Education law conferences 2018
Keynote 2: 10 steps in 10 weeks to GDPR
compliance
10 steps in 10 weeks to GDPR compliance
Is it really that straightforward…?
Join the conversation #BJ_EDC
Why the change?
Very different data landscape than in 1998
Why the change?
90% of all data in the world today created in past few years
2.5 exabytes - that's 2.5 billion gigabytes (GB) - of data was
generated every day in 2012
2018 - 50,000 GB per second
Data per minute today
• 216,000 Instagram posts
• 204,000,000 emails
• 12 hours of footage is uploaded to YouTube
• 277,000 tweets are posted
Key points
• Comes into effect on 25 May 2018 across Europe
• Main concepts and principles remain the same, but new
elements of it enhance the provisions under the DPA
• Some hefty fines… Up to €20,000,000 fine
Sli.do – vote now
How are we feeling about GDPR?
• GDP what…?
• I’m getting there
• I’m worried about staff compliance
• I’m relaxed, I’ve got it all sorted
The 10 steps
Join the conversation #BJ_EDC
Steps to take now
1. Awareness and leadership across the trust
2. Review the information you hold and how and why you
process (include mapping tool)
3. Third party data sharing contracts
4. Review privacy notices and retention and destruction policy
5. Review procedures for individual rights and SARs
Steps to take now
6. Review how you obtain consent
7. Data breach management
8. Privacy by design
9. Take the opportunity to review staff practices
10. Consider training/re-education needs of staff
1. Awareness and leadership
• Make sure decision makers aware of change and impact
• Nominate a responsible member of SLT
• Organise a working group (IT, HR) and put regular meetings
in the diary
2. Information you hold
• Carry out a data mapping exercise
• Document the information you hold
• Where did it came from?
• With whom do you share it?
• Why are you keeping it?
This gets you 50% of the way there…
3. Third party contracts
• Do you share information with other companies?
• Payroll?
• Catering contractors?
• Review the contracts. If they go beyond 25 May 2018 they
will require amendment to reflect GDPR changes
• Ask those third parties to confirm GDPR compliance
4. Privacy notices and retention/destruction
• New privacy notices must include:
• Legal basis for processing
• Data retention periods
• Complaints
• Concise, easy to understand and language
• ICO privacy notice code of practice reflects changes
4. Privacy notices and retention/destruction
• Do you have a retention/destruction policy?
• Why did you choose those timeframes?
• Do you follow it?
• IRMS Information management toolkit for schools
5. Individual rights and subject access request
• Check procedures to make sure they cover all new rights
• Subject access
• Inaccuracies corrected - rectification
• Information erased (‘right to be forgotten’)
• Object to direct marketing and automated decision-making
and profiling
5. Individual rights and subject access request
• Must provide the following to data subjects on request:
• Identity and contact details of data controller and DPO
• Intended purpose of processing and period it will be stored
• Existence of rights: access, rectification, object and erasure
• Right to complain internally and to a supervisory authority
• Categories of recipients to whom data will be disclosed
• Information must be concise, transparent, intelligible and
easily accessible
5. Individual rights and subject access request
• No fee
• Must be provided in writing unless otherwise
requested (requestor can ask for electronic format)
• Must respond within one month - can extend for
complex requests
• Manifestly unfounded or excessive requests may
be charged for or refused
This gets you 70% of the way there…
6. Consent
• Must be freely given, specific, informed and unambiguous,
and a positive affirmation of the individual’s agreement
• Cannot be bundled in with other terms/consents
• Withdrawal of consent should be as easy as grant
of consent
This gets you 80% of the way there…
7. Data breach management
• Must have procedures in place to detect, report and
investigate a personal data breach
• 72 hours from the discovery of the breach to report to ICO
• Breach must be reported unless the personal data breach is
unlikely to result in a risk to the rights and freedoms of
natural persons
• Notify the affected data subjects
8. Privacy by design
• At the outset of every project think about personal data
• Consider how you can minimise personal data use and risk
• Legal requirement to carry out a privacy impact assessment
• ICO guidance on privacy impact assessments
9. Staff practices
…(Governors and trustees/directors too)
• Use of personal emails rather than trust emails?
• Taking hard copy personal data home/out of school?
• Downloading data onto a non-school device?
• USBs, discs, data rooms etc.
This is that difficult final 20%...
10. Training/re-education
• Train staff to recognise a subject access request
• Train/re-educate regarding data security and off site use
• If policies are changed, consider how you disseminate and
evidence staff understanding
• What other training might they need?
Sli.do – vote now
How are we feeling about GDPR now?
• GDP what…?
• I’m getting there
• I’m worried about staff compliance
• I’m relaxed, I’ve got it all sorted
www.brownejacobson.com/education
Please note
The information contained in these notes is based on the
position at March 2018. It does, of course, only represent a
summary of the subject matter covered and is not intended to
be a substitute for detailed advice. If you would like to discuss
any of the matters covered in further detail, our team would
be happy to do so.
© Browne Jacobson LLP 2018. Browne Jacobson LLP is a
limited liability partnership.

More Related Content

What's hot

Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideZymplify
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRBartLieben
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...CharityComms
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)Bright
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...CILIPScotland
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillSymptai Consulting Limited
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017Match-Maker Ventures
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparationPromapp Solutions
 
Enterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving ChangeEnterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving ChangeIron Mountain
 
What Every Attorney Needs to Know
What Every Attorney Needs to KnowWhat Every Attorney Needs to Know
What Every Attorney Needs to KnowBoyarMiller
 
Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions 3Play Media
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR ComplianceDATAVERSITY
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Jonathan Chilton
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Iron Mountain
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]TrustArc
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowPiwik PRO
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPRGDPR Course
 

What's hot (20)

Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
 
Rent-a-DPO for IT Vendors
Rent-a-DPO for IT VendorsRent-a-DPO for IT Vendors
Rent-a-DPO for IT Vendors
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
Balancing Privacy and Digitization
Balancing Privacy and DigitizationBalancing Privacy and Digitization
Balancing Privacy and Digitization
 
Enterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving ChangeEnterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving Change
 
What Every Attorney Needs to Know
What Every Attorney Needs to KnowWhat Every Attorney Needs to Know
What Every Attorney Needs to Know
 
Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
 

Similar to Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GDPR compliance

Education law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOEducation law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOBrowne Jacobson LLP
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
15. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 201015. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 2010Brian Bailey
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...AIIM International
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceCILIPScotland
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
Privacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacyCenter.cloud
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital MarketersOne North
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPRMarketo
 

Similar to Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GDPR compliance (20)

Education law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOEducation law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPO
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
15. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 201015. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 2010
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library Service
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Privacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User Data
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 

More from Browne Jacobson LLP

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Browne Jacobson LLP
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed Browne Jacobson LLP
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionBrowne Jacobson LLP
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Browne Jacobson LLP
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Browne Jacobson LLP
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Browne Jacobson LLP
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Browne Jacobson LLP
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Browne Jacobson LLP
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Browne Jacobson LLP
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamBrowne Jacobson LLP
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London Browne Jacobson LLP
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Browne Jacobson LLP
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 Browne Jacobson LLP
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Browne Jacobson LLP
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterBrowne Jacobson LLP
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Browne Jacobson LLP
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamBrowne Jacobson LLP
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Browne Jacobson LLP
 

More from Browne Jacobson LLP (20)

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham session
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019
 
Health tech slides 12 june 2019
Health tech slides   12 june 2019Health tech slides   12 june 2019
Health tech slides 12 june 2019
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - Birmingham
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019
 
In House Lawyers, March 2019
In House Lawyers, March 2019In House Lawyers, March 2019
In House Lawyers, March 2019
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, Manchester
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, Nottingham
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...
 

Recently uploaded

FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书SD DS
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书SD DS
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书Fir sss
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A HistoryJohn Hustaix
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaBridgeWest.eu
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书Fir L
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书FS LS
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书Fir L
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 

Recently uploaded (20)

FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to Service
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A History
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad Visa
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 

Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GDPR compliance

  • 1. Education law conferences 2018 Keynote 2: 10 steps in 10 weeks to GDPR compliance
  • 2. 10 steps in 10 weeks to GDPR compliance Is it really that straightforward…? Join the conversation #BJ_EDC
  • 3. Why the change? Very different data landscape than in 1998
  • 4. Why the change? 90% of all data in the world today created in past few years 2.5 exabytes - that's 2.5 billion gigabytes (GB) - of data was generated every day in 2012 2018 - 50,000 GB per second
  • 5. Data per minute today • 216,000 Instagram posts • 204,000,000 emails • 12 hours of footage is uploaded to YouTube • 277,000 tweets are posted
  • 6. Key points • Comes into effect on 25 May 2018 across Europe • Main concepts and principles remain the same, but new elements of it enhance the provisions under the DPA • Some hefty fines… Up to €20,000,000 fine
  • 7. Sli.do – vote now How are we feeling about GDPR? • GDP what…? • I’m getting there • I’m worried about staff compliance • I’m relaxed, I’ve got it all sorted
  • 8. The 10 steps Join the conversation #BJ_EDC
  • 9. Steps to take now 1. Awareness and leadership across the trust 2. Review the information you hold and how and why you process (include mapping tool) 3. Third party data sharing contracts 4. Review privacy notices and retention and destruction policy 5. Review procedures for individual rights and SARs
  • 10. Steps to take now 6. Review how you obtain consent 7. Data breach management 8. Privacy by design 9. Take the opportunity to review staff practices 10. Consider training/re-education needs of staff
  • 11. 1. Awareness and leadership • Make sure decision makers aware of change and impact • Nominate a responsible member of SLT • Organise a working group (IT, HR) and put regular meetings in the diary
  • 12. 2. Information you hold • Carry out a data mapping exercise • Document the information you hold • Where did it came from? • With whom do you share it? • Why are you keeping it? This gets you 50% of the way there…
  • 13. 3. Third party contracts • Do you share information with other companies? • Payroll? • Catering contractors? • Review the contracts. If they go beyond 25 May 2018 they will require amendment to reflect GDPR changes • Ask those third parties to confirm GDPR compliance
  • 14. 4. Privacy notices and retention/destruction • New privacy notices must include: • Legal basis for processing • Data retention periods • Complaints • Concise, easy to understand and language • ICO privacy notice code of practice reflects changes
  • 15. 4. Privacy notices and retention/destruction • Do you have a retention/destruction policy? • Why did you choose those timeframes? • Do you follow it? • IRMS Information management toolkit for schools
  • 16. 5. Individual rights and subject access request • Check procedures to make sure they cover all new rights • Subject access • Inaccuracies corrected - rectification • Information erased (‘right to be forgotten’) • Object to direct marketing and automated decision-making and profiling
  • 17. 5. Individual rights and subject access request • Must provide the following to data subjects on request: • Identity and contact details of data controller and DPO • Intended purpose of processing and period it will be stored • Existence of rights: access, rectification, object and erasure • Right to complain internally and to a supervisory authority • Categories of recipients to whom data will be disclosed • Information must be concise, transparent, intelligible and easily accessible
  • 18. 5. Individual rights and subject access request • No fee • Must be provided in writing unless otherwise requested (requestor can ask for electronic format) • Must respond within one month - can extend for complex requests • Manifestly unfounded or excessive requests may be charged for or refused This gets you 70% of the way there…
  • 19. 6. Consent • Must be freely given, specific, informed and unambiguous, and a positive affirmation of the individual’s agreement • Cannot be bundled in with other terms/consents • Withdrawal of consent should be as easy as grant of consent This gets you 80% of the way there…
  • 20. 7. Data breach management • Must have procedures in place to detect, report and investigate a personal data breach • 72 hours from the discovery of the breach to report to ICO • Breach must be reported unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons • Notify the affected data subjects
  • 21. 8. Privacy by design • At the outset of every project think about personal data • Consider how you can minimise personal data use and risk • Legal requirement to carry out a privacy impact assessment • ICO guidance on privacy impact assessments
  • 22. 9. Staff practices …(Governors and trustees/directors too) • Use of personal emails rather than trust emails? • Taking hard copy personal data home/out of school? • Downloading data onto a non-school device? • USBs, discs, data rooms etc. This is that difficult final 20%...
  • 23. 10. Training/re-education • Train staff to recognise a subject access request • Train/re-educate regarding data security and off site use • If policies are changed, consider how you disseminate and evidence staff understanding • What other training might they need?
  • 24. Sli.do – vote now How are we feeling about GDPR now? • GDP what…? • I’m getting there • I’m worried about staff compliance • I’m relaxed, I’ve got it all sorted
  • 26. Please note The information contained in these notes is based on the position at March 2018. It does, of course, only represent a summary of the subject matter covered and is not intended to be a substitute for detailed advice. If you would like to discuss any of the matters covered in further detail, our team would be happy to do so. © Browne Jacobson LLP 2018. Browne Jacobson LLP is a limited liability partnership.