SlideShare a Scribd company logo
1 of 30
Data Protection
EU General Data
Protection Regulation
Webinar Presenters
Miles Maier @LasaICT
Paul Ticher @PaulTicher
Supported by
• Lasa actively promotes and supports the Way Ahead
– Civil Society at the Heart of London. See
www.citybridgetrust.org.uk/publications/way-ahead/
• This webinar is supported by the City of London
Corporation's charity, City Bridge Trust.
www.citybridgetrust.org.uk
About Lasa
• 30 years in the sector
• Technology leadership, publications, events
and consultancy
www.lasa.org.uk
• Welfare Rights
www.rightsnet.org.uk
Webinar Tips
• Ask questions
Post questions via chat or raise your virtual hand
• Interact
Respond to polls during webinar
• Focus
Avoid multitasking. You may just miss the best part of the
presentation
• Webinar PowerPoint & Recording
PowerPoint and recording links will be shared after the
webinar
Paul Ticher
• Data Protection expert, author and trainer
• Specialist in information management and
systems
• Many charity clients
Twitter: @PaulTicher
Data Protection:
The new EU Regulation
June 2017
This presentation is intended to help you
understand aspects of the EU General Data
Protection Regulation and related legislation.
It is not intended to provide detailed advice
on specific points, and is not necessarily a full
statement of the law.
Protecting people


Protecting data
What Data Protection is about: 1
Privacy & choice
Give us
more
money!
Support our
campaign! But of course
we told your
social worker
What Data Protection is about: 2
 Right of Subject Access
Individual rights, such as:
 Right to opt out of direct marketing
 Right to compensation for harm
What Data Protection is about: 3
The current legal framework
EC Directive 95/46/EC
 Data Protection Act 1998
 Similar legislation in most other European countries
Privacy & Electronic Communications (EC Directive)
Regulations 2003
Non-statutory Guidance and Codes of Practice,
including:
 Information Commissioner
 Institute of Fundraising
The new Regulation
First draft January 2012
Extensive negotiations between Commission,
Parliament and Council over nearly four years
Final agreed draft December 2015
Published May 2016 (Reg. 2016/679)
Coming into force 25th May 2018
It’s a Regulation, not a Directive
Themes
“The processing of personal data should be designed
to serve [hu]mankind” (Recital 4)
More control over online services and large
commercial organisations, especially multinationals
Emphasis on reducing risk
Limited extension of individual rights
Data Controller evidence of compliance
Main changes include:
 Definition of consent tightened up
 … but still not always required
 Tighter rules on children’s data (under 16), especially online
 More transparency requirements
 Data minimisation and pseudonymisation
 More rights to have data erased
 Provision for allocating responsibilities between joint Data Controllers
 Data Processors carry more direct responsibilities
 No registration: Data Controller has to keep records
 Requirement to notify serious breaches
 Bigger fines
 Additional responsibilities on large organisations and those doing riskier
processing
Consent
Consent is “any freely given, specific, informed and
unambiguous indication of his or her wishes by which
the data subject, either by a statement or by a clear
affirmative action, signifies agreement to personal
data relating to them being processed” (Article 4(11))
“Where processing is based on consent, the
controller shall be able to demonstrate that consent
was given by the data subject … ” (Article 7(1))
“Silence, pre-ticked boxes or inactivity should … not
constitute consent.” (Recital 32)
When is consent not required?
Similar conditions to now, including:
Processing is lawful [if it is] “necessary for the purposes
of the legitimate interests pursued by the controller or by
a third party, except where such interests are overridden
by the interests or fundamental rights and freedoms of
the data subject which require protection of personal
data, in particular where the data subject is a child. …”
(Article 6(f) )
“The processing of personal data for direct marketing
purposes may be regarded as carried out for a legitimate
interest.” (Recital 47)
Where does this leave
fundraising?
Definitions unclear: when does a communication
become marketing?
How does the fundraising Code relate to the
marketing provisions of the Regulation?
New Regulation does not rescind PECR
Therefore, consent is likely to remain the only reliable
basis for most direct unsolicited fundraising
Consent has to involve “clear affirmative action”
Therefore, are we looking at opting in only?
Tighter rules on children’ data
 Children deserve specific protection … as they may be less
aware of risks, consequences, safeguards and their rights … .
This concerns especially the use of personal data of children for
the purposes of marketing or creating personality or user
profiles and the collection of child data when using services
offered directly to a child. … (Recital 29)
 Where [consent] applies, in relation to the offering of
information society services directly to a child, the processing of
personal data of a child below the age of 16 years … shall only
be lawful if … consent is given … by the holder of parental
responsibility over the child.
More transparency requirements
(Articles 13 & 14)
Data Subjects must usually be made aware of:
 the identity and the contact details of the controller
 the purposes as well as the legal basis of the processing
 where relevant the legitimate interests
 any recipient(s); any overseas transfers
 the storage period or criteria for deletion
 right of access to data and rectification or erasure
 right to withdraw consent at any time
 the right to lodge a complaint to a supervisory authority
 whether the provision of personal data is [contractually]
required [or] the data subject is obliged to provide the data and
… possible consequences of failure to provide [it]
Minimisation and
pseudonymisation
Principle 3 now says data must be: “adequate,
relevant and limited to what is necessary … (“data
minimisation”)”
Data protection by design and by default (Article 25)
stresses pseudonymisation as a security measure –
especially for things like ‘big data’ analysis
Pseudonymisation means that the person is still
identifiable but their identity can only be retrieved
with the use of additional data which is held
separately and securely
Rights to erasure, etc.
Data Subjects have the rights to require:
Rectification of inaccurate data (Article 16)
Completion of incomplete data (Article 16)
Erasure (“right to be forgotten”), with exceptions,
but including removal of links (Article 17)
Restriction of processing in certain cases (Article 18)
Compensation for “material or non-material damage”
(Article 82)
Also the right to complain to the supervisory authority
Data Controller responsibilities
Technical and organisational measures to ensure full
compliance (Article 24)
Appropriate policies (including Data Protection by design
and by default) (Articles 24 & 25)
Records of processing – what, who, how, etc. (Article 30)
… but no registration (notification)
Joint Controllers must transparently “determine their
respective responsibilities” – but each can be “liable for
the entire damage” caused by a breach (Articles 26 & 82)
Data Processor responsibilities
(Article 28)
Data Controller still has responsibility to select
competent Processors
More detailed rules about what has to be in the
contract
Standard contracts should be available
Processor may be liable for breaches and other
compliance (many obligations refer to the “controller
or processor” – including processors based overseas)
Notification of serious breaches
(Article 33)
Must report (preferably within 72 hours) unless the
breach is unlikely to result in a risk to individuals
Individuals must usually be notified where the breach
is likely to result in a high risk to them
Processors must notify breaches to Controllers
Penalties
(Article 79)
Breaches subject to two levels of penalty, depending
on the breach:
€10 million or 2% of total worldwide turnover
€20 million or 4% of total worldwide turnover
(whichever is higher, in each case)
Large organisations & riskier
activities
Impact assessments before starting innovative
processing (Article 35)
Data Protection Officer, with specified competence
and duties (Articles 37– 39)
Selected other changes
Overseas transfers – slight loosening of the
conditions that legitimise transfers (Article 49)
Jurisdiction over multi-national companies operating
into Europe (including web-based) (Recital 101)
Scope for national variations in a number of places
Many thanks
Any questions, clarifications, feedback:
paul@pauticher.com
Follow-up questions:
paul@paulticher.com
Lasa:
@LasaICT

More Related Content

What's hot

Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 
Introduction to gdpr
Introduction to gdprIntroduction to gdpr
Introduction to gdpr3GDR
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017isc2-hellenic
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Lauren Isaacs
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPRTripwire
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 

What's hot (20)

Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
Introduction to gdpr
Introduction to gdprIntroduction to gdpr
Introduction to gdpr
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 

Similar to EU General Data Protection Regulation - Update 2017

GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!Fintan Swanton
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Dione McBride, CISSP, CIPP/E
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protectionInterlogica
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
Legal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services SectorLegal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services SectorMSpadea
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
250220 blockchain gdpr_blockchain_hillemann_presentation
250220 blockchain gdpr_blockchain_hillemann_presentation250220 blockchain gdpr_blockchain_hillemann_presentation
250220 blockchain gdpr_blockchain_hillemann_presentationDennisHillemann
 
General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary Compliance3
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT LegalCyber Watching
 

Similar to EU General Data Protection Regulation - Update 2017 (20)

GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
 
GDPR
GDPRGDPR
GDPR
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
VIAF GDPR
VIAF GDPRVIAF GDPR
VIAF GDPR
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protection
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
Legal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services SectorLegal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services Sector
 
Cyber safe lambeth | GDPR taster
Cyber safe lambeth | GDPR tasterCyber safe lambeth | GDPR taster
Cyber safe lambeth | GDPR taster
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
250220 blockchain gdpr_blockchain_hillemann_presentation
250220 blockchain gdpr_blockchain_hillemann_presentation250220 blockchain gdpr_blockchain_hillemann_presentation
250220 blockchain gdpr_blockchain_hillemann_presentation
 
General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
 

More from Cliff Ashcroft

Facebook for Charities
Facebook for CharitiesFacebook for Charities
Facebook for CharitiesCliff Ashcroft
 
Google Analytics for charities
Google Analytics for charitiesGoogle Analytics for charities
Google Analytics for charitiesCliff Ashcroft
 
Webinar: Office 365 for Beginners
Webinar: Office 365 for BeginnersWebinar: Office 365 for Beginners
Webinar: Office 365 for BeginnersCliff Ashcroft
 
Using Technology to Help deliver Advice Services
Using Technology to Help deliver Advice ServicesUsing Technology to Help deliver Advice Services
Using Technology to Help deliver Advice ServicesCliff Ashcroft
 
Google Analytics for Charities
Google Analytics for CharitiesGoogle Analytics for Charities
Google Analytics for CharitiesCliff Ashcroft
 
Office 365 and using SharePoint Online
Office 365 and using SharePoint OnlineOffice 365 and using SharePoint Online
Office 365 and using SharePoint OnlineCliff Ashcroft
 
Top 10 social media tips
Top 10 social media tipsTop 10 social media tips
Top 10 social media tipsCliff Ashcroft
 
Community IT resources
Community IT resourcesCommunity IT resources
Community IT resourcesCliff Ashcroft
 
Using technology to help deliver Advice Services
Using technology to help deliver Advice ServicesUsing technology to help deliver Advice Services
Using technology to help deliver Advice ServicesCliff Ashcroft
 
Connecting Care @ National Care Forum
Connecting Care @ National Care ForumConnecting Care @ National Care Forum
Connecting Care @ National Care ForumCliff Ashcroft
 
Lasa esolutions campaigning and awareness
Lasa esolutions campaigning and awarenessLasa esolutions campaigning and awareness
Lasa esolutions campaigning and awarenessCliff Ashcroft
 
Better Digital Marketing
Better Digital MarketingBetter Digital Marketing
Better Digital MarketingCliff Ashcroft
 
Lasa amplify your multimedia content
Lasa amplify your multimedia contentLasa amplify your multimedia content
Lasa amplify your multimedia contentCliff Ashcroft
 

More from Cliff Ashcroft (20)

Facebook for Charities
Facebook for CharitiesFacebook for Charities
Facebook for Charities
 
Google Analytics for charities
Google Analytics for charitiesGoogle Analytics for charities
Google Analytics for charities
 
Webinar: Office 365 for Beginners
Webinar: Office 365 for BeginnersWebinar: Office 365 for Beginners
Webinar: Office 365 for Beginners
 
Using Technology to Help deliver Advice Services
Using Technology to Help deliver Advice ServicesUsing Technology to Help deliver Advice Services
Using Technology to Help deliver Advice Services
 
Google Analytics for Charities
Google Analytics for CharitiesGoogle Analytics for Charities
Google Analytics for Charities
 
Office 365 and using SharePoint Online
Office 365 and using SharePoint OnlineOffice 365 and using SharePoint Online
Office 365 and using SharePoint Online
 
Top 10 social media tips
Top 10 social media tipsTop 10 social media tips
Top 10 social media tips
 
Community IT resources
Community IT resourcesCommunity IT resources
Community IT resources
 
Computanews 07
Computanews 07Computanews 07
Computanews 07
 
Computanews 02
Computanews 02Computanews 02
Computanews 02
 
Computanews #1 (1984)
Computanews #1 (1984)Computanews #1 (1984)
Computanews #1 (1984)
 
Using technology to help deliver Advice Services
Using technology to help deliver Advice ServicesUsing technology to help deliver Advice Services
Using technology to help deliver Advice Services
 
E access13
E access13E access13
E access13
 
Connecting Care @ National Care Forum
Connecting Care @ National Care ForumConnecting Care @ National Care Forum
Connecting Care @ National Care Forum
 
Cloudsourcing2013
Cloudsourcing2013Cloudsourcing2013
Cloudsourcing2013
 
Lasa esolutions campaigning and awareness
Lasa esolutions campaigning and awarenessLasa esolutions campaigning and awareness
Lasa esolutions campaigning and awareness
 
User experience
User experienceUser experience
User experience
 
Better Digital Marketing
Better Digital MarketingBetter Digital Marketing
Better Digital Marketing
 
Lucy Buck
Lucy BuckLucy Buck
Lucy Buck
 
Lasa amplify your multimedia content
Lasa amplify your multimedia contentLasa amplify your multimedia content
Lasa amplify your multimedia content
 

Recently uploaded

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 

Recently uploaded (20)

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 

EU General Data Protection Regulation - Update 2017

  • 1. Data Protection EU General Data Protection Regulation
  • 2. Webinar Presenters Miles Maier @LasaICT Paul Ticher @PaulTicher
  • 3. Supported by • Lasa actively promotes and supports the Way Ahead – Civil Society at the Heart of London. See www.citybridgetrust.org.uk/publications/way-ahead/ • This webinar is supported by the City of London Corporation's charity, City Bridge Trust. www.citybridgetrust.org.uk
  • 4. About Lasa • 30 years in the sector • Technology leadership, publications, events and consultancy www.lasa.org.uk • Welfare Rights www.rightsnet.org.uk
  • 5. Webinar Tips • Ask questions Post questions via chat or raise your virtual hand • Interact Respond to polls during webinar • Focus Avoid multitasking. You may just miss the best part of the presentation • Webinar PowerPoint & Recording PowerPoint and recording links will be shared after the webinar
  • 6. Paul Ticher • Data Protection expert, author and trainer • Specialist in information management and systems • Many charity clients Twitter: @PaulTicher
  • 7. Data Protection: The new EU Regulation June 2017
  • 8. This presentation is intended to help you understand aspects of the EU General Data Protection Regulation and related legislation. It is not intended to provide detailed advice on specific points, and is not necessarily a full statement of the law.
  • 10. Privacy & choice Give us more money! Support our campaign! But of course we told your social worker What Data Protection is about: 2
  • 11.  Right of Subject Access Individual rights, such as:  Right to opt out of direct marketing  Right to compensation for harm What Data Protection is about: 3
  • 12. The current legal framework EC Directive 95/46/EC  Data Protection Act 1998  Similar legislation in most other European countries Privacy & Electronic Communications (EC Directive) Regulations 2003 Non-statutory Guidance and Codes of Practice, including:  Information Commissioner  Institute of Fundraising
  • 13. The new Regulation First draft January 2012 Extensive negotiations between Commission, Parliament and Council over nearly four years Final agreed draft December 2015 Published May 2016 (Reg. 2016/679) Coming into force 25th May 2018 It’s a Regulation, not a Directive
  • 14. Themes “The processing of personal data should be designed to serve [hu]mankind” (Recital 4) More control over online services and large commercial organisations, especially multinationals Emphasis on reducing risk Limited extension of individual rights Data Controller evidence of compliance
  • 15. Main changes include:  Definition of consent tightened up  … but still not always required  Tighter rules on children’s data (under 16), especially online  More transparency requirements  Data minimisation and pseudonymisation  More rights to have data erased  Provision for allocating responsibilities between joint Data Controllers  Data Processors carry more direct responsibilities  No registration: Data Controller has to keep records  Requirement to notify serious breaches  Bigger fines  Additional responsibilities on large organisations and those doing riskier processing
  • 16. Consent Consent is “any freely given, specific, informed and unambiguous indication of his or her wishes by which the data subject, either by a statement or by a clear affirmative action, signifies agreement to personal data relating to them being processed” (Article 4(11)) “Where processing is based on consent, the controller shall be able to demonstrate that consent was given by the data subject … ” (Article 7(1)) “Silence, pre-ticked boxes or inactivity should … not constitute consent.” (Recital 32)
  • 17. When is consent not required? Similar conditions to now, including: Processing is lawful [if it is] “necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. …” (Article 6(f) ) “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” (Recital 47)
  • 18. Where does this leave fundraising? Definitions unclear: when does a communication become marketing? How does the fundraising Code relate to the marketing provisions of the Regulation? New Regulation does not rescind PECR Therefore, consent is likely to remain the only reliable basis for most direct unsolicited fundraising Consent has to involve “clear affirmative action” Therefore, are we looking at opting in only?
  • 19. Tighter rules on children’ data  Children deserve specific protection … as they may be less aware of risks, consequences, safeguards and their rights … . This concerns especially the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of child data when using services offered directly to a child. … (Recital 29)  Where [consent] applies, in relation to the offering of information society services directly to a child, the processing of personal data of a child below the age of 16 years … shall only be lawful if … consent is given … by the holder of parental responsibility over the child.
  • 20. More transparency requirements (Articles 13 & 14) Data Subjects must usually be made aware of:  the identity and the contact details of the controller  the purposes as well as the legal basis of the processing  where relevant the legitimate interests  any recipient(s); any overseas transfers  the storage period or criteria for deletion  right of access to data and rectification or erasure  right to withdraw consent at any time  the right to lodge a complaint to a supervisory authority  whether the provision of personal data is [contractually] required [or] the data subject is obliged to provide the data and … possible consequences of failure to provide [it]
  • 21. Minimisation and pseudonymisation Principle 3 now says data must be: “adequate, relevant and limited to what is necessary … (“data minimisation”)” Data protection by design and by default (Article 25) stresses pseudonymisation as a security measure – especially for things like ‘big data’ analysis Pseudonymisation means that the person is still identifiable but their identity can only be retrieved with the use of additional data which is held separately and securely
  • 22. Rights to erasure, etc. Data Subjects have the rights to require: Rectification of inaccurate data (Article 16) Completion of incomplete data (Article 16) Erasure (“right to be forgotten”), with exceptions, but including removal of links (Article 17) Restriction of processing in certain cases (Article 18) Compensation for “material or non-material damage” (Article 82) Also the right to complain to the supervisory authority
  • 23. Data Controller responsibilities Technical and organisational measures to ensure full compliance (Article 24) Appropriate policies (including Data Protection by design and by default) (Articles 24 & 25) Records of processing – what, who, how, etc. (Article 30) … but no registration (notification) Joint Controllers must transparently “determine their respective responsibilities” – but each can be “liable for the entire damage” caused by a breach (Articles 26 & 82)
  • 24. Data Processor responsibilities (Article 28) Data Controller still has responsibility to select competent Processors More detailed rules about what has to be in the contract Standard contracts should be available Processor may be liable for breaches and other compliance (many obligations refer to the “controller or processor” – including processors based overseas)
  • 25. Notification of serious breaches (Article 33) Must report (preferably within 72 hours) unless the breach is unlikely to result in a risk to individuals Individuals must usually be notified where the breach is likely to result in a high risk to them Processors must notify breaches to Controllers
  • 26. Penalties (Article 79) Breaches subject to two levels of penalty, depending on the breach: €10 million or 2% of total worldwide turnover €20 million or 4% of total worldwide turnover (whichever is higher, in each case)
  • 27. Large organisations & riskier activities Impact assessments before starting innovative processing (Article 35) Data Protection Officer, with specified competence and duties (Articles 37– 39)
  • 28. Selected other changes Overseas transfers – slight loosening of the conditions that legitimise transfers (Article 49) Jurisdiction over multi-national companies operating into Europe (including web-based) (Recital 101) Scope for national variations in a number of places
  • 29. Many thanks Any questions, clarifications, feedback: paul@pauticher.com