SlideShare a Scribd company logo
1 of 25
Download to read offline
THE NEW GENERAL
DATA PROTECTION REGULATION –
IMPLICATIONS FOR ENTERPRISES
Forum financier
du Brabant wallon
14.12.2017
Data Protection should
be part of every
company’s or
organisation’s DNA
Do you process
personal data?
collection, recording, organization,
structuring, storage, consulting, editing, etc.
Processing
any information relating to an identified or
identifiable individual (name, tracking
number, location data, etc.) This individual
is called the data subject.
Personal data
says how and why
personal data is processed.
Data Controller
act on the controller's
behalf.
Data Processor
Then you are
or
Name Address
Telephone number
Age
date of birth
gender
nation of origin
colour of skinReligious beliefs Health care/medical history
Identification number
Ethnicity
Location data
IP Address
Exact salary
Employment information
Curriculum vitae
fingerprints
Criminal records
Credit card numbers
Identifying numbers SIN, PRI Marital status
Some examples of personal data
Sensitive personal data?
• processed legally and appropriately:
• collected for specified, explicit
and legitimate purposes;
• relevant and limited to the respective purposes;
• accurate and kept up to date;
• retained for no longer than is necessary;
• kept appropriately secure.
• compile a data register;
• process the minimum volume of personal
data;
• draft a privacy notice,
• develop an internal policy;
• appoint an employee who
is in charge of data protection;
• use data protection impact assessments;
• establish effective procedures protection.
To be compliant, I must:
For accountability I should:
If you process personal
data, you must comply
with the privacy
legislation
Two key principles
TransparencyAccountability
principle which requires that organisations put in place appropriate
technical and organisational measures and are able to demonstrate
what they did and its effectiveness when requested
• Identification of the controller/processor
(register’s owner) and of the DPO
• Identification of the processing activity
• Description of the processing activity
• Details concerning the type of personal data and
the data subjects (+ dates and sources)
• Identification of the processor(s)
• Transfer of personal data (To whom? and whereto?)
• Description of the technology and software
applications used for processing personal data
• Information about risks and security measures
• How to manage data subject rights
• Status of the processing activity
Ideally your register
should contain
Under what circumstances
can I process personal data?
EITHER
with the data subject's consent;
External Personal Data
Internal Personal Data
OR
processing is required:
• performance of a contract,
• legal obligation,
• vital interests,
• public interest,
• legitimate interests.
Public and Private Personal Data
Public data
are data which
are freely
accessible to
everybody or to
a very large
group of people
Private data
are data which
are not freely
accessible
When processing private and/or public personal data GDPR applies.
You need to have a legal base, defined objectives, etc. and you must inform the Data Subject about your processing activity.
Legitimate Interest may be a good legal base for the
processing of public personal data insofar the processing meets
the reasonable expectations of the data subject
• clear affirmative action,
• Specific and non ambiguous
• Opt-in, no preticked boxes
• must be verifiable,
• can be withdrawn at any time,
Consent:
The General Data Protection Regulation
contains new provisions intended to
enhance the protection of children's
personal data.
Children's personal data
Consent obtained previously should not be
sought again if the standard of that
consent meets the new requirements.
• Ensure that data subjects are provided with a clear explanation of
the processing for which they are granting their consent.
• Ensure that the consent mechanism is genuinely voluntary and of an
‘opt-in’ nature.
• Ensure that data subjects can withdraw their consent easily.
• Ensure that consent is not based on unresponsiveness or inactivity.
Two key principles
TransparencyAccountability
principle which requires that controller and processor are open
toward individuals regarding the processing of their data
Rights of data subjects
Right of data subjects to obtain
transparent information, at the time
their personal data are collected, about
the procedure for processing their data
Right to be informed
Right of data subjects to obtain, on
request, a list of their processed
personal data from the controller
Right of access
Right to request the rectification
of inaccurate or incomplete
personal data
Right to rectification
Right of data subjects to object to
processing of their data for marketing
purposes for example
Right to object
Right of data subjects, in specific
circumstances, to ask for their data
to be deleted if the processing of
these data causes them damage
'Right to be
forgotten'
?
Right of data subjects to ask for
all their personal data to be
transferred from one computer
environment/controller
to another
Right to data
portability
Right to refuse to be subject
to a decision based solely on
automated processing
Automated decision-making
and profiling
Rights of data subjects
What are my obligations
as the controller and/or processor?
• review data-processing activities
and keep records;
• protect the security of the personal
data;
• comply with the accountability
principle and cooperate
with the Privacy Commission;
• identify, review and promptly
report data breaches to the Privacy
Commission.
• review my existing data-processing
agreements and ensure the appropriate
security and confidentiality of personal data
I process;
• only process data in accordance
with the controller's instructions;
• identify, review and promptly report
data breaches to the relevant controller;
• be aware that I am only allowed
to appoint sub-processors
with the controller's consent.
As the processor I must:As the controller I must:
What if I transfer data outside the EU?
Switzerland
Canada
Andorra
Argentina
USA (Privacy Shield)
Guernsey
the Isle of Man
the Faroe Islands
Jersey
Australia
Israel
New Zealand
Uruguay
I transfer data to:
YES
These countries offer
adequate protection
I conclude standard data
protection clauses adopted by
the European Commission.
I conclude Binding
Corporate Rules
Nothing has
to be done
EITHER I obtain the data
subject's consent
OR the transfer is required for
the execution of a contract
Transfer within
a corporate group
Transfer outside
a corporate group
Specific transfer
NO
• Notify the Privacy Commission
of any breach within 72 hours
• Where a breach is likely to put
an individual's rights and freedoms
at high risk, you must notify those
concerned directly.
What do I need to do
in case of a data breach?
A data breach means a breach of security leading
to the destruction, loss, alteration or unauthorised
disclosure of or access to personal data.
Make sure to perform this beforehand:
Ensure that your staff understands what constitutes
a data breach.
Appoint an individual to take responsibility for
reviewing and reporting data breaches.
Have robust breach detection, investigation and
internal reporting.
Draft template letters to report any data breach.
When your core business involves large-scale
systematic monitoring of individuals or special
categories of data, you must appoint a Data
Protection Officer (DPO).
FEB advises all enterprises
to appoint a person in
charge of data protection.
The tasks of a data protection
officer:
• inform and advise the enterprise and its employees
of the organisation's obligations to comply
with the GDPR and other data protection laws;
• monitor compliance with the GDPR;
• be the first point of contact for data protection.
Reform of the Data Protection Authority
Board of
Directors
General
Secretary
First-line
service
Litigation
chamber
Inspection
Knowledge
centre
Data Protection
Authority
• Information and Advice
• Guidance for controllers
and processors
• Monitoring and Sanctions
Advice Council
• Sanctions without immediate financial
impact: warning, order to comply,
restriction of processing, suspend transfer
data to third countries, etc.
• Administrative fines up to 4% of
worldwide turnover or 20.000.000 EUR
What are the risks of non
compliance?
A data subject has two options:
• Deposit a complaint at the Data Protection
Authority (DPA)
• Deposit a complaint at the Tribunal/Court
The DPA can act on its own initiative
DPA can impose
Seven key recommendations
1. Keep a record of all personal data
processes along with their intended purpose.
2. Handle the processed
data legally and transparently.
3. Only register mandatory data,
and do so for no longer than necessary.
4. Put appropriate security measures
in place to protect the personal data.
5. Clearly notify the data subjects concerned.
6. Devise an internal data
protection and privacy policy.
7. Appoint a person in charge
of data protection and privacy.
Thank you for
your attention
Questions?
Nathalie Ragheno
nr@vbo-feb.be
02/515 09 52

More Related Content

What's hot

Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015Rachel Aldighieri
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
 
An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014Rachel Aldighieri
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Software Integrity Group
 
An introduction to data protection - Edinburgh
An introduction to data protection - EdinburghAn introduction to data protection - Edinburgh
An introduction to data protection - EdinburghRachel Aldighieri
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 

What's hot (20)

GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
 
An introduction to data protection - Edinburgh
An introduction to data protection - EdinburghAn introduction to data protection - Edinburgh
An introduction to data protection - Edinburgh
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 

Similar to Protection des données et de la vie privée : nouvelles obligations pour les entreprises

ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMichelleSaver
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leadersDeeson
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillSymptai Consulting Limited
 

Similar to Protection des données et de la vie privée : nouvelles obligations pour les entreprises (20)

ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR Demystified
GDPR Demystified GDPR Demystified
GDPR Demystified
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 

More from Forums financiers de Wallonie

Investissements durables : quels sont les principaux défis pour le secteur fi...
Investissements durables : quels sont les principaux défis pour le secteur fi...Investissements durables : quels sont les principaux défis pour le secteur fi...
Investissements durables : quels sont les principaux défis pour le secteur fi...Forums financiers de Wallonie
 
2023_01_31_Forum_Financier Finances Region wallonne.pdf
2023_01_31_Forum_Financier Finances Region wallonne.pdf2023_01_31_Forum_Financier Finances Region wallonne.pdf
2023_01_31_Forum_Financier Finances Region wallonne.pdfForums financiers de Wallonie
 
Prix de l’énergie, inflation et indexation automatique quelles conséquences.pdf
Prix de l’énergie, inflation et indexation automatique  quelles conséquences.pdfPrix de l’énergie, inflation et indexation automatique  quelles conséquences.pdf
Prix de l’énergie, inflation et indexation automatique quelles conséquences.pdfForums financiers de Wallonie
 
Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...
Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...
Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...Forums financiers de Wallonie
 
Un nouveau monde, de nouveaux risques: AG & Ethias.pdf
Un nouveau monde, de nouveaux risques: AG & Ethias.pdfUn nouveau monde, de nouveaux risques: AG & Ethias.pdf
Un nouveau monde, de nouveaux risques: AG & Ethias.pdfForums financiers de Wallonie
 
L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...
L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...
L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...Forums financiers de Wallonie
 
L'investissement responsable ne sauvera pas le monde ... mais
L'investissement  responsable ne sauvera pas le monde ... maisL'investissement  responsable ne sauvera pas le monde ... mais
L'investissement responsable ne sauvera pas le monde ... maisForums financiers de Wallonie
 
L'accroissement des pouvoirs de l'administration fiscale
L'accroissement des pouvoirs de l'administration fiscaleL'accroissement des pouvoirs de l'administration fiscale
L'accroissement des pouvoirs de l'administration fiscaleForums financiers de Wallonie
 

More from Forums financiers de Wallonie (20)

FOFI 20230216.pdf
FOFI 20230216.pdfFOFI 20230216.pdf
FOFI 20230216.pdf
 
Que nous réserve la prochaine réforme fiscale?
Que nous réserve la prochaine réforme fiscale?Que nous réserve la prochaine réforme fiscale?
Que nous réserve la prochaine réforme fiscale?
 
Investissements durables : quels sont les principaux défis pour le secteur fi...
Investissements durables : quels sont les principaux défis pour le secteur fi...Investissements durables : quels sont les principaux défis pour le secteur fi...
Investissements durables : quels sont les principaux défis pour le secteur fi...
 
2023_01_31_Forum_Financier Finances Region wallonne.pdf
2023_01_31_Forum_Financier Finances Region wallonne.pdf2023_01_31_Forum_Financier Finances Region wallonne.pdf
2023_01_31_Forum_Financier Finances Region wallonne.pdf
 
Prix de l’énergie, inflation et indexation automatique quelles conséquences.pdf
Prix de l’énergie, inflation et indexation automatique  quelles conséquences.pdfPrix de l’énergie, inflation et indexation automatique  quelles conséquences.pdf
Prix de l’énergie, inflation et indexation automatique quelles conséquences.pdf
 
Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...
Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...
Bruxelles est-elle une métropole performante, compétitive et attractive en Eu...
 
La réforme du Code des sociétés FF.pdf
La réforme du Code des sociétés FF.pdfLa réforme du Code des sociétés FF.pdf
La réforme du Code des sociétés FF.pdf
 
conference IDEA Forum financier Mons.pdf
conference IDEA Forum financier Mons.pdfconference IDEA Forum financier Mons.pdf
conference IDEA Forum financier Mons.pdf
 
Un nouveau monde, de nouveaux risques: AG & Ethias.pdf
Un nouveau monde, de nouveaux risques: AG & Ethias.pdfUn nouveau monde, de nouveaux risques: AG & Ethias.pdf
Un nouveau monde, de nouveaux risques: AG & Ethias.pdf
 
The European Green Deal - Forum Financier Namur.pdf
The European Green Deal - Forum Financier Namur.pdfThe European Green Deal - Forum Financier Namur.pdf
The European Green Deal - Forum Financier Namur.pdf
 
duo sur vision Wallonie - Borsus De Geest.pdf
duo sur vision Wallonie - Borsus De Geest.pdfduo sur vision Wallonie - Borsus De Geest.pdf
duo sur vision Wallonie - Borsus De Geest.pdf
 
Fofi Charleroi plan relance Wallon slides UWE.pdf
Fofi Charleroi plan relance Wallon slides UWE.pdfFofi Charleroi plan relance Wallon slides UWE.pdf
Fofi Charleroi plan relance Wallon slides UWE.pdf
 
L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...
L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...
L’évolution du secteur hospitalier vers les bassins de soins : l’exemple de E...
 
La forêt mosaïque.pdf
La forêt mosaïque.pdfLa forêt mosaïque.pdf
La forêt mosaïque.pdf
 
Perspectives économiques: Hilgers Namur 2022.pdf
Perspectives économiques:  Hilgers Namur 2022.pdfPerspectives économiques:  Hilgers Namur 2022.pdf
Perspectives économiques: Hilgers Namur 2022.pdf
 
L'investissement responsable ne sauvera pas le monde ... mais
L'investissement  responsable ne sauvera pas le monde ... maisL'investissement  responsable ne sauvera pas le monde ... mais
L'investissement responsable ne sauvera pas le monde ... mais
 
Projections économiques pour la Belgique
Projections économiques pour la BelgiqueProjections économiques pour la Belgique
Projections économiques pour la Belgique
 
L'accroissement des pouvoirs de l'administration fiscale
L'accroissement des pouvoirs de l'administration fiscaleL'accroissement des pouvoirs de l'administration fiscale
L'accroissement des pouvoirs de l'administration fiscale
 
ForumFinancierMons (1).pdf
ForumFinancierMons (1).pdfForumFinancierMons (1).pdf
ForumFinancierMons (1).pdf
 
Presentation Mottet Fofi Namur 11.05.22.pdf
Presentation Mottet Fofi Namur 11.05.22.pdfPresentation Mottet Fofi Namur 11.05.22.pdf
Presentation Mottet Fofi Namur 11.05.22.pdf
 

Recently uploaded

如何办理纽约州立大学石溪分校毕业证学位证书
 如何办理纽约州立大学石溪分校毕业证学位证书 如何办理纽约州立大学石溪分校毕业证学位证书
如何办理纽约州立大学石溪分校毕业证学位证书Fir sss
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx2020000445musaib
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
Understanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesUnderstanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesFinlaw Associates
 
Debt Collection in India - General Procedure
Debt Collection in India  - General ProcedureDebt Collection in India  - General Procedure
Debt Collection in India - General ProcedureBridgeWest.eu
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 
A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxPKrishna18
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 

Recently uploaded (20)

如何办理纽约州立大学石溪分校毕业证学位证书
 如何办理纽约州立大学石溪分校毕业证学位证书 如何办理纽约州立大学石溪分校毕业证学位证书
如何办理纽约州立大学石溪分校毕业证学位证书
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
Understanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesUnderstanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and Challenges
 
Debt Collection in India - General Procedure
Debt Collection in India  - General ProcedureDebt Collection in India  - General Procedure
Debt Collection in India - General Procedure
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 
A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptx
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 

Protection des données et de la vie privée : nouvelles obligations pour les entreprises

  • 1. THE NEW GENERAL DATA PROTECTION REGULATION – IMPLICATIONS FOR ENTERPRISES Forum financier du Brabant wallon 14.12.2017
  • 2. Data Protection should be part of every company’s or organisation’s DNA
  • 3.
  • 4. Do you process personal data? collection, recording, organization, structuring, storage, consulting, editing, etc. Processing any information relating to an identified or identifiable individual (name, tracking number, location data, etc.) This individual is called the data subject. Personal data says how and why personal data is processed. Data Controller act on the controller's behalf. Data Processor Then you are or
  • 5. Name Address Telephone number Age date of birth gender nation of origin colour of skinReligious beliefs Health care/medical history Identification number Ethnicity Location data IP Address Exact salary Employment information Curriculum vitae fingerprints Criminal records Credit card numbers Identifying numbers SIN, PRI Marital status Some examples of personal data
  • 7. • processed legally and appropriately: • collected for specified, explicit and legitimate purposes; • relevant and limited to the respective purposes; • accurate and kept up to date; • retained for no longer than is necessary; • kept appropriately secure. • compile a data register; • process the minimum volume of personal data; • draft a privacy notice, • develop an internal policy; • appoint an employee who is in charge of data protection; • use data protection impact assessments; • establish effective procedures protection. To be compliant, I must: For accountability I should: If you process personal data, you must comply with the privacy legislation
  • 8. Two key principles TransparencyAccountability principle which requires that organisations put in place appropriate technical and organisational measures and are able to demonstrate what they did and its effectiveness when requested
  • 9. • Identification of the controller/processor (register’s owner) and of the DPO • Identification of the processing activity • Description of the processing activity • Details concerning the type of personal data and the data subjects (+ dates and sources) • Identification of the processor(s) • Transfer of personal data (To whom? and whereto?) • Description of the technology and software applications used for processing personal data • Information about risks and security measures • How to manage data subject rights • Status of the processing activity Ideally your register should contain
  • 10. Under what circumstances can I process personal data? EITHER with the data subject's consent; External Personal Data Internal Personal Data OR processing is required: • performance of a contract, • legal obligation, • vital interests, • public interest, • legitimate interests.
  • 11. Public and Private Personal Data Public data are data which are freely accessible to everybody or to a very large group of people Private data are data which are not freely accessible When processing private and/or public personal data GDPR applies. You need to have a legal base, defined objectives, etc. and you must inform the Data Subject about your processing activity. Legitimate Interest may be a good legal base for the processing of public personal data insofar the processing meets the reasonable expectations of the data subject
  • 12. • clear affirmative action, • Specific and non ambiguous • Opt-in, no preticked boxes • must be verifiable, • can be withdrawn at any time, Consent: The General Data Protection Regulation contains new provisions intended to enhance the protection of children's personal data. Children's personal data Consent obtained previously should not be sought again if the standard of that consent meets the new requirements.
  • 13. • Ensure that data subjects are provided with a clear explanation of the processing for which they are granting their consent. • Ensure that the consent mechanism is genuinely voluntary and of an ‘opt-in’ nature. • Ensure that data subjects can withdraw their consent easily. • Ensure that consent is not based on unresponsiveness or inactivity.
  • 14. Two key principles TransparencyAccountability principle which requires that controller and processor are open toward individuals regarding the processing of their data
  • 15. Rights of data subjects Right of data subjects to obtain transparent information, at the time their personal data are collected, about the procedure for processing their data Right to be informed Right of data subjects to obtain, on request, a list of their processed personal data from the controller Right of access Right to request the rectification of inaccurate or incomplete personal data Right to rectification Right of data subjects to object to processing of their data for marketing purposes for example Right to object
  • 16. Right of data subjects, in specific circumstances, to ask for their data to be deleted if the processing of these data causes them damage 'Right to be forgotten' ? Right of data subjects to ask for all their personal data to be transferred from one computer environment/controller to another Right to data portability Right to refuse to be subject to a decision based solely on automated processing Automated decision-making and profiling Rights of data subjects
  • 17. What are my obligations as the controller and/or processor? • review data-processing activities and keep records; • protect the security of the personal data; • comply with the accountability principle and cooperate with the Privacy Commission; • identify, review and promptly report data breaches to the Privacy Commission. • review my existing data-processing agreements and ensure the appropriate security and confidentiality of personal data I process; • only process data in accordance with the controller's instructions; • identify, review and promptly report data breaches to the relevant controller; • be aware that I am only allowed to appoint sub-processors with the controller's consent. As the processor I must:As the controller I must:
  • 18. What if I transfer data outside the EU? Switzerland Canada Andorra Argentina USA (Privacy Shield) Guernsey the Isle of Man the Faroe Islands Jersey Australia Israel New Zealand Uruguay I transfer data to: YES These countries offer adequate protection I conclude standard data protection clauses adopted by the European Commission. I conclude Binding Corporate Rules Nothing has to be done EITHER I obtain the data subject's consent OR the transfer is required for the execution of a contract Transfer within a corporate group Transfer outside a corporate group Specific transfer NO
  • 19. • Notify the Privacy Commission of any breach within 72 hours • Where a breach is likely to put an individual's rights and freedoms at high risk, you must notify those concerned directly. What do I need to do in case of a data breach? A data breach means a breach of security leading to the destruction, loss, alteration or unauthorised disclosure of or access to personal data.
  • 20. Make sure to perform this beforehand: Ensure that your staff understands what constitutes a data breach. Appoint an individual to take responsibility for reviewing and reporting data breaches. Have robust breach detection, investigation and internal reporting. Draft template letters to report any data breach.
  • 21. When your core business involves large-scale systematic monitoring of individuals or special categories of data, you must appoint a Data Protection Officer (DPO). FEB advises all enterprises to appoint a person in charge of data protection. The tasks of a data protection officer: • inform and advise the enterprise and its employees of the organisation's obligations to comply with the GDPR and other data protection laws; • monitor compliance with the GDPR; • be the first point of contact for data protection.
  • 22. Reform of the Data Protection Authority Board of Directors General Secretary First-line service Litigation chamber Inspection Knowledge centre Data Protection Authority • Information and Advice • Guidance for controllers and processors • Monitoring and Sanctions Advice Council
  • 23. • Sanctions without immediate financial impact: warning, order to comply, restriction of processing, suspend transfer data to third countries, etc. • Administrative fines up to 4% of worldwide turnover or 20.000.000 EUR What are the risks of non compliance? A data subject has two options: • Deposit a complaint at the Data Protection Authority (DPA) • Deposit a complaint at the Tribunal/Court The DPA can act on its own initiative DPA can impose
  • 24. Seven key recommendations 1. Keep a record of all personal data processes along with their intended purpose. 2. Handle the processed data legally and transparently. 3. Only register mandatory data, and do so for no longer than necessary. 4. Put appropriate security measures in place to protect the personal data. 5. Clearly notify the data subjects concerned. 6. Devise an internal data protection and privacy policy. 7. Appoint a person in charge of data protection and privacy.
  • 25. Thank you for your attention Questions? Nathalie Ragheno nr@vbo-feb.be 02/515 09 52