SlideShare a Scribd company logo
Data protection 2013
Friday 8 February
#dmadata
Supported by
An introduction to data
protection
Thursday 9 October 2014, Tangible Barge
James Milligan
Solicitor
DMA
Agenda
1.00pm Registration and breakfast
1.30pm Why is data protection important?
1.40pm Understanding the law
The Data Protection Act 1998
Key terms
8 Principles
2.40pm Break
3.00pm Understanding the law
The Privacy and Electronic Communications Regulation 2003
Key rules
Key points
3.30pm Practical tips for marketers
4.00pm Summary and questions
4.30pm Close
Why is it important?
• It helps us to protect information about ourselves and others
• It helps us avoid damage to the reputation of our organisation
• It makes good business sense – it can increase efficiency and
effectiveness
• It helps us avoid enforcement action by the Information
Commissioner
– both employers and employees can be prosecuted
– companies can face a monetary penalty of up to £500,000 for
major breaches
Understanding the law 1
• Data Protection Act 1998 (DPA)
– Came into force 1 March 2000
– Replaced 1984 Act
– Covers doing anything with data
– Applies electronic records and some manual records
Key Terms
• Personal data
– any data that can be used to identify a living individual
– Examples of personal data can include:
• Name and address
• Email address (even business email addresses if they are non
generic)
• Name and telephone number
• Photographs
– Only personal data is protected by the DPA
• Sensitive personal data
– any data relating to:
• Health
• Race or ethnic origin
• Political opinions
• Religious beliefs
• Trade union membership
• Sex life
• Criminal proceedings or convictions
Key terms
• Processing
– obtaining, recording or holding information or carrying out any
operation on the information including
• Organising
• Adapting
• Retrieving
• Disclosing
• Blocking
• Destroying
• Data subject
– a living identifiable individual to whom the personal data
relates
Key Terms
• Data controller
- Determines how data will be used
- Usually owns or rents the data (may be done by 3rd
party on their behalf)
- Required to notify (register) as a controller with the ICO
- May be fined by ICO if any data breaches arise
• Data processor
- Processes data on behalf of controller or other
processor
- Processing can be anything from data storage to
advanced data manipulation and modelling
- Includes companies that manage / broker / collect data
on behalf of others
The 8 Principles
• Fairly and lawfully collected
• Processed for specified and limited purposes
• Adequate, relevant and not excessive
• Accurate and kept up to date
• Not kept for longer than necessary
• Processed in accordance with Individuals’ rights
• Security – appropriate technical and organisational measures
• Not transferred outside the European Economic Area (EEA)
unless adequate protections are in place
• (EEA: The 28 member states of the EU, plus Iceland,
Liechtenstein and Norway)
Principle 1: Fairly and lawfully
collected
• Fair processing information provided
• Organisation’s identity given
• Purpose of collection made clear
• Further information necessary
• Correct permissions obtained
- Implied consent: opt-out mechanism provided
- Express consent: opt-in mechanism provided
• Sensitive personal data only captured if strictly necessary
Principle 2: Processed for limited
purposes
• Only process data for the purpose(s) you told the individual
• Make the purpose(s) clear at the point of data collection
• Change of circumstances – what happens to the data then?
• Subsequent use of data for direct marketing purposes
• Data cleansing – regular and ad hoc
Principle 3: Adequate, relevant
and not excessive
• Minimum amount of information required
• Additional information for specific individuals
• Collect data that you will use now
• Collection of data that ‘may be useful’ in the future is not permitted
Principle 4: Accurate and kept up
to date
• Take reasonable steps to ensure accuracy (but what is
‘reasonable’?)
• Ensure data is not incorrect or misleading
• Undertake regular data cleansing
• Clean data against the relevant preference service files and other
appropriate cleansing files
Principle 5: Not kept for longer
than necessary
• Keep for as long as purpose collected for
• Suppression lists
Principle 6: Processed in
accordance with the rights of data
subjects
• Subject access requests
• ‘Where did you get my data from?’
• Right to prevent direct marketing
• Customer service / legally required communications – no opt-out
provision required
• Right to have inaccurate data corrected
Principle 7: Technological and
organisational security
• Data security must be appropriate – take account of:
– Current state of technological development
– Cost of implementing security measures
– Potential harm that could result from a data breach
– Nature of data to be protected – non/sensitive?
• Need for risk assessment and risk management techniques
• Record your findings and assessments
Principle 7: Technological and
organisational security (continued)
• Ensure adequate organisational data security measures
• Prevent unauthorised as well as unlawful processing or disclosure
of data
• Security measures by data controller and data processor
• Data processing and transfer agreements in place
• Staff training
• Data access on a ‘need to know’ basis – individual log-ins only
• Secure disposal of data – internally/externally - keep records
Principle 8: Processed within the
EEA unless adequate protection in
place
• Data can be freely transferred within the EEA (providing data
transfer agreements are in place)
• Do not transfer data unless the country (destination and countries
data is routed via) have an adequate level of data protection
• Need to inform individuals before transferring their data outside
the EEA but do not need their consent
Understanding the law 2
• Privacy and Electronic Communications Regulations 2003 (PECR)
– Came into force 11 December 2003
– Covers electronic communications – email, telephone, SMS
Key rules
• Sender must not conceal their identity
• Communication must have valid address where opt-outs can be
sent
• Opt-in required for individuals (B2C)
• Soft opt-in/existing customer exemption – available:
– When you are collecting the address/mobile number in the sale
or negotiations for the sale of a product or service;
– You only send communications about similar products and
services;
– You provided an opportunity at time of collection to opt-out.
Key points
• Existing customer exemption: Not an excuse for unsolicited contact
where correct permissions were never obtained
• B2B – Opt-out and marketing message needs to directly relate to
the work they do.
• Subject headers in emails must be clear and accurate
• Free and simple-to-use opt-out method must always be provided
• Action unsubscribe requests promptly – add to internal suppression
file
• Maintain different flags for different types of communication –
helps to avoid general opt-outs for all channels
Practical tips for marketers
• Data capture forms
• Marketing permissions
• Sourcing data
• Regaining lost permission
Data capture forms
• Key information to include;
– Why the data is being requested
– What the data will be used for
– Provision of an opt-in/out for marketing
– Marketing channels to be used
– Link to privacy policy
• Key information to include in privacy policy
– How the data subject can opt-out of marketing
– If the data will be processed outside the EEA
– How long the data will be kept for
– How to make a subject access request
– How to make a complaint regarding use of data
Marketing permissions
Own marketing 3rd party marketing Own marketing 3rd party marketing
Mail opt-out
opt-out (MPS
screening) opt-out opt-out
Telephone opt-out
opt-out (TPS
screening) opt-out
opt-out (TPS/ CTPS
screening)
Email
opt-in/ soft opt-
in opt-in
opt-in (unless
corporate
subscriber
exemption)
opt-in (unless
corporate subscriber
exemption)
SMS
opt-in/ soft opt-
in opt-in opt-in opt-in
Fax opt-in opt-in opt-out
opt-out (FPS
screening)
B2C B2B
Sourcing data/ Due diligence
• Who compiled the list? When? Has it been amended or updated
since?
• When was consent obtained?
• Who obtained consent and what was the context?
• Was it opt-in or opt-out?
• Was information provided clearly and intelligibly? How was it
provided?
• Did it list organisations by name, by description, or any third party?
Regaining lost permissions
• Why was permission lost:
– Poor customer service?
– Poor communications timing?
– Inappropriate offers?
– In-house technical issues – permissions not recorded on CRM
system
• Revalidation exercise – obtaining up-to-date data
• Can very occasionally include request regarding marketing update
in a service message providing it is a minor part of the message
• If you have only lost permission for certain channels, contact via
another channel to update permissions
Determining whether data
controller or data processor
• Look at activities each party is carrying out
• Data Controller – over-arching decisions
• Data Processor – freedom to use technical knowledge
• If both parties working well together and dealing with data
protection compliance – no real issues
• Important to determine for when things go wrong e.g. data breach
• Establish roles and responsibilities before work starts
• Obligations of both parties under DPA 1998
• Need for operational guidance behind data processing contract
• Remember that a data processor will also be a data controller in
respect of own employees .
Summary and questions?
Switchboard: (020)7291 3300
Legal helpdesk: legaladvice@dma.org.uk
My direct email: james.milligan@dma.org.uk

More Related Content

What's hot

Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
Fionnuala Hendrick
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
Browne Jacobson LLP
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
Harrison Clark Rickerbys
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
Andrew Sharpe
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
Harrison Clark Rickerbys
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
Rachel Aldighieri
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
Symptai Consulting Limited
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
Rachel Aldighieri
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
BrightPay Payroll and Auto Enrolment Software
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
GrittyCC
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
Vuzion
 
Legal update
Legal updateLegal update
Legal update
Rachel Aldighieri
 
Data Loss: Derelication of Duties?
Data Loss: Derelication of Duties?Data Loss: Derelication of Duties?
Data Loss: Derelication of Duties?
Napier University
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
Priyanka Aash
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
HackerOne
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
BartLieben
 

What's hot (20)

Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Legal update
Legal updateLegal update
Legal update
 
Data Loss: Derelication of Duties?
Data Loss: Derelication of Duties?Data Loss: Derelication of Duties?
Data Loss: Derelication of Duties?
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 

Viewers also liked

Html5与i pad交互杂志
Html5与i pad交互杂志Html5与i pad交互杂志
Html5与i pad交互杂志
momobeijing
 
Neuro sky overview orange event
Neuro sky overview   orange eventNeuro sky overview   orange event
Neuro sky overview orange event
momobeijing
 
New ASA Digital Remit
New ASA Digital RemitNew ASA Digital Remit
New ASA Digital Remit
Rachel Aldighieri
 
National client email report
National client email reportNational client email report
National client email report
Rachel Aldighieri
 
Nuevo dialogo
Nuevo dialogoNuevo dialogo
Nuevo dialogo
africasanchez1995
 
从产品到应用+开发+产学研
从产品到应用+开发+产学研从产品到应用+开发+产学研
从产品到应用+开发+产学研momobeijing
 
Presentación impress 2.
Presentación impress 2.Presentación impress 2.
Presentación impress 2.
imnhhhc Hujbvv
 
Data Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, MicrosoftData Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, Microsoft
Rachel Aldighieri
 
DMA-IDM Conference 2013 - the evolution of communication
DMA-IDM Conference 2013 - the evolution of communicationDMA-IDM Conference 2013 - the evolution of communication
DMA-IDM Conference 2013 - the evolution of communication
Rachel Aldighieri
 
Html5与i pad交互杂志
Html5与i pad交互杂志Html5与i pad交互杂志
Html5与i pad交互杂志
momobeijing
 
Google kick ass-game_programming_with_gwt
Google   kick ass-game_programming_with_gwtGoogle   kick ass-game_programming_with_gwt
Google kick ass-game_programming_with_gwt
momobeijing
 
Touch china en_mm
Touch china en_mmTouch china en_mm
Touch china en_mm
momobeijing
 
Pinnock SGP
Pinnock SGPPinnock SGP
Pinnock SGP
JalenPinnock
 
Caitlin Ryan
Caitlin RyanCaitlin Ryan
Caitlin Ryan
Rachel Aldighieri
 
Tf mobiel mondya中国文化与产品设计s
Tf mobiel mondya中国文化与产品设计sTf mobiel mondya中国文化与产品设计s
Tf mobiel mondya中国文化与产品设计smomobeijing
 
Planning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaignPlanning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaign
Rachel Aldighieri
 
设计驱动移动应用创新
设计驱动移动应用创新设计驱动移动应用创新
设计驱动移动应用创新
momobeijing
 
Young marketers rising
Young marketers risingYoung marketers rising
Young marketers rising
Rachel Aldighieri
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013
Rachel Aldighieri
 

Viewers also liked (20)

Html5与i pad交互杂志
Html5与i pad交互杂志Html5与i pad交互杂志
Html5与i pad交互杂志
 
Neuro sky overview orange event
Neuro sky overview   orange eventNeuro sky overview   orange event
Neuro sky overview orange event
 
New ASA Digital Remit
New ASA Digital RemitNew ASA Digital Remit
New ASA Digital Remit
 
National client email report
National client email reportNational client email report
National client email report
 
Nuevo dialogo
Nuevo dialogoNuevo dialogo
Nuevo dialogo
 
从产品到应用+开发+产学研
从产品到应用+开发+产学研从产品到应用+开发+产学研
从产品到应用+开发+产学研
 
Presentación impress 2.
Presentación impress 2.Presentación impress 2.
Presentación impress 2.
 
Data Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, MicrosoftData Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, Microsoft
 
DMA-IDM Conference 2013 - the evolution of communication
DMA-IDM Conference 2013 - the evolution of communicationDMA-IDM Conference 2013 - the evolution of communication
DMA-IDM Conference 2013 - the evolution of communication
 
Html5与i pad交互杂志
Html5与i pad交互杂志Html5与i pad交互杂志
Html5与i pad交互杂志
 
Google kick ass-game_programming_with_gwt
Google   kick ass-game_programming_with_gwtGoogle   kick ass-game_programming_with_gwt
Google kick ass-game_programming_with_gwt
 
Touch china en_mm
Touch china en_mmTouch china en_mm
Touch china en_mm
 
Pinnock SGP
Pinnock SGPPinnock SGP
Pinnock SGP
 
Caitlin Ryan
Caitlin RyanCaitlin Ryan
Caitlin Ryan
 
Tf mobiel mondya中国文化与产品设计s
Tf mobiel mondya中国文化与产品设计sTf mobiel mondya中国文化与产品设计s
Tf mobiel mondya中国文化与产品设计s
 
Planning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaignPlanning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaign
 
Carta a meneceu
Carta a meneceuCarta a meneceu
Carta a meneceu
 
设计驱动移动应用创新
设计驱动移动应用创新设计驱动移动应用创新
设计驱动移动应用创新
 
Young marketers rising
Young marketers risingYoung marketers rising
Young marketers rising
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013
 

Similar to An introduction to data protection - Edinburgh

3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
CFG
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
Ian Clive Oultram
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
MyComplianceOffice
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
NiclasGranqvist
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
iof_events
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
Craig Clark ITIL, CIS LI,EU GDPR P
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
MichelleSaver
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
Financial Poise
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
TimBee1
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
TimBee1
 
Living with gdpr
Living with gdprLiving with gdpr
Living with gdpr
Sarah Chadbourne
 
DLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesDLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The Challenges
Napier University
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
Emily Jones
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
m-hance
 

Similar to An introduction to data protection - Edinburgh (19)

3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
Living with gdpr
Living with gdprLiving with gdpr
Living with gdpr
 
DLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesDLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The Challenges
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 

More from Rachel Aldighieri

Navigating B2B marketing
Navigating B2B marketingNavigating B2B marketing
Navigating B2B marketing
Rachel Aldighieri
 
Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015
Rachel Aldighieri
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to know
Rachel Aldighieri
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skills
Rachel Aldighieri
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...
Rachel Aldighieri
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order Form
Rachel Aldighieri
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
Rachel Aldighieri
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 August
Rachel Aldighieri
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015
Rachel Aldighieri
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - Manchester
Rachel Aldighieri
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015
Rachel Aldighieri
 
Legal update - 1 July
Legal update - 1 JulyLegal update - 1 July
Legal update - 1 July
Rachel Aldighieri
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015
Rachel Aldighieri
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - Manchester
Rachel Aldighieri
 
ZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROIZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROI
Rachel Aldighieri
 
Simon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiSimon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBi
Rachel Aldighieri
 
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Rachel Aldighieri
 
Tim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADTim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&AD
Rachel Aldighieri
 
David Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltDavid Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, Redsalt
Rachel Aldighieri
 
Thinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberThinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 November
Rachel Aldighieri
 

More from Rachel Aldighieri (20)

Navigating B2B marketing
Navigating B2B marketingNavigating B2B marketing
Navigating B2B marketing
 
Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to know
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skills
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order Form
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 August
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - Manchester
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015
 
Legal update - 1 July
Legal update - 1 JulyLegal update - 1 July
Legal update - 1 July
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - Manchester
 
ZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROIZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROI
 
Simon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiSimon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBi
 
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...
 
Tim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADTim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&AD
 
David Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltDavid Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, Redsalt
 
Thinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberThinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 November
 

Recently uploaded

Pillar-Based Marketing - Ryan Brock, DemandJump
Pillar-Based Marketing - Ryan Brock, DemandJumpPillar-Based Marketing - Ryan Brock, DemandJump
Mastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis YuMastering SEO for Google in the AI Era - Dennis Yu
Mastering Your Online Visibility - Fernando Angulo
Mastering Your Online Visibility - Fernando AnguloMastering Your Online Visibility - Fernando Angulo
Mastering The Best Restaurant Advertising Campaigns Detailed Guide
Mastering The Best Restaurant Advertising Campaigns Detailed GuideMastering The Best Restaurant Advertising Campaigns Detailed Guide
Mastering The Best Restaurant Advertising Campaigns Detailed Guide
Kopa Global Technologies
 
How to Use AI to Write a High-Quality Article that Ranks
How to Use AI to Write a High-Quality Article that RanksHow to Use AI to Write a High-Quality Article that Ranks
How to Use AI to Write a High-Quality Article that Ranks
minatamang0021
 
Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...
Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...
Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
Mastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis YuMastering SEO for Google in the AI Era - Dennis Yu
WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...
WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...
WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...
Veronika Höller
 
Grow Your Business Online: Introduction to Digital Marketing
Grow Your Business Online: Introduction to Digital MarketingGrow Your Business Online: Introduction to Digital Marketing
Grow Your Business Online: Introduction to Digital Marketing
Digital Discovery Institute
 
Email Marketing Master Class - Chris Ferris
Email Marketing Master Class - Chris FerrisEmail Marketing Master Class - Chris Ferris
Gokila digital marketing| consultant| Coimbatore
Gokila digital marketing| consultant| CoimbatoreGokila digital marketing| consultant| Coimbatore
Gokila digital marketing| consultant| Coimbatore
dmgokila
 
Top digital marketing institutein noida
Top digital marketing institutein noidaTop digital marketing institutein noida
Top digital marketing institutein noida
aditisingh6607
 
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
How to Kickstart Content Marketing With A Small Team - Dennis Shiao
How to Kickstart Content Marketing With A Small Team - Dennis ShiaoHow to Kickstart Content Marketing With A Small Team - Dennis Shiao
How to Kickstart Content Marketing With A Small Team - Dennis Shiao
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
PickUp_conversational AI_Capex, Inc._20240611
PickUp_conversational AI_Capex, Inc._20240611PickUp_conversational AI_Capex, Inc._20240611
PickUp_conversational AI_Capex, Inc._20240611
Shuntaro Kogame
 
Yes, It's Your Fault Book Launch Webinar
Yes, It's Your Fault Book Launch WebinarYes, It's Your Fault Book Launch Webinar
Yes, It's Your Fault Book Launch Webinar
Demandbase
 
AI Driven Emotional Recognition in Digital Ads - Tarun Gupta
AI Driven Emotional Recognition in Digital Ads - Tarun GuptaAI Driven Emotional Recognition in Digital Ads - Tarun Gupta
AI Driven Emotional Recognition in Digital Ads - Tarun Gupta
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...
What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...
What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...
Demandbase
 
From Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptx
From Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptxFrom Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptx
From Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptx
Boston SEO Services
 

Recently uploaded (20)

Pillar-Based Marketing - Ryan Brock, DemandJump
Pillar-Based Marketing - Ryan Brock, DemandJumpPillar-Based Marketing - Ryan Brock, DemandJump
Pillar-Based Marketing - Ryan Brock, DemandJump
 
Mastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis YuMastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis Yu
 
Mastering Your Online Visibility - Fernando Angulo
Mastering Your Online Visibility - Fernando AnguloMastering Your Online Visibility - Fernando Angulo
Mastering Your Online Visibility - Fernando Angulo
 
Mastering The Best Restaurant Advertising Campaigns Detailed Guide
Mastering The Best Restaurant Advertising Campaigns Detailed GuideMastering The Best Restaurant Advertising Campaigns Detailed Guide
Mastering The Best Restaurant Advertising Campaigns Detailed Guide
 
How to Use AI to Write a High-Quality Article that Ranks
How to Use AI to Write a High-Quality Article that RanksHow to Use AI to Write a High-Quality Article that Ranks
How to Use AI to Write a High-Quality Article that Ranks
 
Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...
Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...
Digital Marketing Trends - Experts Insights on How to Gain a Competitive Edge...
 
Mastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis YuMastering SEO for Google in the AI Era - Dennis Yu
Mastering SEO for Google in the AI Era - Dennis Yu
 
WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...
WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...
WTS-Berlin-2024-Veronika-Höller-Innovate-NextGEN-SEO-Merging-AI-Multimedia-an...
 
Grow Your Business Online: Introduction to Digital Marketing
Grow Your Business Online: Introduction to Digital MarketingGrow Your Business Online: Introduction to Digital Marketing
Grow Your Business Online: Introduction to Digital Marketing
 
Email Marketing Master Class - Chris Ferris
Email Marketing Master Class - Chris FerrisEmail Marketing Master Class - Chris Ferris
Email Marketing Master Class - Chris Ferris
 
Gokila digital marketing| consultant| Coimbatore
Gokila digital marketing| consultant| CoimbatoreGokila digital marketing| consultant| Coimbatore
Gokila digital marketing| consultant| Coimbatore
 
Top digital marketing institutein noida
Top digital marketing institutein noidaTop digital marketing institutein noida
Top digital marketing institutein noida
 
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
Get Off the Bandwagon - Separating Digital Marketing Myths from Truth - Scott...
 
How to Kickstart Content Marketing With A Small Team - Dennis Shiao
How to Kickstart Content Marketing With A Small Team - Dennis ShiaoHow to Kickstart Content Marketing With A Small Team - Dennis Shiao
How to Kickstart Content Marketing With A Small Team - Dennis Shiao
 
PickUp_conversational AI_Capex, Inc._20240611
PickUp_conversational AI_Capex, Inc._20240611PickUp_conversational AI_Capex, Inc._20240611
PickUp_conversational AI_Capex, Inc._20240611
 
Yes, It's Your Fault Book Launch Webinar
Yes, It's Your Fault Book Launch WebinarYes, It's Your Fault Book Launch Webinar
Yes, It's Your Fault Book Launch Webinar
 
AI Driven Emotional Recognition in Digital Ads - Tarun Gupta
AI Driven Emotional Recognition in Digital Ads - Tarun GuptaAI Driven Emotional Recognition in Digital Ads - Tarun Gupta
AI Driven Emotional Recognition in Digital Ads - Tarun Gupta
 
What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...
What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...
What’s “In” and “Out” for ABM in 2024: Plays That Help You Grow and Ones to L...
 
From Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptx
From Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptxFrom Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptx
From Hope to Despair The Top 10 Reasons Businesses Ditch SEO Tactics.pptx
 
Unleash the Power of Storytelling - Win Hearts, Change Minds, Get Results - R...
Unleash the Power of Storytelling - Win Hearts, Change Minds, Get Results - R...Unleash the Power of Storytelling - Win Hearts, Change Minds, Get Results - R...
Unleash the Power of Storytelling - Win Hearts, Change Minds, Get Results - R...
 

An introduction to data protection - Edinburgh

  • 1. Data protection 2013 Friday 8 February #dmadata Supported by An introduction to data protection Thursday 9 October 2014, Tangible Barge James Milligan Solicitor DMA
  • 2. Agenda 1.00pm Registration and breakfast 1.30pm Why is data protection important? 1.40pm Understanding the law The Data Protection Act 1998 Key terms 8 Principles 2.40pm Break 3.00pm Understanding the law The Privacy and Electronic Communications Regulation 2003 Key rules Key points 3.30pm Practical tips for marketers 4.00pm Summary and questions 4.30pm Close
  • 3. Why is it important? • It helps us to protect information about ourselves and others • It helps us avoid damage to the reputation of our organisation • It makes good business sense – it can increase efficiency and effectiveness • It helps us avoid enforcement action by the Information Commissioner – both employers and employees can be prosecuted – companies can face a monetary penalty of up to £500,000 for major breaches
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10. Understanding the law 1 • Data Protection Act 1998 (DPA) – Came into force 1 March 2000 – Replaced 1984 Act – Covers doing anything with data – Applies electronic records and some manual records
  • 11. Key Terms • Personal data – any data that can be used to identify a living individual – Examples of personal data can include: • Name and address • Email address (even business email addresses if they are non generic) • Name and telephone number • Photographs – Only personal data is protected by the DPA • Sensitive personal data – any data relating to: • Health • Race or ethnic origin • Political opinions • Religious beliefs • Trade union membership • Sex life • Criminal proceedings or convictions
  • 12. Key terms • Processing – obtaining, recording or holding information or carrying out any operation on the information including • Organising • Adapting • Retrieving • Disclosing • Blocking • Destroying • Data subject – a living identifiable individual to whom the personal data relates
  • 13. Key Terms • Data controller - Determines how data will be used - Usually owns or rents the data (may be done by 3rd party on their behalf) - Required to notify (register) as a controller with the ICO - May be fined by ICO if any data breaches arise • Data processor - Processes data on behalf of controller or other processor - Processing can be anything from data storage to advanced data manipulation and modelling - Includes companies that manage / broker / collect data on behalf of others
  • 14. The 8 Principles • Fairly and lawfully collected • Processed for specified and limited purposes • Adequate, relevant and not excessive • Accurate and kept up to date • Not kept for longer than necessary • Processed in accordance with Individuals’ rights • Security – appropriate technical and organisational measures • Not transferred outside the European Economic Area (EEA) unless adequate protections are in place • (EEA: The 28 member states of the EU, plus Iceland, Liechtenstein and Norway)
  • 15. Principle 1: Fairly and lawfully collected • Fair processing information provided • Organisation’s identity given • Purpose of collection made clear • Further information necessary • Correct permissions obtained - Implied consent: opt-out mechanism provided - Express consent: opt-in mechanism provided • Sensitive personal data only captured if strictly necessary
  • 16. Principle 2: Processed for limited purposes • Only process data for the purpose(s) you told the individual • Make the purpose(s) clear at the point of data collection • Change of circumstances – what happens to the data then? • Subsequent use of data for direct marketing purposes • Data cleansing – regular and ad hoc
  • 17. Principle 3: Adequate, relevant and not excessive • Minimum amount of information required • Additional information for specific individuals • Collect data that you will use now • Collection of data that ‘may be useful’ in the future is not permitted
  • 18. Principle 4: Accurate and kept up to date • Take reasonable steps to ensure accuracy (but what is ‘reasonable’?) • Ensure data is not incorrect or misleading • Undertake regular data cleansing • Clean data against the relevant preference service files and other appropriate cleansing files
  • 19. Principle 5: Not kept for longer than necessary • Keep for as long as purpose collected for • Suppression lists
  • 20. Principle 6: Processed in accordance with the rights of data subjects • Subject access requests • ‘Where did you get my data from?’ • Right to prevent direct marketing • Customer service / legally required communications – no opt-out provision required • Right to have inaccurate data corrected
  • 21. Principle 7: Technological and organisational security • Data security must be appropriate – take account of: – Current state of technological development – Cost of implementing security measures – Potential harm that could result from a data breach – Nature of data to be protected – non/sensitive? • Need for risk assessment and risk management techniques • Record your findings and assessments
  • 22. Principle 7: Technological and organisational security (continued) • Ensure adequate organisational data security measures • Prevent unauthorised as well as unlawful processing or disclosure of data • Security measures by data controller and data processor • Data processing and transfer agreements in place • Staff training • Data access on a ‘need to know’ basis – individual log-ins only • Secure disposal of data – internally/externally - keep records
  • 23. Principle 8: Processed within the EEA unless adequate protection in place • Data can be freely transferred within the EEA (providing data transfer agreements are in place) • Do not transfer data unless the country (destination and countries data is routed via) have an adequate level of data protection • Need to inform individuals before transferring their data outside the EEA but do not need their consent
  • 24. Understanding the law 2 • Privacy and Electronic Communications Regulations 2003 (PECR) – Came into force 11 December 2003 – Covers electronic communications – email, telephone, SMS
  • 25. Key rules • Sender must not conceal their identity • Communication must have valid address where opt-outs can be sent • Opt-in required for individuals (B2C) • Soft opt-in/existing customer exemption – available: – When you are collecting the address/mobile number in the sale or negotiations for the sale of a product or service; – You only send communications about similar products and services; – You provided an opportunity at time of collection to opt-out.
  • 26. Key points • Existing customer exemption: Not an excuse for unsolicited contact where correct permissions were never obtained • B2B – Opt-out and marketing message needs to directly relate to the work they do. • Subject headers in emails must be clear and accurate • Free and simple-to-use opt-out method must always be provided • Action unsubscribe requests promptly – add to internal suppression file • Maintain different flags for different types of communication – helps to avoid general opt-outs for all channels
  • 27. Practical tips for marketers • Data capture forms • Marketing permissions • Sourcing data • Regaining lost permission
  • 28. Data capture forms • Key information to include; – Why the data is being requested – What the data will be used for – Provision of an opt-in/out for marketing – Marketing channels to be used – Link to privacy policy • Key information to include in privacy policy – How the data subject can opt-out of marketing – If the data will be processed outside the EEA – How long the data will be kept for – How to make a subject access request – How to make a complaint regarding use of data
  • 29. Marketing permissions Own marketing 3rd party marketing Own marketing 3rd party marketing Mail opt-out opt-out (MPS screening) opt-out opt-out Telephone opt-out opt-out (TPS screening) opt-out opt-out (TPS/ CTPS screening) Email opt-in/ soft opt- in opt-in opt-in (unless corporate subscriber exemption) opt-in (unless corporate subscriber exemption) SMS opt-in/ soft opt- in opt-in opt-in opt-in Fax opt-in opt-in opt-out opt-out (FPS screening) B2C B2B
  • 30. Sourcing data/ Due diligence • Who compiled the list? When? Has it been amended or updated since? • When was consent obtained? • Who obtained consent and what was the context? • Was it opt-in or opt-out? • Was information provided clearly and intelligibly? How was it provided? • Did it list organisations by name, by description, or any third party?
  • 31. Regaining lost permissions • Why was permission lost: – Poor customer service? – Poor communications timing? – Inappropriate offers? – In-house technical issues – permissions not recorded on CRM system • Revalidation exercise – obtaining up-to-date data • Can very occasionally include request regarding marketing update in a service message providing it is a minor part of the message • If you have only lost permission for certain channels, contact via another channel to update permissions
  • 32. Determining whether data controller or data processor • Look at activities each party is carrying out • Data Controller – over-arching decisions • Data Processor – freedom to use technical knowledge • If both parties working well together and dealing with data protection compliance – no real issues • Important to determine for when things go wrong e.g. data breach • Establish roles and responsibilities before work starts • Obligations of both parties under DPA 1998 • Need for operational guidance behind data processing contract • Remember that a data processor will also be a data controller in respect of own employees .
  • 33. Summary and questions? Switchboard: (020)7291 3300 Legal helpdesk: legaladvice@dma.org.uk My direct email: james.milligan@dma.org.uk