SlideShare a Scribd company logo
Exove
Tietoturvaloukkaukset,
yksityisyydensuojan parantaminen ja
GDPR:n tuomat muutokset
henkilötietojen käsittelijöille
Tobias Bräutigam, Counsel
Agenda
1.  Rights for individuals
2.  Controller/Processor Role based examples
of obligations
3.  Data Breach
Page 2
Rights of individuals
New rights for individuals?
Page 4
Article What is it about New?
13/14 Transparency, right to be informed More details
15 Access to personal data Clarification, more detail
16 Rectification of inaccurate data Old
17 Right to be forgotten Not so new like you think
18 Right to restrict processing Clarification, more detail
20 Data portability New
21 Automated decision making More detail, larger scope
Page 5
Much ado about nothing?
1.  Fines from authorities for the violation of rights
•  4%, i.e. higher level
2.  Enforcement via private action, Article 79
•  Also "non-material" damage is covered, Article 82
3.  Can be delegated
•  Consumer organizations will take care of it
Summary
•  As such relatively small changes, modifications, clarifications
•  Enforcement: Huge change
What does the GDPR mean for processors?
Your
Company
General
obligations
(authorities)
As a processor
Towards data
subjects
As a
controller
Page 8
Processor's new obligations
Assisting controllers
●  Only act on the controller's documented instructions;
●  Assisting the Controller for responding to requests from data subjects for:
access, rectification, suppression, limitation, objection, portability of data
●  Return or delete personal data upon Controller's choice at the end of
services
●  Assisting the controller to notify security breaches, implement DPIAs,
provide information
●  Contribute to audits, including directly made by the Controller
●  Mandatory contract clauses
Own responsibility
●  List of technical and organizational measures
●  Processor's staff must be bound by confidentiality obligations
●  Compliance with international data transfers
Page 9
Key action items as a processor
Build your privacy program
●  Hire a privacy officer where needed
●  Define security measures, processes and
responsibilties
Indemnity and liability
●  Push back on indemnities (strict liability)
●  Push back on unlimited liability clauses, tie to
negligence
Define the lines of responsibilities
●  Only process based on instructions and GDPR
Data Breach Notification
Page 11
Article 33
In the case of a personal data breach,
the controller shall without undue delay
and, where feasible, not later than 72
hours after having become aware of it,
notify the personal data breach to the
supervisory authority […], unless the
personal data breach is unlikely to
result in a risk to the rights and
freedoms of natural persons.
What amounts to a ‘breach’ under the new
rules and to whom the regime applies?
Page 12
●  Relevant provisions in the GDPR can be found in:
•  Recitals: 73, 85-88
•  Articles: 4, 33, 34, 66 and 83
●  The regime applies to data controllers but indirectly also to
their processors
●  The GDPR refers to "a breach of security leading to the
accidental or unlawful destruction, loss, alteration,
unauthorised disclosure of, or access to, personal data
transmitted, stored or otherwise processed"
●  It’s important to note that the wilful destruction or alteration of
data is as much a breach as theft
Practical scenarios for your organisation to
consider
Page 13
Breach?
Four laptops containing 5,000 employee records are stolen from
the HR department…
A flash drive containing 5,000 customer records is forgotten in a
bus and never retrieved. There is no evidence that customer
records were compromised.
An employee has given to a third party the login and password
for an account with global access read only right to the client
database. Logs evidence use of the account by this third party.
A rogue employee supresses all contact details provided in the
consumer records of his organisation before resigning.
Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses.
Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number OC340318 and is authorised and regulated by the
Solicitors Regulation Authority. Its registered office and principal place of business is at 12 New Fetter Lane, London EC4A 1JP. A list of members of Bird & Bird
LLP and of any non-members who are designated as partners, and of their respective professional qualifications, is open to inspection at that address.
twobirds.com
Thank you
Page 15
Demonstrate compliance with the GDPR's principles
●  Implement appropriate security policies and measures
●  Privacy impact assessment and prior consultation (when applicable)
●  Adopt certain "data protection by design" measures
●  Record of all processing activities
●  Undertake audits
●  Adherence to approved codes of conduct and certifications
●  Implement Privacy Policies
●  Appropriate staffing (e.g. data protection officer)
●  Staff training programs
General obligations
Page 16
Work on your privacy program
●  Audit your privacy practices (use self-assessments
and interviews)
●  Start designing governance and risk management
elements first
●  Decide which IT-systems need to be improved to
close gaps (e.g. consumer dash-board)
●  Improve privacy processes like subcontractor
management, data subject access, partnering
Key action items for general compliance
Page 17
Transparency
●  General privacy policy must mention specific information, such as
legal basis, data retention, contact details of DP officer etc.
●  Specific notices where needed, e.g. information about the right to
withdraw consent
Legitimacy of processing
●  Most data processing is *not* based on consent!
●  Performance of a contract or legitimate interest (e.g. Marketing to
employees of corporate subscribers)
●  Where consent is the only option, systems must be ready for
withdrawal of consent
Honouring data subject rights
●  Access, rectification, limitation, objection, portability of data
●  If acting as a processor, Exove must assist the controller fulfilling
those rights
Obligations towards data subjects
(for example: corporate subscribers and consumers)
Page 18
Define reason for processing for each major process
●  Legitimate interest, consent or contract?
Review privacy notices
●  Follow list in Articles 13/14 GDPR
Design access and deletion process of data subjects
●  This includes appropriate IT systems and training of staff
●  Draft/update template responses
Key action items: compliance towards data
subjects
Page 19
Managing processors
●  Review and update all data processing agreements
●  Instruct processors and follow up (audit)
Accountability
●  Keep records of all processing activities
●  Appointment of DPO (if applicable)
●  Map data transfer and compliance
●  Staff training programs and collection of metrics
General obligations
●  Implement appropriate technical and organizational security
measures (incl. policies)
●  Privacy by design and default
●  Reply to data subject requests
Obligations as a controller
Page 20
Cover your own base (=> see also above
●  Look for certification on technical and organizational matters
●  Follow guidance of authorities
Insist of DPA covering a minimum amount of rules on
●  Type/categories of PD processed, purpose, duration
●  Appropriate tech and org measures e.g. encryption &
pseudonymisation
●  Breach notification assistance
●  Permit and "contribute" to compliance audits
●  Sub-contracting flow down commitments
Provide instructions to the processor
●  Best done via policies/standards that are regularly updated +
statement of works
Key action items as a controller
Lawfulness of processing
Consent & Legitimate interests
Page 22
Lawfulness of processing
Processing only lawful if:
●  Data subject has given consent
●  Necessary for the performance of contract or to take steps prior
to entering into a contract
●  Necessary to protect vital interests of data subject
●  Necessary for legitimate interests of controller or 3rd party
MS are allowed to
maintain or introduce
national provisions to
further specify the
application of these rules
(Recital 8)
●  Necessary for compliance with legal
obligation to which the controller is subject
●  Necessary for task carried out in the public
interest or exercise of official authority
Page 23
Consent strengthened under GDPR
NEW
●  Consent must be
•  actively given
•  separable from other written agreements
•  clearly presented
•  as easily revoked as given
●  Additional requirements include an effective prohibition on
"bundled" consents and the offering of services which are
contingent on consent to processing
●  Where consent is relied on controllers should be able to
demonstrate that consent was given by the data subject to the
processing
Page 24
It will be even harder to rely on consent
●  A clear, affirmative action
●  A written, electronic or oral statement
•  Ticking box on website
•  Choosing technical settings
•  Other statement or conduct
●  Consent is NOT
•  Silence (implied)
•  Pre-ticked boxes
●  Consent must be given (and demonstrated to have been given)
for all purposes of the processing
Consent will be a very difficult basis to rely on
© Bird & Bird LLP 2016
Page 25
Lawfulness of processing (4)
Legitimate interests
Article 7(f) DPD Article 6(1)(f) GDPR
processing is necessary for the
purposes of the legitimate interests
pursued by the controller or by the
third party or parties to whom the data
are disclosed, except where such
interests are overridden by the
interests for fundamental rights and
freedoms of the data subject which
require protection under Article 1 (1).
processing is necessary for the purposes of the
legitimate interests pursued by the controller or
by a third party, except where such interests are
overridden by the interests or fundamental rights
and freedoms of the data subject which require
protection of personal data, in particular where
the data subject is a child. This shall not apply to
processing carried out by public authorities in the
performance of their tasks.
Consent becomes rather
difficult to achieve &
demonstrate
Other grounds for
processingrelativelynarrow
Legitimate interests likely to
become one of the most
important grounds
Page 26
Legitimate interests
●  NEW Controllers that rely on "legitimate
interests" should maintain a record of the
assessment to demonstrate that they have
given proper consideration to the rights and
freedoms of data subjects
●  NEW When relying on "legitimate interests":
must be set out in the information notices
●  Recommendation: perform risk assessment
and documentation
Examples
●  Processing for direct marketing
purposes or preventing fraud
●  Transmission of personal data
within a group of undertakings for
internal administrative purposes,
including client and employee data
●  Processing for the purposes of
ensuring network and information
security, including preventing
unauthorised access to e-
communications networks and
stopping damage to computer and
e-communication systems
●  Reporting possible criminal acts or
threats to public security to a
competent authority

More Related Content

What's hot

EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
Tom Haynes
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution
Google
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Cvent
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
Claudio Bolla, CISM
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Omo Osagiede
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Caroline Boscher
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
Sarah Fox
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
RAKESH S
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
Jane Lambert
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
Paul O'Carroll
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
Stephanie Vasey
 
GDPR for developers
GDPR for developersGDPR for developers
GDPR for developers
Bozhidar Bozhanov
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to Opportunity
Dean Sappey
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
Capgemini
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Qualsys Ltd
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
Amarach Research
 
CIO Summit talk: EU GDPR
CIO Summit talk: EU GDPRCIO Summit talk: EU GDPR
CIO Summit talk: EU GDPR
John Culkin
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
Fintan Swanton
 

What's hot (20)

EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 
GDPR for developers
GDPR for developersGDPR for developers
GDPR for developers
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to Opportunity
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
CIO Summit talk: EU GDPR
CIO Summit talk: EU GDPRCIO Summit talk: EU GDPR
CIO Summit talk: EU GDPR
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 

Similar to Data breaches, privacy programs and what will change for processors

GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
Terry Gorry
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
Neha Patel
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
Lava Consult BVBA
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
EQS Group
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
NCVO - National Council for Voluntary Organisations
 
The Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR CompliantThe Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR Compliant
WSO2
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
Kwanzoo Inc
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018
Shane Gray
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
ControlCase
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Kimberly Simon MBA
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
accenture
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
Ulf Mattsson
 
GDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratgGDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratg
Cyber StratG
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
Match-Maker Ventures
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
Olivier BARROT
 

Similar to Data breaches, privacy programs and what will change for processors (20)

GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
The Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR CompliantThe Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR Compliant
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratgGDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratg
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 

More from Exove

Data security in the age of GDPR – most common data security problems
Data security in the age of GDPR – most common data security problemsData security in the age of GDPR – most common data security problems
Data security in the age of GDPR – most common data security problems
Exove
 
Provisioning infrastructure to AWS using Terraform – Exove
Provisioning infrastructure to AWS using Terraform – ExoveProvisioning infrastructure to AWS using Terraform – Exove
Provisioning infrastructure to AWS using Terraform – Exove
Exove
 
Advanced custom fields in Wordpress
Advanced custom fields in WordpressAdvanced custom fields in Wordpress
Advanced custom fields in Wordpress
Exove
 
Introduction to Robot Framework – Exove
Introduction to Robot Framework – ExoveIntroduction to Robot Framework – Exove
Introduction to Robot Framework – Exove
Exove
 
Jenkins and visual regression – Exove
Jenkins and visual regression – ExoveJenkins and visual regression – Exove
Jenkins and visual regression – Exove
Exove
 
Server-side React with Headless CMS – Exove
Server-side React with Headless CMS – ExoveServer-side React with Headless CMS – Exove
Server-side React with Headless CMS – Exove
Exove
 
WebSockets in Bravo Dashboard – Exove
WebSockets in Bravo Dashboard – ExoveWebSockets in Bravo Dashboard – Exove
WebSockets in Bravo Dashboard – Exove
Exove
 
Diversity in recruitment
Diversity in recruitmentDiversity in recruitment
Diversity in recruitment
Exove
 
Saavutettavuus liiketoimintana
Saavutettavuus liiketoimintanaSaavutettavuus liiketoimintana
Saavutettavuus liiketoimintana
Exove
 
Saavutettavuus osana Eläkeliiton verkkosivu-uudistusta
Saavutettavuus osana Eläkeliiton verkkosivu-uudistustaSaavutettavuus osana Eläkeliiton verkkosivu-uudistusta
Saavutettavuus osana Eläkeliiton verkkosivu-uudistusta
Exove
 
Mitä saavutettavuusdirektiivi pitää sisällään
Mitä saavutettavuusdirektiivi pitää sisälläänMitä saavutettavuusdirektiivi pitää sisällään
Mitä saavutettavuusdirektiivi pitää sisällään
Exove
 
Creating Landing Pages for Drupal 8
Creating Landing Pages for Drupal 8Creating Landing Pages for Drupal 8
Creating Landing Pages for Drupal 8
Exove
 
GDPR for developers
GDPR for developersGDPR for developers
GDPR for developers
Exove
 
Managing Complexity and Privacy Debt with Drupal
Managing Complexity and Privacy Debt with DrupalManaging Complexity and Privacy Debt with Drupal
Managing Complexity and Privacy Debt with Drupal
Exove
 
Life with digital services after GDPR
Life with digital services after GDPRLife with digital services after GDPR
Life with digital services after GDPR
Exove
 
GDPR - no beginning no end
GDPR - no beginning no endGDPR - no beginning no end
GDPR - no beginning no end
Exove
 
Developing truly personalised experiences
Developing truly personalised experiencesDeveloping truly personalised experiences
Developing truly personalised experiences
Exove
 
Customer Experience and Personalisation
Customer Experience and PersonalisationCustomer Experience and Personalisation
Customer Experience and Personalisation
Exove
 
Adventures In Programmatic Branding – How To Design With Algorithms And How T...
Adventures In Programmatic Branding – How To Design With Algorithms And How T...Adventures In Programmatic Branding – How To Design With Algorithms And How T...
Adventures In Programmatic Branding – How To Design With Algorithms And How T...
Exove
 
Dataohjattu asiakaskokemus
Dataohjattu asiakaskokemusDataohjattu asiakaskokemus
Dataohjattu asiakaskokemus
Exove
 

More from Exove (20)

Data security in the age of GDPR – most common data security problems
Data security in the age of GDPR – most common data security problemsData security in the age of GDPR – most common data security problems
Data security in the age of GDPR – most common data security problems
 
Provisioning infrastructure to AWS using Terraform – Exove
Provisioning infrastructure to AWS using Terraform – ExoveProvisioning infrastructure to AWS using Terraform – Exove
Provisioning infrastructure to AWS using Terraform – Exove
 
Advanced custom fields in Wordpress
Advanced custom fields in WordpressAdvanced custom fields in Wordpress
Advanced custom fields in Wordpress
 
Introduction to Robot Framework – Exove
Introduction to Robot Framework – ExoveIntroduction to Robot Framework – Exove
Introduction to Robot Framework – Exove
 
Jenkins and visual regression – Exove
Jenkins and visual regression – ExoveJenkins and visual regression – Exove
Jenkins and visual regression – Exove
 
Server-side React with Headless CMS – Exove
Server-side React with Headless CMS – ExoveServer-side React with Headless CMS – Exove
Server-side React with Headless CMS – Exove
 
WebSockets in Bravo Dashboard – Exove
WebSockets in Bravo Dashboard – ExoveWebSockets in Bravo Dashboard – Exove
WebSockets in Bravo Dashboard – Exove
 
Diversity in recruitment
Diversity in recruitmentDiversity in recruitment
Diversity in recruitment
 
Saavutettavuus liiketoimintana
Saavutettavuus liiketoimintanaSaavutettavuus liiketoimintana
Saavutettavuus liiketoimintana
 
Saavutettavuus osana Eläkeliiton verkkosivu-uudistusta
Saavutettavuus osana Eläkeliiton verkkosivu-uudistustaSaavutettavuus osana Eläkeliiton verkkosivu-uudistusta
Saavutettavuus osana Eläkeliiton verkkosivu-uudistusta
 
Mitä saavutettavuusdirektiivi pitää sisällään
Mitä saavutettavuusdirektiivi pitää sisälläänMitä saavutettavuusdirektiivi pitää sisällään
Mitä saavutettavuusdirektiivi pitää sisällään
 
Creating Landing Pages for Drupal 8
Creating Landing Pages for Drupal 8Creating Landing Pages for Drupal 8
Creating Landing Pages for Drupal 8
 
GDPR for developers
GDPR for developersGDPR for developers
GDPR for developers
 
Managing Complexity and Privacy Debt with Drupal
Managing Complexity and Privacy Debt with DrupalManaging Complexity and Privacy Debt with Drupal
Managing Complexity and Privacy Debt with Drupal
 
Life with digital services after GDPR
Life with digital services after GDPRLife with digital services after GDPR
Life with digital services after GDPR
 
GDPR - no beginning no end
GDPR - no beginning no endGDPR - no beginning no end
GDPR - no beginning no end
 
Developing truly personalised experiences
Developing truly personalised experiencesDeveloping truly personalised experiences
Developing truly personalised experiences
 
Customer Experience and Personalisation
Customer Experience and PersonalisationCustomer Experience and Personalisation
Customer Experience and Personalisation
 
Adventures In Programmatic Branding – How To Design With Algorithms And How T...
Adventures In Programmatic Branding – How To Design With Algorithms And How T...Adventures In Programmatic Branding – How To Design With Algorithms And How T...
Adventures In Programmatic Branding – How To Design With Algorithms And How T...
 
Dataohjattu asiakaskokemus
Dataohjattu asiakaskokemusDataohjattu asiakaskokemus
Dataohjattu asiakaskokemus
 

Recently uploaded

Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
anjalidixit21
 
Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
Knowyourright
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Gabe Whitley
 
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptxASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
shweeta209
 
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptxRIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
OmGod1
 
Cold War - 1, talks about cold water bro
Cold War - 1, talks about cold water broCold War - 1, talks about cold water bro
Cold War - 1, talks about cold water bro
SidharthKashyap5
 
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptxPRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
OmGod1
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
9ib5wiwt
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
BridgeWest.eu
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
Wendy Couture
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
ssuser5750e1
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
9ib5wiwt
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
ssuser0576e4
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Thomas (Tom) Jasper
 
DNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptxDNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptx
patrons legal
 
WINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of DissolutionWINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of Dissolution
KHURRAMWALI
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
BRELGOSIMAT
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
Abdul-Hakim Shabazz
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
MwaiMapemba
 

Recently uploaded (20)

Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
 
Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
 
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptxASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
 
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptxRIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
 
Cold War - 1, talks about cold water bro
Cold War - 1, talks about cold water broCold War - 1, talks about cold water bro
Cold War - 1, talks about cold water bro
 
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptxPRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
 
DNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptxDNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptx
 
WINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of DissolutionWINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of Dissolution
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
 

Data breaches, privacy programs and what will change for processors

  • 1. Exove Tietoturvaloukkaukset, yksityisyydensuojan parantaminen ja GDPR:n tuomat muutokset henkilötietojen käsittelijöille Tobias Bräutigam, Counsel
  • 2. Agenda 1.  Rights for individuals 2.  Controller/Processor Role based examples of obligations 3.  Data Breach Page 2
  • 4. New rights for individuals? Page 4 Article What is it about New? 13/14 Transparency, right to be informed More details 15 Access to personal data Clarification, more detail 16 Rectification of inaccurate data Old 17 Right to be forgotten Not so new like you think 18 Right to restrict processing Clarification, more detail 20 Data portability New 21 Automated decision making More detail, larger scope
  • 5. Page 5 Much ado about nothing? 1.  Fines from authorities for the violation of rights •  4%, i.e. higher level 2.  Enforcement via private action, Article 79 •  Also "non-material" damage is covered, Article 82 3.  Can be delegated •  Consumer organizations will take care of it Summary •  As such relatively small changes, modifications, clarifications •  Enforcement: Huge change
  • 6. What does the GDPR mean for processors?
  • 8. Page 8 Processor's new obligations Assisting controllers ●  Only act on the controller's documented instructions; ●  Assisting the Controller for responding to requests from data subjects for: access, rectification, suppression, limitation, objection, portability of data ●  Return or delete personal data upon Controller's choice at the end of services ●  Assisting the controller to notify security breaches, implement DPIAs, provide information ●  Contribute to audits, including directly made by the Controller ●  Mandatory contract clauses Own responsibility ●  List of technical and organizational measures ●  Processor's staff must be bound by confidentiality obligations ●  Compliance with international data transfers
  • 9. Page 9 Key action items as a processor Build your privacy program ●  Hire a privacy officer where needed ●  Define security measures, processes and responsibilties Indemnity and liability ●  Push back on indemnities (strict liability) ●  Push back on unlimited liability clauses, tie to negligence Define the lines of responsibilities ●  Only process based on instructions and GDPR
  • 11. Page 11 Article 33 In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority […], unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
  • 12. What amounts to a ‘breach’ under the new rules and to whom the regime applies? Page 12 ●  Relevant provisions in the GDPR can be found in: •  Recitals: 73, 85-88 •  Articles: 4, 33, 34, 66 and 83 ●  The regime applies to data controllers but indirectly also to their processors ●  The GDPR refers to "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed" ●  It’s important to note that the wilful destruction or alteration of data is as much a breach as theft
  • 13. Practical scenarios for your organisation to consider Page 13 Breach? Four laptops containing 5,000 employee records are stolen from the HR department… A flash drive containing 5,000 customer records is forgotten in a bus and never retrieved. There is no evidence that customer records were compromised. An employee has given to a third party the login and password for an account with global access read only right to the client database. Logs evidence use of the account by this third party. A rogue employee supresses all contact details provided in the consumer records of his organisation before resigning.
  • 14. Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses. Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number OC340318 and is authorised and regulated by the Solicitors Regulation Authority. Its registered office and principal place of business is at 12 New Fetter Lane, London EC4A 1JP. A list of members of Bird & Bird LLP and of any non-members who are designated as partners, and of their respective professional qualifications, is open to inspection at that address. twobirds.com Thank you
  • 15. Page 15 Demonstrate compliance with the GDPR's principles ●  Implement appropriate security policies and measures ●  Privacy impact assessment and prior consultation (when applicable) ●  Adopt certain "data protection by design" measures ●  Record of all processing activities ●  Undertake audits ●  Adherence to approved codes of conduct and certifications ●  Implement Privacy Policies ●  Appropriate staffing (e.g. data protection officer) ●  Staff training programs General obligations
  • 16. Page 16 Work on your privacy program ●  Audit your privacy practices (use self-assessments and interviews) ●  Start designing governance and risk management elements first ●  Decide which IT-systems need to be improved to close gaps (e.g. consumer dash-board) ●  Improve privacy processes like subcontractor management, data subject access, partnering Key action items for general compliance
  • 17. Page 17 Transparency ●  General privacy policy must mention specific information, such as legal basis, data retention, contact details of DP officer etc. ●  Specific notices where needed, e.g. information about the right to withdraw consent Legitimacy of processing ●  Most data processing is *not* based on consent! ●  Performance of a contract or legitimate interest (e.g. Marketing to employees of corporate subscribers) ●  Where consent is the only option, systems must be ready for withdrawal of consent Honouring data subject rights ●  Access, rectification, limitation, objection, portability of data ●  If acting as a processor, Exove must assist the controller fulfilling those rights Obligations towards data subjects (for example: corporate subscribers and consumers)
  • 18. Page 18 Define reason for processing for each major process ●  Legitimate interest, consent or contract? Review privacy notices ●  Follow list in Articles 13/14 GDPR Design access and deletion process of data subjects ●  This includes appropriate IT systems and training of staff ●  Draft/update template responses Key action items: compliance towards data subjects
  • 19. Page 19 Managing processors ●  Review and update all data processing agreements ●  Instruct processors and follow up (audit) Accountability ●  Keep records of all processing activities ●  Appointment of DPO (if applicable) ●  Map data transfer and compliance ●  Staff training programs and collection of metrics General obligations ●  Implement appropriate technical and organizational security measures (incl. policies) ●  Privacy by design and default ●  Reply to data subject requests Obligations as a controller
  • 20. Page 20 Cover your own base (=> see also above ●  Look for certification on technical and organizational matters ●  Follow guidance of authorities Insist of DPA covering a minimum amount of rules on ●  Type/categories of PD processed, purpose, duration ●  Appropriate tech and org measures e.g. encryption & pseudonymisation ●  Breach notification assistance ●  Permit and "contribute" to compliance audits ●  Sub-contracting flow down commitments Provide instructions to the processor ●  Best done via policies/standards that are regularly updated + statement of works Key action items as a controller
  • 21. Lawfulness of processing Consent & Legitimate interests
  • 22. Page 22 Lawfulness of processing Processing only lawful if: ●  Data subject has given consent ●  Necessary for the performance of contract or to take steps prior to entering into a contract ●  Necessary to protect vital interests of data subject ●  Necessary for legitimate interests of controller or 3rd party MS are allowed to maintain or introduce national provisions to further specify the application of these rules (Recital 8) ●  Necessary for compliance with legal obligation to which the controller is subject ●  Necessary for task carried out in the public interest or exercise of official authority
  • 23. Page 23 Consent strengthened under GDPR NEW ●  Consent must be •  actively given •  separable from other written agreements •  clearly presented •  as easily revoked as given ●  Additional requirements include an effective prohibition on "bundled" consents and the offering of services which are contingent on consent to processing ●  Where consent is relied on controllers should be able to demonstrate that consent was given by the data subject to the processing
  • 24. Page 24 It will be even harder to rely on consent ●  A clear, affirmative action ●  A written, electronic or oral statement •  Ticking box on website •  Choosing technical settings •  Other statement or conduct ●  Consent is NOT •  Silence (implied) •  Pre-ticked boxes ●  Consent must be given (and demonstrated to have been given) for all purposes of the processing Consent will be a very difficult basis to rely on © Bird & Bird LLP 2016
  • 25. Page 25 Lawfulness of processing (4) Legitimate interests Article 7(f) DPD Article 6(1)(f) GDPR processing is necessary for the purposes of the legitimate interests pursued by the controller or by the third party or parties to whom the data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subject which require protection under Article 1 (1). processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. This shall not apply to processing carried out by public authorities in the performance of their tasks. Consent becomes rather difficult to achieve & demonstrate Other grounds for processingrelativelynarrow Legitimate interests likely to become one of the most important grounds
  • 26. Page 26 Legitimate interests ●  NEW Controllers that rely on "legitimate interests" should maintain a record of the assessment to demonstrate that they have given proper consideration to the rights and freedoms of data subjects ●  NEW When relying on "legitimate interests": must be set out in the information notices ●  Recommendation: perform risk assessment and documentation Examples ●  Processing for direct marketing purposes or preventing fraud ●  Transmission of personal data within a group of undertakings for internal administrative purposes, including client and employee data ●  Processing for the purposes of ensuring network and information security, including preventing unauthorised access to e- communications networks and stopping damage to computer and e-communication systems ●  Reporting possible criminal acts or threats to public security to a competent authority