SlideShare a Scribd company logo
Education law conferences 2018
Keynote 2: 10 steps in 10 weeks to GDPR
compliance
10 steps in 10 weeks to GDPR compliance
Is it really that straightforward…?
Join the conversation #BJ_EDC
Why the change?
Very different data landscape than in 1998
Why the change?
90% of all data in the world today created in past few years
2.5 exabytes - that's 2.5 billion gigabytes (GB) - of data was
generated every day in 2012
2018 - 50,000 GB per second
Data per minute today
• 216,000 Instagram posts
• 204,000,000 emails
• 12 hours of footage is uploaded to YouTube
• 277,000 tweets are posted
Key points
• Comes into effect on 25 May 2018 across Europe
• Main concepts and principles remain the same, but new
elements of it enhance the provisions under the DPA
• Some hefty fines… Up to €20,000,000 fine
Sli.do – vote now
How are we feeling about GDPR?
• GDP what…?
• I’m getting there
• I’m worried about staff compliance
• I’m relaxed, I’ve got it all sorted
The 10 steps
Join the conversation #BJ_EDC
Steps to take now
1. Awareness and leadership across the trust
2. Review the information you hold and how and why you
process (include mapping tool)
3. Third party data sharing contracts
4. Review privacy notices and retention and destruction policy
5. Review procedures for individual rights and SARs
Steps to take now
6. Review how you obtain consent
7. Data breach management
8. Privacy by design
9. Take the opportunity to review staff practices
10. Consider training/re-education needs of staff
1. Awareness and leadership
• Make sure decision makers aware of change and impact
• Nominate a responsible member of SLT
• Organise a working group (IT, HR) and put regular meetings
in the diary
2. Information you hold
• Carry out a data mapping exercise
• Document the information you hold
• Where did it came from?
• With whom do you share it?
• Why are you keeping it?
This gets you 50% of the way there…
3. Third party contracts
• Do you share information with other companies?
• Payroll?
• Catering contractors?
• Review the contracts. If they go beyond 25 May 2018 they
will require amendment to reflect GDPR changes
• Ask those third parties to confirm GDPR compliance
4. Privacy notices and retention/destruction
• New privacy notices must include:
• Legal basis for processing
• Data retention periods
• Complaints
• Concise, easy to understand and language
• ICO privacy notice code of practice reflects changes
4. Privacy notices and retention/destruction
• Do you have a retention/destruction policy?
• Why did you choose those timeframes?
• Do you follow it?
• IRMS Information management toolkit for schools
5. Individual rights and subject access request
• Check procedures to make sure they cover all new rights
• Subject access
• Inaccuracies corrected - rectification
• Information erased (‘right to be forgotten’)
• Object to direct marketing and automated decision-making
and profiling
5. Individual rights and subject access request
• Must provide the following to data subjects on request:
• Identity and contact details of data controller and DPO
• Intended purpose of processing and period it will be stored
• Existence of rights: access, rectification, object and erasure
• Right to complain internally and to a supervisory authority
• Categories of recipients to whom data will be disclosed
• Information must be concise, transparent, intelligible and
easily accessible
5. Individual rights and subject access request
• No fee
• Must be provided in writing unless otherwise
requested (requestor can ask for electronic format)
• Must respond within one month - can extend for
complex requests
• Manifestly unfounded or excessive requests may
be charged for or refused
This gets you 70% of the way there…
6. Consent
• Must be freely given, specific, informed and unambiguous,
and a positive affirmation of the individual’s agreement
• Cannot be bundled in with other terms/consents
• Withdrawal of consent should be as easy as grant
of consent
This gets you 80% of the way there…
7. Data breach management
• Must have procedures in place to detect, report and
investigate a personal data breach
• 72 hours from the discovery of the breach to report to ICO
• Breach must be reported unless the personal data breach is
unlikely to result in a risk to the rights and freedoms of
natural persons
• Notify the affected data subjects
8. Privacy by design
• At the outset of every project think about personal data
• Consider how you can minimise personal data use and risk
• Legal requirement to carry out a privacy impact assessment
• ICO guidance on privacy impact assessments
9. Staff practices
…(Governors and trustees/directors too)
• Use of personal emails rather than trust emails?
• Taking hard copy personal data home/out of school?
• Downloading data onto a non-school device?
• USBs, discs, data rooms etc.
This is that difficult final 20%...
10. Training/re-education
• Train staff to recognise a subject access request
• Train/re-educate regarding data security and off site use
• If policies are changed, consider how you disseminate and
evidence staff understanding
• What other training might they need?
Sli.do – vote now
How are we feeling about GDPR now?
• GDP what…?
• I’m getting there
• I’m worried about staff compliance
• I’m relaxed, I’ve got it all sorted
www.brownejacobson.com/education
Please note
The information contained in these notes is based on the
position at March 2018. It does, of course, only represent a
summary of the subject matter covered and is not intended to
be a substitute for detailed advice. If you would like to discuss
any of the matters covered in further detail, our team would
be happy to do so.
© Browne Jacobson LLP 2018. Browne Jacobson LLP is a
limited liability partnership.

More Related Content

What's hot

Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
Zymplify
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
BartLieben
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
CharityComms
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)
Bright
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
CILIPScotland
 
Rent-a-DPO for IT Vendors
Rent-a-DPO for IT VendorsRent-a-DPO for IT Vendors
Rent-a-DPO for IT Vendors
Richard Kranendonk
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
Symptai Consulting Limited
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
Match-Maker Ventures
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
Microsoft Österreich
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
Promapp Solutions
 
Balancing Privacy and Digitization
Balancing Privacy and DigitizationBalancing Privacy and Digitization
Balancing Privacy and Digitization
Symptai Consulting Limited
 
Enterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving ChangeEnterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving ChangeIron Mountain
 
What Every Attorney Needs to Know
What Every Attorney Needs to KnowWhat Every Attorney Needs to Know
What Every Attorney Needs to Know
BoyarMiller
 
Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions
3Play Media
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
DATAVERSITY
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
Jonathan Chilton
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Iron Mountain
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
TrustArc
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
Piwik PRO
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
GDPR Course
 

What's hot (20)

Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
 
Rent-a-DPO for IT Vendors
Rent-a-DPO for IT VendorsRent-a-DPO for IT Vendors
Rent-a-DPO for IT Vendors
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
Balancing Privacy and Digitization
Balancing Privacy and DigitizationBalancing Privacy and Digitization
Balancing Privacy and Digitization
 
Enterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving ChangeEnterprise Discovery: Taking Control, Driving Change
Enterprise Discovery: Taking Control, Driving Change
 
What Every Attorney Needs to Know
What Every Attorney Needs to KnowWhat Every Attorney Needs to Know
What Every Attorney Needs to Know
 
Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions Accessibility 101 for Financial Institutions
Accessibility 101 for Financial Institutions
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
 

Similar to Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GDPR compliance

Education law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOEducation law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPO
Browne Jacobson LLP
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
NiclasGranqvist
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
NCVO - National Council for Voluntary Organisations
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
Louise Owens
 
15. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 201015. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 2010Brian Bailey
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
AIIM International
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
James Mulhern
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library Service
CILIPScotland
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
Browne Jacobson LLP
 
Privacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User Data
PrivacyCenter.cloud
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
Marketo
 

Similar to Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GDPR compliance (20)

Education law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOEducation law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPO
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
15. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 201015. Brian Bailey presentation 2 DQ Asia Pacific 2010
15. Brian Bailey presentation 2 DQ Asia Pacific 2010
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library Service
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Privacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User Data
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 

More from Browne Jacobson LLP

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020
Browne Jacobson LLP
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed
Browne Jacobson LLP
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham session
Browne Jacobson LLP
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019
Browne Jacobson LLP
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...
Browne Jacobson LLP
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019
Browne Jacobson LLP
 
Health tech slides 12 june 2019
Health tech slides   12 june 2019Health tech slides   12 june 2019
Health tech slides 12 june 2019
Browne Jacobson LLP
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019
Browne Jacobson LLP
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019
Browne Jacobson LLP
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019
Browne Jacobson LLP
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - Birmingham
Browne Jacobson LLP
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London
Browne Jacobson LLP
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London
Browne Jacobson LLP
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019
Browne Jacobson LLP
 
In House Lawyers, March 2019
In House Lawyers, March 2019In House Lawyers, March 2019
In House Lawyers, March 2019
Browne Jacobson LLP
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019
Browne Jacobson LLP
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, Manchester
Browne Jacobson LLP
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter
Browne Jacobson LLP
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, Nottingham
Browne Jacobson LLP
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...
Browne Jacobson LLP
 

More from Browne Jacobson LLP (20)

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham session
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019
 
Health tech slides 12 june 2019
Health tech slides   12 june 2019Health tech slides   12 june 2019
Health tech slides 12 june 2019
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - Birmingham
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019
 
In House Lawyers, March 2019
In House Lawyers, March 2019In House Lawyers, March 2019
In House Lawyers, March 2019
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, Manchester
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, Nottingham
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...
 

Recently uploaded

XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
bhavenpr
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
Wendy Couture
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
9ib5wiwt
 
The Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptxThe Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptx
nehatalele22st
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
BRELGOSIMAT
 
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptxNATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
anvithaav
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
Trademark Quick
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
9ib5wiwt
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
Dr. Oliver Massmann
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
ssuser5750e1
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
BridgeWest.eu
 
Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
Knowyourright
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Gabe Whitley
 
VAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act PresentationVAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act Presentation
FernandoSimesBlanco1
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
46adnanshahzad
 
Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
johncavitthouston
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
ssuser0576e4
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
9ib5wiwt
 
Bharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptxBharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptx
ShivkumarIyer18
 

Recently uploaded (20)

XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
 
The Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptxThe Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptx
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
 
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptxNATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
 
Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
 
VAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act PresentationVAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act Presentation
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
 
Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
 
Bharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptxBharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptx
 

Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GDPR compliance

  • 1. Education law conferences 2018 Keynote 2: 10 steps in 10 weeks to GDPR compliance
  • 2. 10 steps in 10 weeks to GDPR compliance Is it really that straightforward…? Join the conversation #BJ_EDC
  • 3. Why the change? Very different data landscape than in 1998
  • 4. Why the change? 90% of all data in the world today created in past few years 2.5 exabytes - that's 2.5 billion gigabytes (GB) - of data was generated every day in 2012 2018 - 50,000 GB per second
  • 5. Data per minute today • 216,000 Instagram posts • 204,000,000 emails • 12 hours of footage is uploaded to YouTube • 277,000 tweets are posted
  • 6. Key points • Comes into effect on 25 May 2018 across Europe • Main concepts and principles remain the same, but new elements of it enhance the provisions under the DPA • Some hefty fines… Up to €20,000,000 fine
  • 7. Sli.do – vote now How are we feeling about GDPR? • GDP what…? • I’m getting there • I’m worried about staff compliance • I’m relaxed, I’ve got it all sorted
  • 8. The 10 steps Join the conversation #BJ_EDC
  • 9. Steps to take now 1. Awareness and leadership across the trust 2. Review the information you hold and how and why you process (include mapping tool) 3. Third party data sharing contracts 4. Review privacy notices and retention and destruction policy 5. Review procedures for individual rights and SARs
  • 10. Steps to take now 6. Review how you obtain consent 7. Data breach management 8. Privacy by design 9. Take the opportunity to review staff practices 10. Consider training/re-education needs of staff
  • 11. 1. Awareness and leadership • Make sure decision makers aware of change and impact • Nominate a responsible member of SLT • Organise a working group (IT, HR) and put regular meetings in the diary
  • 12. 2. Information you hold • Carry out a data mapping exercise • Document the information you hold • Where did it came from? • With whom do you share it? • Why are you keeping it? This gets you 50% of the way there…
  • 13. 3. Third party contracts • Do you share information with other companies? • Payroll? • Catering contractors? • Review the contracts. If they go beyond 25 May 2018 they will require amendment to reflect GDPR changes • Ask those third parties to confirm GDPR compliance
  • 14. 4. Privacy notices and retention/destruction • New privacy notices must include: • Legal basis for processing • Data retention periods • Complaints • Concise, easy to understand and language • ICO privacy notice code of practice reflects changes
  • 15. 4. Privacy notices and retention/destruction • Do you have a retention/destruction policy? • Why did you choose those timeframes? • Do you follow it? • IRMS Information management toolkit for schools
  • 16. 5. Individual rights and subject access request • Check procedures to make sure they cover all new rights • Subject access • Inaccuracies corrected - rectification • Information erased (‘right to be forgotten’) • Object to direct marketing and automated decision-making and profiling
  • 17. 5. Individual rights and subject access request • Must provide the following to data subjects on request: • Identity and contact details of data controller and DPO • Intended purpose of processing and period it will be stored • Existence of rights: access, rectification, object and erasure • Right to complain internally and to a supervisory authority • Categories of recipients to whom data will be disclosed • Information must be concise, transparent, intelligible and easily accessible
  • 18. 5. Individual rights and subject access request • No fee • Must be provided in writing unless otherwise requested (requestor can ask for electronic format) • Must respond within one month - can extend for complex requests • Manifestly unfounded or excessive requests may be charged for or refused This gets you 70% of the way there…
  • 19. 6. Consent • Must be freely given, specific, informed and unambiguous, and a positive affirmation of the individual’s agreement • Cannot be bundled in with other terms/consents • Withdrawal of consent should be as easy as grant of consent This gets you 80% of the way there…
  • 20. 7. Data breach management • Must have procedures in place to detect, report and investigate a personal data breach • 72 hours from the discovery of the breach to report to ICO • Breach must be reported unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons • Notify the affected data subjects
  • 21. 8. Privacy by design • At the outset of every project think about personal data • Consider how you can minimise personal data use and risk • Legal requirement to carry out a privacy impact assessment • ICO guidance on privacy impact assessments
  • 22. 9. Staff practices …(Governors and trustees/directors too) • Use of personal emails rather than trust emails? • Taking hard copy personal data home/out of school? • Downloading data onto a non-school device? • USBs, discs, data rooms etc. This is that difficult final 20%...
  • 23. 10. Training/re-education • Train staff to recognise a subject access request • Train/re-educate regarding data security and off site use • If policies are changed, consider how you disseminate and evidence staff understanding • What other training might they need?
  • 24. Sli.do – vote now How are we feeling about GDPR now? • GDP what…? • I’m getting there • I’m worried about staff compliance • I’m relaxed, I’ve got it all sorted
  • 26. Please note The information contained in these notes is based on the position at March 2018. It does, of course, only represent a summary of the subject matter covered and is not intended to be a substitute for detailed advice. If you would like to discuss any of the matters covered in further detail, our team would be happy to do so. © Browne Jacobson LLP 2018. Browne Jacobson LLP is a limited liability partnership.