SlideShare a Scribd company logo
AN OVERVIEW OF GDPR
MASOOD BUTT – COMMERCIAL & REGULATORY LAWYER
AHSAN HUSAIN – HEAD OF MIS & IT AND [DATA COMPLIANCE]
DISCLAIMER
The information contained herein and the statements
expressed are of a general nature and are not intended to
address the circumstances of any particular individual or
entity. Although we endeavour to provide accurate and timely
information and use sources we consider reliable, there can be
no guarantee that such information is accurate as of the date
it is received or that it will continue to be accurate in the
future. No one should act on such information without
appropriate professional advice after a thorough examination
of the particular situation.
Some Research based FACTS
1. 98% of the UK private sector is not ready for the GDPR
2. 84% of the small and medium sized businesses and 43% of
the large companies are unaware of the implications of the
GDPR.
3. 75% of the data held by companies shall become unuseable
or risky after GDPR.
4. 48% of the adults surveyed in the UK confirmed they shall
exercise their rights to Data protection afforded under GDPR.
Contents
Data Protection Frame Work
GDPR – Responsibilities
GDPR – Changes
GDPR - Exemptions
GDPR – Rights
Penalty
TEN HIGH LEVEL STEPS
Data Protection Framework
1. Data Protection Directive EU 95/46
2. Data Protection Act 1998.
3. Information Commissioner’s Office (ICO).
3. A 2008 Council Framework Decision applies to the cross-
border processing of personal data in police and judicial
cooperation in criminal matters.
4. Criminal Justice and Data Protection (Protocol No. 36)
Regulations 2014.
Data Protection framework
1. The EU’s Charter of Fundamental Rights and Freedoms.
2. In January 2012, a new EU legislative framework for data
protection.
In its now finalised form, this has two elements:
• The General Data Protection Regulation (“GDPR”) EU
2016/679
• The Police and Criminal Justice Directive (the “Law
Enforcement Directive” (LED), also known as the “PCJ
Directive”) EU 2016/680
The General Data Protection Regulation (GDPR)
Passed on 24 May 2016
Coming into force on 25th May 2018
Duty Holders:
Data controllers - the persons or bodies that determine the purposes and means of processing of personal
data) and
Data processors - those who process personal data on behalf of a controller.
Right Holders:
Data subjects - (the individuals whose personal data is being processed).
Data – any information relating to an identifiable natural person –Art 4 (1)
Personal Data Breach means breach of security accidental or unlawful destruction,
loss, alteration, unauthorised disclosure of or access to personal data stored,
processed or transmitted. (Art 4 (12)
Changes made by GDPR
•Territorial scope
•Data protection by design and default
•A European Data Protection Board
•Increased penalties
•Data protection officers
•A “one-stop shop” principle
• Enhanced transparency duties when communicating with
data subjects
Exemption - Art 9
Exempted for data subjects, where processing does not include data on;
Racial;
Ethnic;
Political opinions;
Religious or philosophical beliefs;
Trade union membership;
Genetic data;
Biometric data;
Health data;
Sex life or sexual orientation data;
Exemptions – Art 30(5)
•Organisation employs less than 250 staff;
• unless
•Likely to result in a risk to the rights or freedoms;
•Occasional processing;
•Special categories as above;
•Data relating to criminal conviction and offences.
Data subject rights
Lawful processing – express and specific consent - Art 6
Right to withdraw consent at any time - Art 7
Right of access - Art 15
Right to rectification - Art 16
Right to erasure (forgotten) - Art 17
Right to restriction - Art 18
Right to be notified Art - 19
Right to data portability - Art 20
Right to object - Art 21
Right for not to be profiled automatically - Art 22
Right to lodge a complaint to supervisory authority - Art 77
Right to an effective judicial remedy against controller or processor - Art 79
Right to compensation for damages - Art 82
The General Data Protection Regulation (GDPR)
Strengthened consent is one of the major changes that the GDPR will make for data subjects.
Article 4 (11) defines consent as follows:
‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data
subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the
processing of personal data relating to him
or her.
The definition’s references to “unambiguous” and “clear affirmative action”
are new.
A data controller must be able to demonstrate that a data subject has consented to the processing of their
personal data. It must be possible to withdraw consent at any time.
Article 7 (conditions for consent) states:
1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has
consented to processing of his or her personal data.
PENALTY
Non compliance with an Order of
supervisory body be subject to
20,000 000 EUR or 4% global
annual turn over - Art 83
Further costs
• In addition to the sanctions, fines and reputational damage.
• Problems which are only identified after the project has launched are more
likely to require expensive fixes.
• The use of biometric information or potentially intrusive tracking technologies
may cause increased concern and cause people to avoid engaging with the
organisation.
• Information which is collected and stored unnecessarily, or is not properly
managed so that duplicate records are created, is less useful to the business.
• Public distrust about how information is used can damage an organisation’s
reputation and lead to loss of business.
• Data losses which damage individuals could lead to claims for compensation.
Ten HIGH LEVEL STEPS
Here are ten high-level steps to help you prepare.
1 be aware and be accountable;
2 Create/Renew Data Policy;
3 Classify Risk & Retention;
4 Evaluate and actively manage existing contracts with third
party service providers;
5 Establish, embed and test a procedure to handle personal
data incidents • Increase internal privacy-awareness;
Ten HIGH LEVEL STEPS –cont.
6 Ensure how to recognise and respond appropriately to requests
from data subjects;
7 Determine and document Privacy Impact Assessment and
appointment of Data Protection Officer;
8 Review and amend and document privacy policy and statements
and notices to meet the enhanced transparency requirements;
9 Document and identify the main causes of any potential data
breach;
10. Would you be able to notify the regulator of any data breach
within 72 hours?
AN OVERVIEW OF GDPR
MASOOD BUTT – COMMERCIAL & REGULATORY LAWYER
AHSAN HUSAIN – HEAD OF MIS & IT AND [DATA COMPLIANCE]

More Related Content

What's hot

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Kimberly Simon MBA
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
SPIN Chennai
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
DipanjanDey12
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Cvent
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Extentia Information Technology
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
RahulGarg294918
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
Martin Hawksey
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Caroline Boscher
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Qualsys Ltd
 
GDPR: Data Breach Notification and Communications
GDPR: Data Breach Notification and CommunicationsGDPR: Data Breach Notification and Communications
GDPR: Data Breach Notification and Communications
Charlie Pownall
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
accenture
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
Vertex Holdings
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
WilmerHale
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
Craig Clark ITIL, CIS LI,EU GDPR P
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Priyanka Aash
 
Data protection and privacy
Data protection and privacyData protection and privacy
Data protection and privacy
himanshu jain
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risks
IT Governance Ltd
 
kvkk sunum
kvkk sunumkvkk sunum
kvkk sunum
Bilgi İşlem
 

What's hot (20)

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR and Security.pdf
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR: Data Breach Notification and Communications
GDPR: Data Breach Notification and CommunicationsGDPR: Data Breach Notification and Communications
GDPR: Data Breach Notification and Communications
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
Data protection and privacy
Data protection and privacyData protection and privacy
Data protection and privacy
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risks
 
kvkk sunum
kvkk sunumkvkk sunum
kvkk sunum
 

Similar to An Overview of GDPR

GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
Morris Dorfer
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
zayadeen2003
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
NetworkIQ
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
PECB
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
Acquia
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPR
Jenny Ferguson
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
SecurityScorecard
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
Jake DiMare
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
SilverTech
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
Olivier Vandeputte
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
Tim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
Tim Hyman LLB
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
Parsons Behle & Latimer
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
Happiest Minds Technologies
 
GDPR for Security Professionals
GDPR for Security ProfessionalsGDPR for Security Professionals
GDPR for Security Professionals
Saumya Vishnoi
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
dan hyde
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It Webinar
Sagittarius
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 

Similar to An Overview of GDPR (20)

GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPR
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
GDPR for Security Professionals
GDPR for Security ProfessionalsGDPR for Security Professionals
GDPR for Security Professionals
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It Webinar
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 

More from The Pathway Group

Talk to us - Safaraz Ali for linkedin.pptx
Talk to us - Safaraz Ali for linkedin.pptxTalk to us - Safaraz Ali for linkedin.pptx
Talk to us - Safaraz Ali for linkedin.pptx
The Pathway Group
 
Responsible Individual Training - F5 Foster Care.pptx
Responsible Individual Training -  F5 Foster Care.pptxResponsible Individual Training -  F5 Foster Care.pptx
Responsible Individual Training - F5 Foster Care.pptx
The Pathway Group
 
Responsible Individual Training fostercare- F5 Foster Care UK
Responsible Individual Training  fostercare-  F5 Foster Care UKResponsible Individual Training  fostercare-  F5 Foster Care UK
Responsible Individual Training fostercare- F5 Foster Care UK
The Pathway Group
 
Pathway Group 2024 by Safaraz Ali.pdf
Pathway Group 2024 by Safaraz Ali.pdfPathway Group 2024 by Safaraz Ali.pdf
Pathway Group 2024 by Safaraz Ali.pdf
The Pathway Group
 
1973 Toyota Production System Handbook
1973 Toyota Production System Handbook1973 Toyota Production System Handbook
1973 Toyota Production System Handbook
The Pathway Group
 
Multicultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdf
Multicultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdfMulticultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdf
Multicultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdf
The Pathway Group
 
Empowering The Nation - White Paper .pdf
Empowering The Nation - White Paper .pdfEmpowering The Nation - White Paper .pdf
Empowering The Nation - White Paper .pdf
The Pathway Group
 
Peer Meetup by Safaraz Ali 13.Oct.2023.pdf
Peer Meetup by Safaraz Ali 13.Oct.2023.pdfPeer Meetup by Safaraz Ali 13.Oct.2023.pdf
Peer Meetup by Safaraz Ali 13.Oct.2023.pdf
The Pathway Group
 
Peer Meetup by Safaraz Ali 13.Oct.2023.ppt
Peer Meetup by Safaraz Ali 13.Oct.2023.pptPeer Meetup by Safaraz Ali 13.Oct.2023.ppt
Peer Meetup by Safaraz Ali 13.Oct.2023.ppt
The Pathway Group
 
A Guide to Apprenticeships for the Higher Education Sector.pdf
A Guide to Apprenticeships for the Higher Education Sector.pdfA Guide to Apprenticeships for the Higher Education Sector.pdf
A Guide to Apprenticeships for the Higher Education Sector.pdf
The Pathway Group
 
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdf
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdfAll Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdf
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdf
The Pathway Group
 
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.ppt
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pptAll Matters Regulatory - Apprenticeship Training Material - Pathway Group.ppt
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.ppt
The Pathway Group
 
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
The Pathway Group
 
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
The Pathway Group
 
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
The Pathway Group
 
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
The Pathway Group
 
The World of Learning - Apprenticeship Training Material - Pathway Group.ppt
The World of Learning - Apprenticeship Training Material - Pathway Group.pptThe World of Learning - Apprenticeship Training Material - Pathway Group.ppt
The World of Learning - Apprenticeship Training Material - Pathway Group.ppt
The Pathway Group
 
The World of Learning - Apprenticeship Training Material - Pathway Group.pdf
The World of Learning - Apprenticeship Training Material - Pathway Group.pdfThe World of Learning - Apprenticeship Training Material - Pathway Group.pdf
The World of Learning - Apprenticeship Training Material - Pathway Group.pdf
The Pathway Group
 
How Independent Training Providers (ITPs) can survive and thrive in an inflat...
How Independent Training Providers (ITPs) can survive and thrive in an inflat...How Independent Training Providers (ITPs) can survive and thrive in an inflat...
How Independent Training Providers (ITPs) can survive and thrive in an inflat...
The Pathway Group
 
Birmingham Pakistani Report PDF June 2023.pdf
Birmingham Pakistani Report PDF June 2023.pdfBirmingham Pakistani Report PDF June 2023.pdf
Birmingham Pakistani Report PDF June 2023.pdf
The Pathway Group
 

More from The Pathway Group (20)

Talk to us - Safaraz Ali for linkedin.pptx
Talk to us - Safaraz Ali for linkedin.pptxTalk to us - Safaraz Ali for linkedin.pptx
Talk to us - Safaraz Ali for linkedin.pptx
 
Responsible Individual Training - F5 Foster Care.pptx
Responsible Individual Training -  F5 Foster Care.pptxResponsible Individual Training -  F5 Foster Care.pptx
Responsible Individual Training - F5 Foster Care.pptx
 
Responsible Individual Training fostercare- F5 Foster Care UK
Responsible Individual Training  fostercare-  F5 Foster Care UKResponsible Individual Training  fostercare-  F5 Foster Care UK
Responsible Individual Training fostercare- F5 Foster Care UK
 
Pathway Group 2024 by Safaraz Ali.pdf
Pathway Group 2024 by Safaraz Ali.pdfPathway Group 2024 by Safaraz Ali.pdf
Pathway Group 2024 by Safaraz Ali.pdf
 
1973 Toyota Production System Handbook
1973 Toyota Production System Handbook1973 Toyota Production System Handbook
1973 Toyota Production System Handbook
 
Multicultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdf
Multicultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdfMulticultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdf
Multicultural-Apprenticeship-Awards-2023-Compressed-Brochure.pdf
 
Empowering The Nation - White Paper .pdf
Empowering The Nation - White Paper .pdfEmpowering The Nation - White Paper .pdf
Empowering The Nation - White Paper .pdf
 
Peer Meetup by Safaraz Ali 13.Oct.2023.pdf
Peer Meetup by Safaraz Ali 13.Oct.2023.pdfPeer Meetup by Safaraz Ali 13.Oct.2023.pdf
Peer Meetup by Safaraz Ali 13.Oct.2023.pdf
 
Peer Meetup by Safaraz Ali 13.Oct.2023.ppt
Peer Meetup by Safaraz Ali 13.Oct.2023.pptPeer Meetup by Safaraz Ali 13.Oct.2023.ppt
Peer Meetup by Safaraz Ali 13.Oct.2023.ppt
 
A Guide to Apprenticeships for the Higher Education Sector.pdf
A Guide to Apprenticeships for the Higher Education Sector.pdfA Guide to Apprenticeships for the Higher Education Sector.pdf
A Guide to Apprenticeships for the Higher Education Sector.pdf
 
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdf
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdfAll Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdf
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pdf
 
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.ppt
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.pptAll Matters Regulatory - Apprenticeship Training Material - Pathway Group.ppt
All Matters Regulatory - Apprenticeship Training Material - Pathway Group.ppt
 
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
 
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
End-Point Assessment Organisations EPAOs - Apprenticeship Training Material -...
 
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
 
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
How Apprenticeships Work & Why They Work - Apprenticeship Training Material -...
 
The World of Learning - Apprenticeship Training Material - Pathway Group.ppt
The World of Learning - Apprenticeship Training Material - Pathway Group.pptThe World of Learning - Apprenticeship Training Material - Pathway Group.ppt
The World of Learning - Apprenticeship Training Material - Pathway Group.ppt
 
The World of Learning - Apprenticeship Training Material - Pathway Group.pdf
The World of Learning - Apprenticeship Training Material - Pathway Group.pdfThe World of Learning - Apprenticeship Training Material - Pathway Group.pdf
The World of Learning - Apprenticeship Training Material - Pathway Group.pdf
 
How Independent Training Providers (ITPs) can survive and thrive in an inflat...
How Independent Training Providers (ITPs) can survive and thrive in an inflat...How Independent Training Providers (ITPs) can survive and thrive in an inflat...
How Independent Training Providers (ITPs) can survive and thrive in an inflat...
 
Birmingham Pakistani Report PDF June 2023.pdf
Birmingham Pakistani Report PDF June 2023.pdfBirmingham Pakistani Report PDF June 2023.pdf
Birmingham Pakistani Report PDF June 2023.pdf
 

Recently uploaded

Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
Ben Wann
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Avirahi City Dholera
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
Workforce Group
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
awaisafdar
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Navpack & Print
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
tanyjahb
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
seri bangash
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
Nicola Wreford-Howard
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
zechu97
 
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
taqyed
 
What is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdfWhat is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdf
seoforlegalpillers
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
fisherameliaisabella
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
ofm712785
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
anasabutalha2013
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
usawebmarket
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
agatadrynko
 

Recently uploaded (20)

Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
 
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
 
What is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdfWhat is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdf
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
 

An Overview of GDPR

  • 1. AN OVERVIEW OF GDPR MASOOD BUTT – COMMERCIAL & REGULATORY LAWYER AHSAN HUSAIN – HEAD OF MIS & IT AND [DATA COMPLIANCE]
  • 2. DISCLAIMER The information contained herein and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity. Although we endeavour to provide accurate and timely information and use sources we consider reliable, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act on such information without appropriate professional advice after a thorough examination of the particular situation.
  • 3. Some Research based FACTS 1. 98% of the UK private sector is not ready for the GDPR 2. 84% of the small and medium sized businesses and 43% of the large companies are unaware of the implications of the GDPR. 3. 75% of the data held by companies shall become unuseable or risky after GDPR. 4. 48% of the adults surveyed in the UK confirmed they shall exercise their rights to Data protection afforded under GDPR.
  • 4. Contents Data Protection Frame Work GDPR – Responsibilities GDPR – Changes GDPR - Exemptions GDPR – Rights Penalty TEN HIGH LEVEL STEPS
  • 5. Data Protection Framework 1. Data Protection Directive EU 95/46 2. Data Protection Act 1998. 3. Information Commissioner’s Office (ICO). 3. A 2008 Council Framework Decision applies to the cross- border processing of personal data in police and judicial cooperation in criminal matters. 4. Criminal Justice and Data Protection (Protocol No. 36) Regulations 2014.
  • 6. Data Protection framework 1. The EU’s Charter of Fundamental Rights and Freedoms. 2. In January 2012, a new EU legislative framework for data protection. In its now finalised form, this has two elements: • The General Data Protection Regulation (“GDPR”) EU 2016/679 • The Police and Criminal Justice Directive (the “Law Enforcement Directive” (LED), also known as the “PCJ Directive”) EU 2016/680
  • 7. The General Data Protection Regulation (GDPR) Passed on 24 May 2016 Coming into force on 25th May 2018 Duty Holders: Data controllers - the persons or bodies that determine the purposes and means of processing of personal data) and Data processors - those who process personal data on behalf of a controller. Right Holders: Data subjects - (the individuals whose personal data is being processed). Data – any information relating to an identifiable natural person –Art 4 (1) Personal Data Breach means breach of security accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data stored, processed or transmitted. (Art 4 (12)
  • 8. Changes made by GDPR •Territorial scope •Data protection by design and default •A European Data Protection Board •Increased penalties •Data protection officers •A “one-stop shop” principle • Enhanced transparency duties when communicating with data subjects
  • 9. Exemption - Art 9 Exempted for data subjects, where processing does not include data on; Racial; Ethnic; Political opinions; Religious or philosophical beliefs; Trade union membership; Genetic data; Biometric data; Health data; Sex life or sexual orientation data;
  • 10. Exemptions – Art 30(5) •Organisation employs less than 250 staff; • unless •Likely to result in a risk to the rights or freedoms; •Occasional processing; •Special categories as above; •Data relating to criminal conviction and offences.
  • 11. Data subject rights Lawful processing – express and specific consent - Art 6 Right to withdraw consent at any time - Art 7 Right of access - Art 15 Right to rectification - Art 16 Right to erasure (forgotten) - Art 17 Right to restriction - Art 18 Right to be notified Art - 19 Right to data portability - Art 20 Right to object - Art 21 Right for not to be profiled automatically - Art 22 Right to lodge a complaint to supervisory authority - Art 77 Right to an effective judicial remedy against controller or processor - Art 79 Right to compensation for damages - Art 82
  • 12. The General Data Protection Regulation (GDPR) Strengthened consent is one of the major changes that the GDPR will make for data subjects. Article 4 (11) defines consent as follows: ‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. The definition’s references to “unambiguous” and “clear affirmative action” are new. A data controller must be able to demonstrate that a data subject has consented to the processing of their personal data. It must be possible to withdraw consent at any time. Article 7 (conditions for consent) states: 1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
  • 13. PENALTY Non compliance with an Order of supervisory body be subject to 20,000 000 EUR or 4% global annual turn over - Art 83
  • 14. Further costs • In addition to the sanctions, fines and reputational damage. • Problems which are only identified after the project has launched are more likely to require expensive fixes. • The use of biometric information or potentially intrusive tracking technologies may cause increased concern and cause people to avoid engaging with the organisation. • Information which is collected and stored unnecessarily, or is not properly managed so that duplicate records are created, is less useful to the business. • Public distrust about how information is used can damage an organisation’s reputation and lead to loss of business. • Data losses which damage individuals could lead to claims for compensation.
  • 15. Ten HIGH LEVEL STEPS Here are ten high-level steps to help you prepare. 1 be aware and be accountable; 2 Create/Renew Data Policy; 3 Classify Risk & Retention; 4 Evaluate and actively manage existing contracts with third party service providers; 5 Establish, embed and test a procedure to handle personal data incidents • Increase internal privacy-awareness;
  • 16. Ten HIGH LEVEL STEPS –cont. 6 Ensure how to recognise and respond appropriately to requests from data subjects; 7 Determine and document Privacy Impact Assessment and appointment of Data Protection Officer; 8 Review and amend and document privacy policy and statements and notices to meet the enhanced transparency requirements; 9 Document and identify the main causes of any potential data breach; 10. Would you be able to notify the regulator of any data breach within 72 hours?
  • 17. AN OVERVIEW OF GDPR MASOOD BUTT – COMMERCIAL & REGULATORY LAWYER AHSAN HUSAIN – HEAD OF MIS & IT AND [DATA COMPLIANCE]