SlideShare a Scribd company logo
1 of 16
Download to read offline
IRIS Customer Conference
GDPR – Game Changing Legislation
Will Richmond-Coggan, Pitmans Law
27 March 2018
GDPR – Game Changing Legislation
We’re lawyers, so we always start with a disclaimer.
The guidance that follows is in the nature of general information about
the subject matter concerned – it is invariably the case that detailed
legal advice requires a lot of fact-sensitive information that we will not
have while discussing points today. As such, no reliance should be
placed on the guidance given in this talk without first taking such
detailed advice.
Nevertheless, feel free to ask questions, even those embarrassing
ones on behalf of your “friend” who couldn’t make it – it will help us to
make sure that the content is as relevant as possible!
General overview – this talk
I am going to cover as much of the following as
possible!
• An introduction to key concepts / main changes
• Outlining a roadmap to GDPR readiness
• The data subject’s rights
Core Concept – Personal data
• Now includes identification numbers, location, online identifiers
and factors specific to the individual's physical, physiological,
genetic, mental, economic, cultural or social identity.
• Still includes information about activities when linked to an
identifier
• Sensitive data now includes genetic and biometric data
• Criminal records now occupy a separate category and are
treated distinctly
Core Concept – Lawful processing
• Contract – necessary for the formation or performance of
a contract between the controller and subject
• Obligation – necessary for performance of a legal
obligation, or discharge of a statutory function
• Vital interests – to protect the vital interests of the data
subject or someone else
• Legitimate interests – of the data processor and
controller, but only where other rights aren’t affected
Lawful processing (cont.) – Consent
• Consent must be freely given, specific, informed and
unambiguous by “some form of clear affirmative action”
• It cannot be signified by inaction, silence or be a pre-
condition to other actions
• It must be as easy for a subject to withdraw consent as
to give it – form and substance
• Remember that processing under consent gives the data
subject wider rights than other lawfulness gateways
General overview – the legislation
Key game-changers brought in by GDPR:
• Direct accountability of data processors
• Data controller/processor distinction
• Limited scope to re-allocate risk contractually
• Territorial extent
• The “Global” Data Protection Regulation?
• Third countries – nomination of a data regulator
• And (of course) Brexit!
General overview – the legislation
Key game-changers brought in by GDPR:
• Breach notification and record keeping
• “Accountability principle” – document intensive
• Mandatory notification – data regulator
• Mandatory notification – data subjects
• Consequences are broader
• Wider fines – the greater of EUR 10m or 2% of global group
turnover for “minor” issues, it’s 4% / EUR 20m for major ones!
• ICO audits; data subject compensation; reputation
Get ready with… D… P… R…
Roadmap - Data discovery
Headline points:
• What is “personal data”
• Identification of an individual or information about activities
• Where should the data be located…
• Think about local drives, servers, cloud services, portable
• …where else is it actually…
• Think about personal devices, webmail, pen drives, offshore
• …and data flows
• Internal/external, compliant processing chains, cross-border
Roadmap – Policies for compliance
Headline points:
• Compliance with standards
• e.g. Cyber-Essentials, ISO 27001, BS 10012:2017
• GDPR-specific procedures
• Consent management, privacy protection systems, notifications
• Policy and process review
• System capabilities, gap analysis, develop and implement
• Training and awareness at all levels
• “Baked in” compliance – privacy by design and by default
Roadmap – Record keeping
Headline points:
• Accountability principle
• Have to be able to “show” as well as “do”
• Records are essential
• Of data held, decisions taken, policies and procedures
• ICO ability to audit
• Including onsite inspection and requiring delivery of information
• As part of a supply chain
• Accountability up and down the chain
Processes – Risk assessment
• Identify each of the processes of your business which
engage personal data
• Do you process as controller or processor – what is the
lawfulness gateway?
• Is the processing proportionate to the objectives?
• What measures of safeguarding are appropriate –
anonymisation/pseudonymisation; encryption;
permissions; policies
Processes – Breach notification
• Now mandatory for breaches: “leading to the destruction,
loss, alteration, unauthorised disclosure of, or access to,
personal data”
• Notification must be made within 72 hours of detection
• Data subjects must also be notified “without undue
delay” where the breach poses a high risk to their rights
• Think about the steps that will need to be taken in those
72 hours – processes need to be in place already
The Data Subject’s Journey
Inform
Access Rectify
Restrict Transfer
Object Erase
With Pitmans Law you can be assured of the quality of advice and service
you demand from a city law firm – but with a distinction. The courage to stand apart, to
think and act personably, with an uncompromising focus on achieving outstanding client
outcomes. We say what we mean, matching our behaviours to our words.
Established for over 150 years, Pitmans Law is headquartered in Reading with offices in
London and Southampton. The lower overheads of a regional office ensure we can
provide city quality legal advice at a competitive price to deliver exceptional value for our
corporate and private clients locally, nationally and internationally.
Pitmans provides legal advice to address our clients’ needs across a wide range
of industry sectors and specialisms including particularly strong specialist teams in
pensions advisory, real estate, dispute resolution as well as corporate and commercial
law. Our clients draw confidence from the top tier recognition Pitmans achieves in the
industry benchmarking directories, Legal 500 and Chambers UK.
Reading, London, Southampton
Pitmans Law is the founding UK member firm of the global legal network, Interact Law.
Contact us
T +44 (0)345 222 9222
E law@pitmans.com

More Related Content

What's hot

Optimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digitalOptimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digitalChristiana Kozakou
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)Bright
 
Csa privacy by design & gdpr austin chambers 11-4-17
Csa   privacy by design & gdpr austin chambers 11-4-17Csa   privacy by design & gdpr austin chambers 11-4-17
Csa privacy by design & gdpr austin chambers 11-4-17Trish McGinity, CCSK
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceCILIPScotland
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesDimitri Sirota
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketingSpotler
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...Ardoq
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality Susan Moran
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for developmentTomppa Järvinen
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashedChris Gilmour
 
Human resources: protecting confidentiality
Human resources: protecting confidentiality Human resources: protecting confidentiality
Human resources: protecting confidentiality KelbySchwender
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers networkBart Van Den Brande
 

What's hot (20)

Optimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digitalOptimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digital
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)
 
Csa privacy by design & gdpr austin chambers 11-4-17
Csa   privacy by design & gdpr austin chambers 11-4-17Csa   privacy by design & gdpr austin chambers 11-4-17
Csa privacy by design & gdpr austin chambers 11-4-17
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library Service
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
 
Data Privacy & Security
Data Privacy & SecurityData Privacy & Security
Data Privacy & Security
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
S719a
S719aS719a
S719a
 
Human resources: protecting confidentiality
Human resources: protecting confidentiality Human resources: protecting confidentiality
Human resources: protecting confidentiality
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers network
 

Similar to Game changing legislation

#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance Dovetail Software
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Global Data Privacy Regulation
Global Data Privacy RegulationGlobal Data Privacy Regulation
Global Data Privacy RegulationJatin Kochhar
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?Jatin Kochhar
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 

Similar to Game changing legislation (20)

#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Global Data Privacy Regulation
Global Data Privacy RegulationGlobal Data Privacy Regulation
Global Data Privacy Regulation
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?
 
13687562.ppt
13687562.ppt13687562.ppt
13687562.ppt
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPRforum London
GDPRforum LondonGDPRforum London
GDPRforum London
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 

More from IRIS

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS
 
HMRC
HMRCHMRC
HMRCIRIS
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdprIRIS
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burdenIRIS
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedIRIS
 
Happy clients happy compliance
Happy clients happy complianceHappy clients happy compliance
Happy clients happy complianceIRIS
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anywayIRIS
 

More from IRIS (10)

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital Economy
 
HMRC
HMRCHMRC
HMRC
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdpr
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint hearted
 
Happy clients happy compliance
Happy clients happy complianceHappy clients happy compliance
Happy clients happy compliance
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
 

Recently uploaded

High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur EscortsHigh Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escortsranjana rawat
 
letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...
letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...
letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...Henry Tapper
 
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure serviceCall US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure servicePooja Nehwal
 
Stock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdfStock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdfMichael Silva
 
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...shivangimorya083
 
Lundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfLundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfAdnet Communications
 
VIP Call Girls Thane Sia 8617697112 Independent Escort Service Thane
VIP Call Girls Thane Sia 8617697112 Independent Escort Service ThaneVIP Call Girls Thane Sia 8617697112 Independent Escort Service Thane
VIP Call Girls Thane Sia 8617697112 Independent Escort Service ThaneCall girls in Ahmedabad High profile
 
05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx
05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx
05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptxFinTech Belgium
 
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...
Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...
Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...Pooja Nehwal
 
03_Emmanuel Ndiaye_Degroof Petercam.pptx
03_Emmanuel Ndiaye_Degroof Petercam.pptx03_Emmanuel Ndiaye_Degroof Petercam.pptx
03_Emmanuel Ndiaye_Degroof Petercam.pptxFinTech Belgium
 
How Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingHow Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingAggregage
 
00_Main ppt_MeetupDORA&CyberSecurity.pptx
00_Main ppt_MeetupDORA&CyberSecurity.pptx00_Main ppt_MeetupDORA&CyberSecurity.pptx
00_Main ppt_MeetupDORA&CyberSecurity.pptxFinTech Belgium
 
Q3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast SlidesQ3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast SlidesMarketing847413
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...ssifa0344
 
Quarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingQuarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingMaristelaRamos12
 
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex
 
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...Call Girls in Nagpur High Profile
 

Recently uploaded (20)

High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur EscortsHigh Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
 
letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...
letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...
letter-from-the-chair-to-the-fca-relating-to-british-steel-pensions-scheme-15...
 
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure serviceCall US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
 
Stock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdfStock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdf
 
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
 
Lundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfLundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdf
 
VIP Call Girls Thane Sia 8617697112 Independent Escort Service Thane
VIP Call Girls Thane Sia 8617697112 Independent Escort Service ThaneVIP Call Girls Thane Sia 8617697112 Independent Escort Service Thane
VIP Call Girls Thane Sia 8617697112 Independent Escort Service Thane
 
05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx
05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx
05_Annelore Lenoir_Docbyte_MeetupDora&Cybersecurity.pptx
 
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...
Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...
Dharavi Russian callg Girls, { 09892124323 } || Call Girl In Mumbai ...
 
03_Emmanuel Ndiaye_Degroof Petercam.pptx
03_Emmanuel Ndiaye_Degroof Petercam.pptx03_Emmanuel Ndiaye_Degroof Petercam.pptx
03_Emmanuel Ndiaye_Degroof Petercam.pptx
 
How Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingHow Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of Reporting
 
00_Main ppt_MeetupDORA&CyberSecurity.pptx
00_Main ppt_MeetupDORA&CyberSecurity.pptx00_Main ppt_MeetupDORA&CyberSecurity.pptx
00_Main ppt_MeetupDORA&CyberSecurity.pptx
 
Q3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast SlidesQ3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast Slides
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
 
Veritas Interim Report 1 January–31 March 2024
Veritas Interim Report 1 January–31 March 2024Veritas Interim Report 1 January–31 March 2024
Veritas Interim Report 1 January–31 March 2024
 
Quarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingQuarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of Marketing
 
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024
 
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
 

Game changing legislation

  • 1. IRIS Customer Conference GDPR – Game Changing Legislation Will Richmond-Coggan, Pitmans Law 27 March 2018
  • 2. GDPR – Game Changing Legislation We’re lawyers, so we always start with a disclaimer. The guidance that follows is in the nature of general information about the subject matter concerned – it is invariably the case that detailed legal advice requires a lot of fact-sensitive information that we will not have while discussing points today. As such, no reliance should be placed on the guidance given in this talk without first taking such detailed advice. Nevertheless, feel free to ask questions, even those embarrassing ones on behalf of your “friend” who couldn’t make it – it will help us to make sure that the content is as relevant as possible!
  • 3. General overview – this talk I am going to cover as much of the following as possible! • An introduction to key concepts / main changes • Outlining a roadmap to GDPR readiness • The data subject’s rights
  • 4. Core Concept – Personal data • Now includes identification numbers, location, online identifiers and factors specific to the individual's physical, physiological, genetic, mental, economic, cultural or social identity. • Still includes information about activities when linked to an identifier • Sensitive data now includes genetic and biometric data • Criminal records now occupy a separate category and are treated distinctly
  • 5. Core Concept – Lawful processing • Contract – necessary for the formation or performance of a contract between the controller and subject • Obligation – necessary for performance of a legal obligation, or discharge of a statutory function • Vital interests – to protect the vital interests of the data subject or someone else • Legitimate interests – of the data processor and controller, but only where other rights aren’t affected
  • 6. Lawful processing (cont.) – Consent • Consent must be freely given, specific, informed and unambiguous by “some form of clear affirmative action” • It cannot be signified by inaction, silence or be a pre- condition to other actions • It must be as easy for a subject to withdraw consent as to give it – form and substance • Remember that processing under consent gives the data subject wider rights than other lawfulness gateways
  • 7. General overview – the legislation Key game-changers brought in by GDPR: • Direct accountability of data processors • Data controller/processor distinction • Limited scope to re-allocate risk contractually • Territorial extent • The “Global” Data Protection Regulation? • Third countries – nomination of a data regulator • And (of course) Brexit!
  • 8. General overview – the legislation Key game-changers brought in by GDPR: • Breach notification and record keeping • “Accountability principle” – document intensive • Mandatory notification – data regulator • Mandatory notification – data subjects • Consequences are broader • Wider fines – the greater of EUR 10m or 2% of global group turnover for “minor” issues, it’s 4% / EUR 20m for major ones! • ICO audits; data subject compensation; reputation
  • 9. Get ready with… D… P… R…
  • 10. Roadmap - Data discovery Headline points: • What is “personal data” • Identification of an individual or information about activities • Where should the data be located… • Think about local drives, servers, cloud services, portable • …where else is it actually… • Think about personal devices, webmail, pen drives, offshore • …and data flows • Internal/external, compliant processing chains, cross-border
  • 11. Roadmap – Policies for compliance Headline points: • Compliance with standards • e.g. Cyber-Essentials, ISO 27001, BS 10012:2017 • GDPR-specific procedures • Consent management, privacy protection systems, notifications • Policy and process review • System capabilities, gap analysis, develop and implement • Training and awareness at all levels • “Baked in” compliance – privacy by design and by default
  • 12. Roadmap – Record keeping Headline points: • Accountability principle • Have to be able to “show” as well as “do” • Records are essential • Of data held, decisions taken, policies and procedures • ICO ability to audit • Including onsite inspection and requiring delivery of information • As part of a supply chain • Accountability up and down the chain
  • 13. Processes – Risk assessment • Identify each of the processes of your business which engage personal data • Do you process as controller or processor – what is the lawfulness gateway? • Is the processing proportionate to the objectives? • What measures of safeguarding are appropriate – anonymisation/pseudonymisation; encryption; permissions; policies
  • 14. Processes – Breach notification • Now mandatory for breaches: “leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data” • Notification must be made within 72 hours of detection • Data subjects must also be notified “without undue delay” where the breach poses a high risk to their rights • Think about the steps that will need to be taken in those 72 hours – processes need to be in place already
  • 15. The Data Subject’s Journey Inform Access Rectify Restrict Transfer Object Erase
  • 16. With Pitmans Law you can be assured of the quality of advice and service you demand from a city law firm – but with a distinction. The courage to stand apart, to think and act personably, with an uncompromising focus on achieving outstanding client outcomes. We say what we mean, matching our behaviours to our words. Established for over 150 years, Pitmans Law is headquartered in Reading with offices in London and Southampton. The lower overheads of a regional office ensure we can provide city quality legal advice at a competitive price to deliver exceptional value for our corporate and private clients locally, nationally and internationally. Pitmans provides legal advice to address our clients’ needs across a wide range of industry sectors and specialisms including particularly strong specialist teams in pensions advisory, real estate, dispute resolution as well as corporate and commercial law. Our clients draw confidence from the top tier recognition Pitmans achieves in the industry benchmarking directories, Legal 500 and Chambers UK. Reading, London, Southampton Pitmans Law is the founding UK member firm of the global legal network, Interact Law. Contact us T +44 (0)345 222 9222 E law@pitmans.com