SlideShare a Scribd company logo
New EU data protection law
How to avoid disaster
Stephen Groom
1
osborneclarke.com
Osborne Clarke
• An international law firm
• 600 lawyers
• 8 countries
• 18 offices
• 6 key sectors including digital business
• Leaders in marketing and privacy law
• Marketinglaw.co.uk
2
Current data protection obligations in a nutshell
Restrictions
on transfers
outside the
EEA Keep data
accurate &
up-to-date
Retain data
for an
appropriate
period
Respond to
data
subject
requests
Annual
notification
obligation
Get opt in /
out consent
for email /
SMS
marketing
Screen
against
TPS/FPS
"do not call"
lists
Get opt-in
consent to
use cookies
Data must
be relevant
and not
excessive
Notify ICO of
security
breaches
(not yet
compulsory for
all)
Knowledge/
Consent
Data
protection
obligations
New data protection obligations from February 2017?
Restrictions
on transfers
outside the
EEA Keep data
accurate &
up-to-date
Retain data
for an
appropriate
period
Respond to
data
subject
requests
Annual
notification
obligation
Get opt in /
out consent
for email /
SMS
marketing
Screen
against
TPS/FPS
"do not call"
lists
Get opt-in
consent to
use cookies
Data must
be relevant
and not
excessive
Notify ICO of
security
breaches
(not yet
compulsory for
all)
Knowledge/
Consent
Data
protection
obligations DPO requirement
Enhanced data
subject rights:
- right to be forgotten
- data portability
24 / 72 hours to
notify data / cyber
breaches
Fines to increase (<2% world-
wide turnover or €1m)
Expanded
definition of
personal data
Data
processor
responsibility
Higher level of
consent
required
Increased use of
Privacy Impact
Assessments (PIAs)
and emphasis on
accountability
Processor BCRS
Profiling only with
explicit prior
consent
osborneclarke.com
5
Non-compliance – the penalties
Key regulator weapons and other impacts
1. Fines – Are on the increase:
• UK (ICO has had power to fine up to £500k from April 2010)
2. Weapons used by National Regulatory Authorities:
• Good Practice Assessments
• Enforcement Notices/Undertakings
3. It's not just about fines
• Negative impact on share value
• Customer and staff perception and trust
• Brand damage
• Diversion of time and resources
osborneclarke.com
Increase in Enforcement
2013/4 marketing law milestones
• June 2013: ICO fines Save Britain Money £225,000 for nuisance calls
• December 2013: ICO fines payday lender First Financial UK Ltd
£175,000 fine for spam texts
• January 2014: Spain – jewellery companies first in Europe to be
fined for non compliance with cookie laws
• January 2014: UK High Court Vidal-Hall vs Google – behavioural
targeting (ongoing)
• February 2014: Trading standards criminal prosecution against cold
callers Apple Group Holdings £36,000
• March 2014: "serious breach" £500K hurdle may be lowered to
"serious nuisance and annoyance"
6
osborneclarke.com
£0.00
£20,000.00
£40,000.00
£60,000.00
£80,000.00
£100,000.00
£120,000.00
£140,000.00
£160,000.00
£180,000.00
£200,000.00
2010 2011 2012 2013 2014
Averagemonetarypenalty
* Statistics for 2010 only include November and December Based on data from http://ico.org.uk/enforcement/trends
Average Monetary Penalty Notice amount per year*
7
osborneclarke.com
Data privacy and marketing
The bottom line
• So with stricter data protection laws round
the corner..
• enforcers taking more action under the
existing law and..
• the threshold for six figure fines likely to be
reduced…
• doing nothing until new data protection laws
arrive …
• is not an option.
8
osborneclarke.com
9
Technology and business trends
What makes our phone ring?
• Cloud computing
• BYOD
• Location marketing
• Tracking / Cookies
• Social media
• Digital sales
• Near field communications/payments
• Outsourcing / offshoring
• Telematics/vehicle tracking
• Smart meters, grid, devices, home…..
• Global HR systems
osborneclarke.com
(1) Assign responsibility
Bite the bullet and appoint a DPO
1. Assign ownership (and budget)
 Time to appoint a DPO (law may oblige you to soon)
2. Who should it be: IT, Legal, Compliance, HR?
 Benefits of legal privilege
3. Visible reporting lines
 To existing risk committees
 And to board
4. Risk registers
 Failure to address known issues increases penalties
 Whether your issues or a 3rd party's
10
osborneclarke.com
(2) Get serious about training
ICO's #1 pet hate
1. 72% of ICO enforcement action last year cited lack of suitable
training as a reason action taken
2. So who to train?
− Start with DPO and leaders of teams who process your most
sensitive data
− Viral training – train the trainer
3. Desk top or in person?
4. The message can be spread in other ways too
− Videos, notices, pop up reminders, pay slip inserts…..
5. Ensure it's not a 1 off event
11
osborneclarke.com
12
(3) Time to review your policies
Are your current policies fit for purpose?
1. Technology/business developments have rendered many policies
out of date
− Privacy
− Cookies
− Social media
− BYOD
− Security
− Data retention
3. Beware need for Works Council approval if changing policies in EU
osborneclarke.com
(4) Review your approach to hiring marketing service
suppliers
What have you agreed, what will you agree?
Key DPA principles:
"Appropriate technical and organisational measures must be taken
against unauthorised or unlawful processing of personal data and
against accidental loss, destruction or damage"
– Written contracts required with suppliers
– Staff reliability measures
– Supplier selection linked to security guarantees
– Steps to ensure ongoing supplier compliance
Data only kept as long as it is needed
• Check which suppliers process valuable data
• Check existing contracts, precedents and RFP language
13
osborneclarke.com
(5) Registrations
In place and up to date?
1. Classic error is to be under-registered
2. N.B. each group company must notify – as must company pension
trusts
3. Separate registrations required in each EU country for each Data
Controller
4. In the UK 2 tier fees – payable annually:
• £35; or
• £500 if > £25.9M turnover and > 249 staff
14
osborneclarke.com
(6) Intra-group data transfers
Assess your compliance with the fiddliest aspect of DP laws
1. Even if you don't have global operations your
suppliers may do
2. Europe's law makers and regulators are fixated by
data transfer issues
• Check your data transfer solutions – model
contracts, safe harbor, BCRs
• Beware model contract registration
requirement in many EU countries
3. Remember that
• viewing personal data on a UK server from a
terminal in the US= a data transfer
• EU data laws apply to personal data of all living
individuals, not just EU citizens
15
osborneclarke.com
16
(7) Security breach notification
Plan your approach to reacting to cyber attack or data loss
1. Design your team – Legal, IT, PR, HR?
2. Pre-plan for the issues which it will need to consider:
i. Location – breach, affected individuals
ii. Seriousness of breach (timing, potential for harm, numbers affected,
Sensitivity of data involved)
iii. Measures taken to limit harm
iv. Evidence preservation
v. Legal privilege
vi. Who will need to be notified?
vii. Insurance position
osborneclarke.com
(8) Marketing compliance
Do your sales and marketing teams know their responsibilities?
1. Ensure that relevant teams understand opt in / out
2. Consider partners
• Do you have control of all notices
3. Review approach to marketing list purchase
• The DMA's list purchase warranties
4. Time for a marketing audit?
17
osborneclarke.com
18
Useful Materials
General:
• ICO's introductory DP guide
– https://www.ico.gov.uk/Global/~/media/documents/library/Data_Protection/Practical_
application/THE_GUIDE_TO_DATA_PROTECTION.ashx
• ICO's direct marketing guidance
– http://ico.org.uk/enforcement/action/~/media/documents/library/Privacy_and_electro
nic/Practical_application/direct-marketing-guidance.pdf
• ICO's data breach guidance note
– http://www.ico.gov.uk/for_organisations/guidance_index/~/media/documents/library/
Data_Protection/Practical_application/breach_reporting.ashx
• EC's review of Data Protection laws and link to draft
regulation
– http://ec.europa.eu/justice/news/consulting_public/0006/com_2010_609_en.pdf
Osborne Clarke:
• OC's White Paper - "Prepare now and avoid the risks"
– Contact us for a copy
• OC's Data report (The Data Gold Rush) and DP blog:
– http://www.osborneclarke.com/connected-insights/campaigns/data-gold-rush/
osborneclarke.com
19
Any questions?
Stephen Groom
Co-chair-Advertising & Marketing Law Group
Deputy Chair-Privacy and Data Law Group
T +44 (0) 207 105 7078
M +44 (0) 7788 584 295
stephen.groom@osborneclarke.com
www.marketinglaw.co.uk
[insert photo here]
Height = 5.39cm
Width = 5.81cm

More Related Content

What's hot

What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...TrustArc
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-LatemAnn Van den Bunder
 
New rules of Digital Marketing 25 May2016
New rules of Digital Marketing 25 May2016New rules of Digital Marketing 25 May2016
New rules of Digital Marketing 25 May2016Andrew Sanderson
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...Feroot
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
Trade Secret Asset Management
Trade Secret Asset ManagementTrade Secret Asset Management
Trade Secret Asset ManagementDonal O'Connell
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Agustin Argelich Casals
 
Lexing Barcelona Conference
Lexing Barcelona ConferenceLexing Barcelona Conference
Lexing Barcelona ConferenceMarc Gallardo
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
Martha Buyer V SCTC day conference 24 feb16
Martha Buyer V SCTC day conference 24 feb16Martha Buyer V SCTC day conference 24 feb16
Martha Buyer V SCTC day conference 24 feb16Agustin Argelich Casals
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014Rachel Aldighieri
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataMark Aldrich
 

What's hot (20)

What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
 
EU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection ChangesEU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection Changes
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
 
New rules of Digital Marketing 25 May2016
New rules of Digital Marketing 25 May2016New rules of Digital Marketing 25 May2016
New rules of Digital Marketing 25 May2016
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Trade Secret Asset Management
Trade Secret Asset ManagementTrade Secret Asset Management
Trade Secret Asset Management
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16
 
Lexing Barcelona Conference
Lexing Barcelona ConferenceLexing Barcelona Conference
Lexing Barcelona Conference
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
EU Border Measure Regulation
EU Border Measure RegulationEU Border Measure Regulation
EU Border Measure Regulation
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
Martha Buyer V SCTC day conference 24 feb16
Martha Buyer V SCTC day conference 24 feb16Martha Buyer V SCTC day conference 24 feb16
Martha Buyer V SCTC day conference 24 feb16
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border Data
 

Viewers also liked

Jas Purewal, Osborne Clarke
Jas Purewal, Osborne ClarkeJas Purewal, Osborne Clarke
Jas Purewal, Osborne ClarkeUKIE_Slide
 
Ecovis German Tax for founders 101
Ecovis German Tax for founders 101Ecovis German Tax for founders 101
Ecovis German Tax for founders 101BerlinStartupAcademy
 
BSA Public Sessions | Public Subsidies with CP Wackernagel
BSA Public Sessions | Public Subsidies with CP WackernagelBSA Public Sessions | Public Subsidies with CP Wackernagel
BSA Public Sessions | Public Subsidies with CP WackernagelBerlinStartupAcademy
 
Präsentation_Ecovis_BerlinStartupAcademy
Präsentation_Ecovis_BerlinStartupAcademyPräsentation_Ecovis_BerlinStartupAcademy
Präsentation_Ecovis_BerlinStartupAcademyBerlinStartupAcademy
 
OsbornrClarke German Law for founders 101
OsbornrClarke German Law for founders 101OsbornrClarke German Law for founders 101
OsbornrClarke German Law for founders 101BerlinStartupAcademy
 

Viewers also liked (8)

Jas Purewal, Osborne Clarke
Jas Purewal, Osborne ClarkeJas Purewal, Osborne Clarke
Jas Purewal, Osborne Clarke
 
Ecovis German Tax for founders 101
Ecovis German Tax for founders 101Ecovis German Tax for founders 101
Ecovis German Tax for founders 101
 
BSA Public Sessions | Public Subsidies with CP Wackernagel
BSA Public Sessions | Public Subsidies with CP WackernagelBSA Public Sessions | Public Subsidies with CP Wackernagel
BSA Public Sessions | Public Subsidies with CP Wackernagel
 
Präsentation_Ecovis_BerlinStartupAcademy
Präsentation_Ecovis_BerlinStartupAcademyPräsentation_Ecovis_BerlinStartupAcademy
Präsentation_Ecovis_BerlinStartupAcademy
 
OsbornrClarke German Law for founders 101
OsbornrClarke German Law for founders 101OsbornrClarke German Law for founders 101
OsbornrClarke German Law for founders 101
 
German VAT regulations
German VAT regulations German VAT regulations
German VAT regulations
 
Leitfaden ecovis bsa quiznight
Leitfaden ecovis bsa quiznightLeitfaden ecovis bsa quiznight
Leitfaden ecovis bsa quiznight
 
Succession “Losers”: What Happens to Executives Passed Over for the CEO Job?
Succession “Losers”: What Happens to Executives Passed Over for the CEO Job? Succession “Losers”: What Happens to Executives Passed Over for the CEO Job?
Succession “Losers”: What Happens to Executives Passed Over for the CEO Job?
 

Similar to CASE STUDY: New EU legislation: how to avoid data disaster

GDPR training
GDPR training GDPR training
GDPR training ASL
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownAgile PR
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing associationiof_events
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementGACC_Midwest
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protectionMRS
 
Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Antoine Gay
 
Challenges and opportunities in the paperless NHS & beyond - A data protectio...
Challenges and opportunities in the paperless NHS & beyond - A data protectio...Challenges and opportunities in the paperless NHS & beyond - A data protectio...
Challenges and opportunities in the paperless NHS & beyond - A data protectio...Osborne Clarke
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesRob Blamires
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesRob Blamires
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberRachel Aldighieri
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPiwik PRO
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Emily Jones
 
Data Protection and Comnpliance with the GDPR Event 22 september 2016
Data Protection and Comnpliance with the GDPR Event 22 september 2016 Data Protection and Comnpliance with the GDPR Event 22 september 2016
Data Protection and Comnpliance with the GDPR Event 22 september 2016 Dr. Donald Macfarlane
 
Data protection For CYP Organisations
Data protection For CYP OrganisationsData protection For CYP Organisations
Data protection For CYP OrganisationsCliff Ashcroft
 

Similar to CASE STUDY: New EU legislation: how to avoid data disaster (20)

GDPR training
GDPR training GDPR training
GDPR training
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011
 
Challenges and opportunities in the paperless NHS & beyond - A data protectio...
Challenges and opportunities in the paperless NHS & beyond - A data protectio...Challenges and opportunities in the paperless NHS & beyond - A data protectio...
Challenges and opportunities in the paperless NHS & beyond - A data protectio...
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square Ventures
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square Ventures
 
Legal update
Legal updateLegal update
Legal update
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
 
Data Protection and Comnpliance with the GDPR Event 22 september 2016
Data Protection and Comnpliance with the GDPR Event 22 september 2016 Data Protection and Comnpliance with the GDPR Event 22 september 2016
Data Protection and Comnpliance with the GDPR Event 22 september 2016
 
Data protection For CYP Organisations
Data protection For CYP OrganisationsData protection For CYP Organisations
Data protection For CYP Organisations
 

More from B2B Marketing

8 steps for excellent B2B CX (customer experience)
8 steps for excellent B2B CX (customer experience)8 steps for excellent B2B CX (customer experience)
8 steps for excellent B2B CX (customer experience)B2B Marketing
 
B2B Summit 2016 - Technology industry
B2B Summit 2016 - Technology industry B2B Summit 2016 - Technology industry
B2B Summit 2016 - Technology industry B2B Marketing
 
B2B Summit 2016 - Manufacturing industry
B2B Summit 2016 - Manufacturing industry B2B Summit 2016 - Manufacturing industry
B2B Summit 2016 - Manufacturing industry B2B Marketing
 
B2B Summit 2016 - Finance industry
B2B Summit 2016 - Finance industry B2B Summit 2016 - Finance industry
B2B Summit 2016 - Finance industry B2B Marketing
 
Andrew Rogerson, Managing director, Grist and Nathan Hambrook-Skinner, direc...
Andrew Rogerson, Managing director, Grist  and Nathan Hambrook-Skinner, direc...Andrew Rogerson, Managing director, Grist  and Nathan Hambrook-Skinner, direc...
Andrew Rogerson, Managing director, Grist and Nathan Hambrook-Skinner, direc...B2B Marketing
 
1130 Heidi Taylor Heidimarketing
1130 Heidi Taylor Heidimarketing1130 Heidi Taylor Heidimarketing
1130 Heidi Taylor HeidimarketingB2B Marketing
 
1425 1455 Peter Isaacson Demandbase
1425 1455 Peter Isaacson Demandbase1425 1455 Peter Isaacson Demandbase
1425 1455 Peter Isaacson DemandbaseB2B Marketing
 
1500 1530 Alana Griffths and Alex Gill Harte Hanks
1500 1530 Alana Griffths and Alex Gill Harte Hanks1500 1530 Alana Griffths and Alex Gill Harte Hanks
1500 1530 Alana Griffths and Alex Gill Harte HanksB2B Marketing
 
James foulkes, director and co founder, kingpin
James foulkes, director and co founder, kingpinJames foulkes, director and co founder, kingpin
James foulkes, director and co founder, kingpinB2B Marketing
 
John Webb, marketing director (EMEA), Spiceworks
John Webb, marketing director (EMEA), SpiceworksJohn Webb, marketing director (EMEA), Spiceworks
John Webb, marketing director (EMEA), SpiceworksB2B Marketing
 
1500 1530 Simon Morris, Adobe
1500 1530 Simon Morris, Adobe1500 1530 Simon Morris, Adobe
1500 1530 Simon Morris, AdobeB2B Marketing
 
1500 1530 Fiona Shepherd and Sinead Woodley, April Six
1500 1530 Fiona Shepherd and Sinead Woodley, April Six1500 1530 Fiona Shepherd and Sinead Woodley, April Six
1500 1530 Fiona Shepherd and Sinead Woodley, April SixB2B Marketing
 
1130 1210 Tim Hughes, oracle
1130 1210 Tim Hughes, oracle1130 1210 Tim Hughes, oracle
1130 1210 Tim Hughes, oracleB2B Marketing
 
0940 Jeremy Bevan, Cisco
0940 Jeremy Bevan, Cisco0940 Jeremy Bevan, Cisco
0940 Jeremy Bevan, CiscoB2B Marketing
 
0940 Peter thomas accenture
0940 Peter thomas accenture0940 Peter thomas accenture
0940 Peter thomas accentureB2B Marketing
 
BEST PRACTICE: Just for you - How to drive better engagement with localisatio...
BEST PRACTICE: Just for you - How to drive better engagement with localisatio...BEST PRACTICE: Just for you - How to drive better engagement with localisatio...
BEST PRACTICE: Just for you - How to drive better engagement with localisatio...B2B Marketing
 
CASE STUDY: How insights on your customer’s end consumers can help your B2B s...
CASE STUDY: How insights on your customer’s end consumers can help your B2B s...CASE STUDY: How insights on your customer’s end consumers can help your B2B s...
CASE STUDY: How insights on your customer’s end consumers can help your B2B s...B2B Marketing
 
BEST PRACTICE: Building long-term relationships with data & customer insights
BEST PRACTICE: Building long-term relationships with data & customer insightsBEST PRACTICE: Building long-term relationships with data & customer insights
BEST PRACTICE: Building long-term relationships with data & customer insightsB2B Marketing
 
BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...
BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...
BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...B2B Marketing
 

More from B2B Marketing (20)

8 steps for excellent B2B CX (customer experience)
8 steps for excellent B2B CX (customer experience)8 steps for excellent B2B CX (customer experience)
8 steps for excellent B2B CX (customer experience)
 
B2B Summit 2016 - Technology industry
B2B Summit 2016 - Technology industry B2B Summit 2016 - Technology industry
B2B Summit 2016 - Technology industry
 
B2B Summit 2016 - Manufacturing industry
B2B Summit 2016 - Manufacturing industry B2B Summit 2016 - Manufacturing industry
B2B Summit 2016 - Manufacturing industry
 
B2B Summit 2016 - Finance industry
B2B Summit 2016 - Finance industry B2B Summit 2016 - Finance industry
B2B Summit 2016 - Finance industry
 
Andrew Rogerson, Managing director, Grist and Nathan Hambrook-Skinner, direc...
Andrew Rogerson, Managing director, Grist  and Nathan Hambrook-Skinner, direc...Andrew Rogerson, Managing director, Grist  and Nathan Hambrook-Skinner, direc...
Andrew Rogerson, Managing director, Grist and Nathan Hambrook-Skinner, direc...
 
1130 Heidi Taylor Heidimarketing
1130 Heidi Taylor Heidimarketing1130 Heidi Taylor Heidimarketing
1130 Heidi Taylor Heidimarketing
 
1425 1455 Peter Isaacson Demandbase
1425 1455 Peter Isaacson Demandbase1425 1455 Peter Isaacson Demandbase
1425 1455 Peter Isaacson Demandbase
 
1500 1530 Alana Griffths and Alex Gill Harte Hanks
1500 1530 Alana Griffths and Alex Gill Harte Hanks1500 1530 Alana Griffths and Alex Gill Harte Hanks
1500 1530 Alana Griffths and Alex Gill Harte Hanks
 
James foulkes, director and co founder, kingpin
James foulkes, director and co founder, kingpinJames foulkes, director and co founder, kingpin
James foulkes, director and co founder, kingpin
 
John Webb, marketing director (EMEA), Spiceworks
John Webb, marketing director (EMEA), SpiceworksJohn Webb, marketing director (EMEA), Spiceworks
John Webb, marketing director (EMEA), Spiceworks
 
1500 1530 Simon Morris, Adobe
1500 1530 Simon Morris, Adobe1500 1530 Simon Morris, Adobe
1500 1530 Simon Morris, Adobe
 
1500 1530 Fiona Shepherd and Sinead Woodley, April Six
1500 1530 Fiona Shepherd and Sinead Woodley, April Six1500 1530 Fiona Shepherd and Sinead Woodley, April Six
1500 1530 Fiona Shepherd and Sinead Woodley, April Six
 
Jon moger, Aruba
Jon moger, ArubaJon moger, Aruba
Jon moger, Aruba
 
1130 1210 Tim Hughes, oracle
1130 1210 Tim Hughes, oracle1130 1210 Tim Hughes, oracle
1130 1210 Tim Hughes, oracle
 
0940 Jeremy Bevan, Cisco
0940 Jeremy Bevan, Cisco0940 Jeremy Bevan, Cisco
0940 Jeremy Bevan, Cisco
 
0940 Peter thomas accenture
0940 Peter thomas accenture0940 Peter thomas accenture
0940 Peter thomas accenture
 
BEST PRACTICE: Just for you - How to drive better engagement with localisatio...
BEST PRACTICE: Just for you - How to drive better engagement with localisatio...BEST PRACTICE: Just for you - How to drive better engagement with localisatio...
BEST PRACTICE: Just for you - How to drive better engagement with localisatio...
 
CASE STUDY: How insights on your customer’s end consumers can help your B2B s...
CASE STUDY: How insights on your customer’s end consumers can help your B2B s...CASE STUDY: How insights on your customer’s end consumers can help your B2B s...
CASE STUDY: How insights on your customer’s end consumers can help your B2B s...
 
BEST PRACTICE: Building long-term relationships with data & customer insights
BEST PRACTICE: Building long-term relationships with data & customer insightsBEST PRACTICE: Building long-term relationships with data & customer insights
BEST PRACTICE: Building long-term relationships with data & customer insights
 
BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...
BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...
BEST PRACTICE: How to be insightful: a storyteller’s guide to developing the ...
 

Recently uploaded

Taking The Guesswork Out of Your Lead Generation Campaign
Taking The Guesswork Out of Your Lead Generation CampaignTaking The Guesswork Out of Your Lead Generation Campaign
Taking The Guesswork Out of Your Lead Generation CampaignMartal Group
 
Mastering Multi-Touchpoint Content Strategy: Navigate Fragmented User Journeys
Mastering Multi-Touchpoint Content Strategy: Navigate Fragmented User JourneysMastering Multi-Touchpoint Content Strategy: Navigate Fragmented User Journeys
Mastering Multi-Touchpoint Content Strategy: Navigate Fragmented User JourneysSearch Engine Journal
 
Liquid Staking: An Overview for Beginners in 2024
Liquid Staking: An Overview for Beginners in 2024Liquid Staking: An Overview for Beginners in 2024
Liquid Staking: An Overview for Beginners in 2024nehapardhi711
 
Unlocking Success: The Leading SEO Reseller Services in India
Unlocking Success: The Leading SEO Reseller Services in IndiaUnlocking Success: The Leading SEO Reseller Services in India
Unlocking Success: The Leading SEO Reseller Services in IndiaPitchPineMedia1
 
A Guide to UK Top Search Engine Optimization
A Guide to UK Top Search Engine OptimizationA Guide to UK Top Search Engine Optimization
A Guide to UK Top Search Engine OptimizationBrand Highlighters
 
20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf
20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf
20221005110010_633d63baa84f6_learn___week_3_ch._5.pdflevuag
 
A chronological journey of jobs and responsibilities.
A chronological journey of jobs and responsibilities.A chronological journey of jobs and responsibilities.
A chronological journey of jobs and responsibilities.Stacey Cost
 
Metropolis of Dreams metaverse virtual city
Metropolis of Dreams metaverse virtual cityMetropolis of Dreams metaverse virtual city
Metropolis of Dreams metaverse virtual cityDonna Lenk
 
Search Engine Marketing - Competitor and Keyword research
Search Engine Marketing  - Competitor and Keyword researchSearch Engine Marketing  - Competitor and Keyword research
Search Engine Marketing - Competitor and Keyword researchETMARK ACADEMY
 
TikTok: The Cultural Revolution in 10 minutes!
TikTok: The Cultural Revolution in 10 minutes! TikTok: The Cultural Revolution in 10 minutes!
TikTok: The Cultural Revolution in 10 minutes! Tasos Veliadis
 
How to Run Landing Page Tests On and Off Paid Social Platforms
How to Run Landing Page Tests On and Off Paid Social PlatformsHow to Run Landing Page Tests On and Off Paid Social Platforms
How to Run Landing Page Tests On and Off Paid Social PlatformsVWO
 
Digital Money Maker Club – von Gunnar Kessler digital.
Digital Money Maker Club – von Gunnar Kessler digital.Digital Money Maker Club – von Gunnar Kessler digital.
Digital Money Maker Club – von Gunnar Kessler digital.focsh890
 
Core Web Vitals SEO Workshop - improve your performance [pdf]
Core Web Vitals SEO Workshop - improve your performance [pdf]Core Web Vitals SEO Workshop - improve your performance [pdf]
Core Web Vitals SEO Workshop - improve your performance [pdf]Peter Mead
 
The Impact of Technological Advancements on Elastic Webbing Production in Chi...
The Impact of Technological Advancements on Elastic Webbing Production in Chi...The Impact of Technological Advancements on Elastic Webbing Production in Chi...
The Impact of Technological Advancements on Elastic Webbing Production in Chi...Stk-Interlining
 
Blue and Yellow Illustrative Digital Education Presentation (1).pptx
Blue and Yellow Illustrative Digital Education Presentation (1).pptxBlue and Yellow Illustrative Digital Education Presentation (1).pptx
Blue and Yellow Illustrative Digital Education Presentation (1).pptxayush20231
 
Ash By Ash Benson Rebrand Creative Direction
Ash By Ash Benson Rebrand Creative DirectionAsh By Ash Benson Rebrand Creative Direction
Ash By Ash Benson Rebrand Creative DirectionMark Milutin
 
AI-Powered Personalization: Principles, Use Cases, and Its Impact on CRO
AI-Powered Personalization: Principles, Use Cases, and Its Impact on CROAI-Powered Personalization: Principles, Use Cases, and Its Impact on CRO
AI-Powered Personalization: Principles, Use Cases, and Its Impact on CROVWO
 
SMM Cheap - No. 1 SMM panel in the world
SMM Cheap - No. 1 SMM panel in the worldSMM Cheap - No. 1 SMM panel in the world
SMM Cheap - No. 1 SMM panel in the worldsmmpanel567
 
Digital Marketing Training In Bangalore
Digital Marketing Training In BangaloreDigital Marketing Training In Bangalore
Digital Marketing Training In Bangaloresyedasifsyed46
 

Recently uploaded (20)

Taking The Guesswork Out of Your Lead Generation Campaign
Taking The Guesswork Out of Your Lead Generation CampaignTaking The Guesswork Out of Your Lead Generation Campaign
Taking The Guesswork Out of Your Lead Generation Campaign
 
Mastering Multi-Touchpoint Content Strategy: Navigate Fragmented User Journeys
Mastering Multi-Touchpoint Content Strategy: Navigate Fragmented User JourneysMastering Multi-Touchpoint Content Strategy: Navigate Fragmented User Journeys
Mastering Multi-Touchpoint Content Strategy: Navigate Fragmented User Journeys
 
Liquid Staking: An Overview for Beginners in 2024
Liquid Staking: An Overview for Beginners in 2024Liquid Staking: An Overview for Beginners in 2024
Liquid Staking: An Overview for Beginners in 2024
 
Unlocking Success: The Leading SEO Reseller Services in India
Unlocking Success: The Leading SEO Reseller Services in IndiaUnlocking Success: The Leading SEO Reseller Services in India
Unlocking Success: The Leading SEO Reseller Services in India
 
A Guide to UK Top Search Engine Optimization
A Guide to UK Top Search Engine OptimizationA Guide to UK Top Search Engine Optimization
A Guide to UK Top Search Engine Optimization
 
20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf
20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf
20221005110010_633d63baa84f6_learn___week_3_ch._5.pdf
 
A chronological journey of jobs and responsibilities.
A chronological journey of jobs and responsibilities.A chronological journey of jobs and responsibilities.
A chronological journey of jobs and responsibilities.
 
Metropolis of Dreams metaverse virtual city
Metropolis of Dreams metaverse virtual cityMetropolis of Dreams metaverse virtual city
Metropolis of Dreams metaverse virtual city
 
Media Wall Street | Best Branding And Marketing Agency In Chandigarh
Media Wall Street | Best Branding And Marketing Agency In ChandigarhMedia Wall Street | Best Branding And Marketing Agency In Chandigarh
Media Wall Street | Best Branding And Marketing Agency In Chandigarh
 
Search Engine Marketing - Competitor and Keyword research
Search Engine Marketing  - Competitor and Keyword researchSearch Engine Marketing  - Competitor and Keyword research
Search Engine Marketing - Competitor and Keyword research
 
TikTok: The Cultural Revolution in 10 minutes!
TikTok: The Cultural Revolution in 10 minutes! TikTok: The Cultural Revolution in 10 minutes!
TikTok: The Cultural Revolution in 10 minutes!
 
How to Run Landing Page Tests On and Off Paid Social Platforms
How to Run Landing Page Tests On and Off Paid Social PlatformsHow to Run Landing Page Tests On and Off Paid Social Platforms
How to Run Landing Page Tests On and Off Paid Social Platforms
 
Digital Money Maker Club – von Gunnar Kessler digital.
Digital Money Maker Club – von Gunnar Kessler digital.Digital Money Maker Club – von Gunnar Kessler digital.
Digital Money Maker Club – von Gunnar Kessler digital.
 
Core Web Vitals SEO Workshop - improve your performance [pdf]
Core Web Vitals SEO Workshop - improve your performance [pdf]Core Web Vitals SEO Workshop - improve your performance [pdf]
Core Web Vitals SEO Workshop - improve your performance [pdf]
 
The Impact of Technological Advancements on Elastic Webbing Production in Chi...
The Impact of Technological Advancements on Elastic Webbing Production in Chi...The Impact of Technological Advancements on Elastic Webbing Production in Chi...
The Impact of Technological Advancements on Elastic Webbing Production in Chi...
 
Blue and Yellow Illustrative Digital Education Presentation (1).pptx
Blue and Yellow Illustrative Digital Education Presentation (1).pptxBlue and Yellow Illustrative Digital Education Presentation (1).pptx
Blue and Yellow Illustrative Digital Education Presentation (1).pptx
 
Ash By Ash Benson Rebrand Creative Direction
Ash By Ash Benson Rebrand Creative DirectionAsh By Ash Benson Rebrand Creative Direction
Ash By Ash Benson Rebrand Creative Direction
 
AI-Powered Personalization: Principles, Use Cases, and Its Impact on CRO
AI-Powered Personalization: Principles, Use Cases, and Its Impact on CROAI-Powered Personalization: Principles, Use Cases, and Its Impact on CRO
AI-Powered Personalization: Principles, Use Cases, and Its Impact on CRO
 
SMM Cheap - No. 1 SMM panel in the world
SMM Cheap - No. 1 SMM panel in the worldSMM Cheap - No. 1 SMM panel in the world
SMM Cheap - No. 1 SMM panel in the world
 
Digital Marketing Training In Bangalore
Digital Marketing Training In BangaloreDigital Marketing Training In Bangalore
Digital Marketing Training In Bangalore
 

CASE STUDY: New EU legislation: how to avoid data disaster

  • 1. New EU data protection law How to avoid disaster Stephen Groom 1
  • 2. osborneclarke.com Osborne Clarke • An international law firm • 600 lawyers • 8 countries • 18 offices • 6 key sectors including digital business • Leaders in marketing and privacy law • Marketinglaw.co.uk 2
  • 3. Current data protection obligations in a nutshell Restrictions on transfers outside the EEA Keep data accurate & up-to-date Retain data for an appropriate period Respond to data subject requests Annual notification obligation Get opt in / out consent for email / SMS marketing Screen against TPS/FPS "do not call" lists Get opt-in consent to use cookies Data must be relevant and not excessive Notify ICO of security breaches (not yet compulsory for all) Knowledge/ Consent Data protection obligations
  • 4. New data protection obligations from February 2017? Restrictions on transfers outside the EEA Keep data accurate & up-to-date Retain data for an appropriate period Respond to data subject requests Annual notification obligation Get opt in / out consent for email / SMS marketing Screen against TPS/FPS "do not call" lists Get opt-in consent to use cookies Data must be relevant and not excessive Notify ICO of security breaches (not yet compulsory for all) Knowledge/ Consent Data protection obligations DPO requirement Enhanced data subject rights: - right to be forgotten - data portability 24 / 72 hours to notify data / cyber breaches Fines to increase (<2% world- wide turnover or €1m) Expanded definition of personal data Data processor responsibility Higher level of consent required Increased use of Privacy Impact Assessments (PIAs) and emphasis on accountability Processor BCRS Profiling only with explicit prior consent
  • 5. osborneclarke.com 5 Non-compliance – the penalties Key regulator weapons and other impacts 1. Fines – Are on the increase: • UK (ICO has had power to fine up to £500k from April 2010) 2. Weapons used by National Regulatory Authorities: • Good Practice Assessments • Enforcement Notices/Undertakings 3. It's not just about fines • Negative impact on share value • Customer and staff perception and trust • Brand damage • Diversion of time and resources
  • 6. osborneclarke.com Increase in Enforcement 2013/4 marketing law milestones • June 2013: ICO fines Save Britain Money £225,000 for nuisance calls • December 2013: ICO fines payday lender First Financial UK Ltd £175,000 fine for spam texts • January 2014: Spain – jewellery companies first in Europe to be fined for non compliance with cookie laws • January 2014: UK High Court Vidal-Hall vs Google – behavioural targeting (ongoing) • February 2014: Trading standards criminal prosecution against cold callers Apple Group Holdings £36,000 • March 2014: "serious breach" £500K hurdle may be lowered to "serious nuisance and annoyance" 6
  • 7. osborneclarke.com £0.00 £20,000.00 £40,000.00 £60,000.00 £80,000.00 £100,000.00 £120,000.00 £140,000.00 £160,000.00 £180,000.00 £200,000.00 2010 2011 2012 2013 2014 Averagemonetarypenalty * Statistics for 2010 only include November and December Based on data from http://ico.org.uk/enforcement/trends Average Monetary Penalty Notice amount per year* 7
  • 8. osborneclarke.com Data privacy and marketing The bottom line • So with stricter data protection laws round the corner.. • enforcers taking more action under the existing law and.. • the threshold for six figure fines likely to be reduced… • doing nothing until new data protection laws arrive … • is not an option. 8
  • 9. osborneclarke.com 9 Technology and business trends What makes our phone ring? • Cloud computing • BYOD • Location marketing • Tracking / Cookies • Social media • Digital sales • Near field communications/payments • Outsourcing / offshoring • Telematics/vehicle tracking • Smart meters, grid, devices, home….. • Global HR systems
  • 10. osborneclarke.com (1) Assign responsibility Bite the bullet and appoint a DPO 1. Assign ownership (and budget)  Time to appoint a DPO (law may oblige you to soon) 2. Who should it be: IT, Legal, Compliance, HR?  Benefits of legal privilege 3. Visible reporting lines  To existing risk committees  And to board 4. Risk registers  Failure to address known issues increases penalties  Whether your issues or a 3rd party's 10
  • 11. osborneclarke.com (2) Get serious about training ICO's #1 pet hate 1. 72% of ICO enforcement action last year cited lack of suitable training as a reason action taken 2. So who to train? − Start with DPO and leaders of teams who process your most sensitive data − Viral training – train the trainer 3. Desk top or in person? 4. The message can be spread in other ways too − Videos, notices, pop up reminders, pay slip inserts….. 5. Ensure it's not a 1 off event 11
  • 12. osborneclarke.com 12 (3) Time to review your policies Are your current policies fit for purpose? 1. Technology/business developments have rendered many policies out of date − Privacy − Cookies − Social media − BYOD − Security − Data retention 3. Beware need for Works Council approval if changing policies in EU
  • 13. osborneclarke.com (4) Review your approach to hiring marketing service suppliers What have you agreed, what will you agree? Key DPA principles: "Appropriate technical and organisational measures must be taken against unauthorised or unlawful processing of personal data and against accidental loss, destruction or damage" – Written contracts required with suppliers – Staff reliability measures – Supplier selection linked to security guarantees – Steps to ensure ongoing supplier compliance Data only kept as long as it is needed • Check which suppliers process valuable data • Check existing contracts, precedents and RFP language 13
  • 14. osborneclarke.com (5) Registrations In place and up to date? 1. Classic error is to be under-registered 2. N.B. each group company must notify – as must company pension trusts 3. Separate registrations required in each EU country for each Data Controller 4. In the UK 2 tier fees – payable annually: • £35; or • £500 if > £25.9M turnover and > 249 staff 14
  • 15. osborneclarke.com (6) Intra-group data transfers Assess your compliance with the fiddliest aspect of DP laws 1. Even if you don't have global operations your suppliers may do 2. Europe's law makers and regulators are fixated by data transfer issues • Check your data transfer solutions – model contracts, safe harbor, BCRs • Beware model contract registration requirement in many EU countries 3. Remember that • viewing personal data on a UK server from a terminal in the US= a data transfer • EU data laws apply to personal data of all living individuals, not just EU citizens 15
  • 16. osborneclarke.com 16 (7) Security breach notification Plan your approach to reacting to cyber attack or data loss 1. Design your team – Legal, IT, PR, HR? 2. Pre-plan for the issues which it will need to consider: i. Location – breach, affected individuals ii. Seriousness of breach (timing, potential for harm, numbers affected, Sensitivity of data involved) iii. Measures taken to limit harm iv. Evidence preservation v. Legal privilege vi. Who will need to be notified? vii. Insurance position
  • 17. osborneclarke.com (8) Marketing compliance Do your sales and marketing teams know their responsibilities? 1. Ensure that relevant teams understand opt in / out 2. Consider partners • Do you have control of all notices 3. Review approach to marketing list purchase • The DMA's list purchase warranties 4. Time for a marketing audit? 17
  • 18. osborneclarke.com 18 Useful Materials General: • ICO's introductory DP guide – https://www.ico.gov.uk/Global/~/media/documents/library/Data_Protection/Practical_ application/THE_GUIDE_TO_DATA_PROTECTION.ashx • ICO's direct marketing guidance – http://ico.org.uk/enforcement/action/~/media/documents/library/Privacy_and_electro nic/Practical_application/direct-marketing-guidance.pdf • ICO's data breach guidance note – http://www.ico.gov.uk/for_organisations/guidance_index/~/media/documents/library/ Data_Protection/Practical_application/breach_reporting.ashx • EC's review of Data Protection laws and link to draft regulation – http://ec.europa.eu/justice/news/consulting_public/0006/com_2010_609_en.pdf Osborne Clarke: • OC's White Paper - "Prepare now and avoid the risks" – Contact us for a copy • OC's Data report (The Data Gold Rush) and DP blog: – http://www.osborneclarke.com/connected-insights/campaigns/data-gold-rush/
  • 19. osborneclarke.com 19 Any questions? Stephen Groom Co-chair-Advertising & Marketing Law Group Deputy Chair-Privacy and Data Law Group T +44 (0) 207 105 7078 M +44 (0) 7788 584 295 stephen.groom@osborneclarke.com www.marketinglaw.co.uk [insert photo here] Height = 5.39cm Width = 5.81cm