SlideShare a Scribd company logo
1 of 40
-GDPR - 5 Months On!
-
CPD Accredited
Fill out survey at the end of the webinar
Q&A Session
Questions Tab or #BPWebinars
Q&A
CPD
On Demand
This session is being recorded
REC
The Presenters…
Jennifer Hussey
Employment Law Advisor & Payroll Specialist
Thesaurus Software / Bright Contracts
Rachel Hynes
Marketing Executive
Thesaurus Software / BrightPay
Webinar Agenda
•Breakdown of the General Data Protection Regulation
•Processing Employee Data under GDPR
•GDPR and Payroll Processing
•How BrightPay and BrightPay Connect Can Help
•How Thesaurus Software Has Prepared
Questions & Answers
-Breakdown of GDPR
GDPR, what is it?
General Data Protection Regulation
• Aims to provide better protection for personal data
• Current data legislation dates back to 1998
Definition of Personal Data
“Any information related on a natural person or ‘Data Subject’, that can
be used to directly or indirectly identify a person.”
✓ A name
✓ A photo
✓ An email address
✓ Bank details
✓ Posts on social networking websites
✓ Medical information
✓ CCTV images
✓ Records of websites visited
✓ A computer IP address
Data Protection Principles
Lawfulness Purpose
Limitation
Data
Minimisation
Accuracy Storage
Limitation
Integrity &
Confidentiality
What’s new in GDPR
• Accountability – demonstrating compliance
• Transparency – providing information pre-processing
• Mandatory data breach reporting (72 hours)
• DPO – Data Protection Officer
• Fines – Administrative Fines, Civil Liability
• Strengthened ‘Consent’ obligations
• New and enhanced Data Subject rights
Integrity &
Confidentiality
Demonstrating Accountability
Article 24.1- “….the controller shall implement appropriate technical
and organizational measures to ensure and to be able to
demonstrate that processing is performed in accordance with
this Regulation”
• Putting together an inventory of the data you currently hold and
process
• Complete Data Protection Impact Assesment (DPIA)
• Appoint a DPO if necessary
Integrity &
Confidentiality
• Details of Data Controller or DPO
• Purpose and legal basis for processing
• Sharing of data – internally / any third
parties
• Storage or transfer of data outside EEA
• Retention periods
• Rights of data subjects
• Consent
• Breach reporting / complaints to supervising
authority
• Any automated decision making processes
• Any Special Categories processed
Transparency
Article 12 - “The controller shall take appropriate measures to provide any
information……..relating to processing to the data subject in a concise, transparent, intelligible
and easily accessible form, using clear and plain language, in particular for any information
addressed specifically to a child”
At the time when personal data is obtained, the data subject must be
provided with information on:
Breach Reporting / Fines
Integrity &
Confidentiality
5. Changes to Consent Rules
1. Consent must be:
- Specific, informed,
unambiguous and freely given
- Must be for a specified purpose
2. Where consent is
obtained as part of a larger
document covering other
things, consent must be
clearly distinguished from
everything else
3. Evidence needs to be
retained as to how the consent
was obtained
Forms, brochures signage,
website screenshots etc.
4. Language must be
accessible and easily
understood
9. Enhanced Rights for Data Subjects
The right to
erasure
The right to
restrict
processing
The right to data
portability
The right to
object
Rights in relation to
automated
decision making
Right to be
informed
The right to
access
The right to
rectification
-Processing Employee Data under GDPR
Who?
• Job Applicants
• Existing Employees
• Leaver
What?
• Name and address
• Payroll information
• Next of kin
• Performance review
• Health or sickness information
HR and Payroll under GDPR
Data Management
Payroll and personal data must be processed lawfully, fairly and
in a transparent manner.
- A lawful reason for processing data must exist
- All data must be kept up-to-date and only be used for purposes that
have been communicated
- Only hold information required for as long as it is needed.
- Data needs to be protected and stored in a secure manner.
The data subject has given consent
Necessary for the performance of contract
Necessary for the compliance with legal obligation
In order to protect vital interests of a person
Necessary for public interest or official authority
For the legitimate interests of data controller or yourself the
employer in this case.
Lawful Processing
• Under GDPR consent must be "freely given, specific, informed and
unambiguous".
• Consent can no longer be relied upon as a lawful reason for
processing employee personal data
Lawful Processing & Consent
Enhanced Rights for Employees
The right to be informed
The right of access
The right to rectification
© NEST Corporation 2015
Recommended Self-Service Option
The GDPR includes a best practice recommendation that,
where possible, organisations should be able to provide remote
access to a secure self-service system which would provide the
individual with direct access to his or her information.
24/7 Online
Access
Payroll
Information
Employee
Documents
Annual Leave
Entitlements
-GDPR & Payroll Processing
Email Payslips
• Yes you can email payslips
• Security measures should be
taken, like password protecting
the payslips
Postal Payslips
• Yes you can post payslips
• Security measures should be
taken, like security sealed
envelopes
Distributing Payslips
• It is recommended (but not mandatory) to offer a secure
self-service portal to securely send and store payslips
Recommended Self-Service Option
• Password protected for each employee
• Provides flexibility and full transparency for employees to retrieve
and update their information at any time
• Employers can login and view payslips, payroll reports and
amounts due to Revenue
• Distribution of payslips and reports are automated and
automatically available to employees
Securely Storing Employee Payroll Data
• Password protect computers that hold
personal data
• Password protect software applications
that hold personal data
• Password protect or encrypt payslips
and other documents that may be
emailed to employees
-Data Processor Agreement
Who Processes Payroll?
In-house Payroll Outsourced Payroll
Data Processor Employer Payroll Bureau
Data
Controller
Employer Employer
Data Subject Employees Employees
A written contract must
be in place!
Employees must be
informed, consent is
not required.
Data Processor Agreement
• Whenever a data controller uses a data processor there needs to be
a written contract in place
• Controllers are liable for their compliance with the GDPR and must
only appoint processors who can provide ‘sufficient guarantees’ that
the requirements of the GDPR will be met
• Data processors will have some direct responsibilities and may be
subject to fines or other sanctions if they don’t comply
What does this contract look like?
• Compliance:
• Draft new Terms of Service / EULAs / Engagement Letters
• Issue an Addendum to any existing contract
• Contract Content
• Mandatory content has expanded
• Template Data Processor Agreement (DPA)
-How BrightPay can help
-
Standard Licence: £99 + VAT
• One employer
• Unlimited employees
• Free phone & email support
• Full functionality
Payroll Software
Bureau Licence: £229 + VAT
• Unlimited employers
• Unlimited employees
• Free phone & email support
• Full functionality
-
How can Bright Contracts help
with GDPR compliance?
-
Standard Licence: £99 + VAT
• One employer
• Unlimited employees
• Free phone & email support
• Online HR templates
Employment Contracts,
Handbooks & Privacy Policies
Bureau Licence: £199 + VAT
• Unlimited employers
• Unlimited employees
• Free phone & email support
• Online HR templates
-
How can BrightPay Connect help
with GDPR compliance?
© NEST Corporation 2015
BrightPay
Connect
•Automated
Cloud Backup
Self-Service
Remote
Access
Password
Protected
Payslip Portal
Secure
Document
Exchange
Accurate
Employee
Records
Right to
Rectification
User
Restrictions
Central
Location for
Documents
-
Single Employer:
£49
+ VAT per tax year
BrightPay Connect
Standard Pro Bundle:
• BrightPay Payroll
• BrightPay Connect
• Bright Contracts
Worth: £247
Bundle Price: £199
-How have we prepared for GDPR?
© NEST Corporation 2015
Key
Changes
•In-Program
Customer
Support
Privacy
Policy
Internal
IT Audits
Secure
Servers
Additional
Consent
Staff Training
& Awareness
Bright
Contracts
Thesaurus &
BrightPay
Connect
-Questions & Answers

More Related Content

What's hot

Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Ulf Mattsson
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)Madhumita Mantri
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceSarah Fox
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 

What's hot (20)

Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 

Similar to GDPR - 5 Months On!

GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantEsendex
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPRMarketo
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Followetouches
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
Managed Service Provider Contracts
Managed Service Provider ContractsManaged Service Provider Contracts
Managed Service Provider ContractsWhitmeyerTuffin
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersSpain-Holiday.com
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 

Similar to GDPR - 5 Months On! (20)

Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Follow
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Managed Service Provider Contracts
Managed Service Provider ContractsManaged Service Provider Contracts
Managed Service Provider Contracts
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 

More from BrightPay Payroll and Auto Enrolment Software

More from BrightPay Payroll and Auto Enrolment Software (20)

Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back
 
BrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it worksBrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it works
 
Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022
 
Webinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQWebinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQ
 
Revenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for OctoberRevenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for October
 
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker RevenueEmployment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
 
EWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to knowEWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to know
 
The End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term ImpactsThe End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term Impacts
 
BrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for AccountantsBrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for Accountants
 
BrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting SoftwareBrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting Software
 
Furlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from JulyFurlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from July
 
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine PolicyLeaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
 
Take the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflowsTake the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflows
 
Payroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule ChangesPayroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule Changes
 
Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...
 
Optimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve ProfitabilityOptimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve Profitability
 
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC QuirksCJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
 
IR35 - Are you Ready?
IR35 - Are you Ready?IR35 - Are you Ready?
IR35 - Are you Ready?
 
The Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-HouseThe Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-House
 
Switch to BrightPay
Switch to BrightPaySwitch to BrightPay
Switch to BrightPay
 

Recently uploaded

Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmSujith Sukumaran
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...OnePlan Solutions
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio, Inc.
 
英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作qr0udbr0
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantAxelRicardoTrocheRiq
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsAhmed Mohamed
 
What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....kzayra69
 
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesFolding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesPhilip Schwarz
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based projectAnoyGreter
 
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...stazi3110
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfAlina Yurenko
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)jennyeacort
 
React Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaReact Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaHanief Utama
 
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024StefanoLambiase
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanyChristoph Pohl
 
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...OnePlan Solutions
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxTier1 app
 
The Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfThe Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfPower Karaoke
 
Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Hr365.us smith
 
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataAdobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataBradBedford3
 

Recently uploaded (20)

Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalm
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
 
英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service Consultant
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
 
What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....
 
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesFolding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a series
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based project
 
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
 
React Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaReact Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief Utama
 
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
 
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
 
The Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfThe Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdf
 
Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)
 
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataAdobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
 

GDPR - 5 Months On!

  • 1. -GDPR - 5 Months On!
  • 2. - CPD Accredited Fill out survey at the end of the webinar Q&A Session Questions Tab or #BPWebinars Q&A CPD On Demand This session is being recorded REC
  • 3. The Presenters… Jennifer Hussey Employment Law Advisor & Payroll Specialist Thesaurus Software / Bright Contracts Rachel Hynes Marketing Executive Thesaurus Software / BrightPay
  • 4. Webinar Agenda •Breakdown of the General Data Protection Regulation •Processing Employee Data under GDPR •GDPR and Payroll Processing •How BrightPay and BrightPay Connect Can Help •How Thesaurus Software Has Prepared Questions & Answers
  • 6. GDPR, what is it? General Data Protection Regulation • Aims to provide better protection for personal data • Current data legislation dates back to 1998
  • 7. Definition of Personal Data “Any information related on a natural person or ‘Data Subject’, that can be used to directly or indirectly identify a person.” ✓ A name ✓ A photo ✓ An email address ✓ Bank details ✓ Posts on social networking websites ✓ Medical information ✓ CCTV images ✓ Records of websites visited ✓ A computer IP address
  • 8. Data Protection Principles Lawfulness Purpose Limitation Data Minimisation Accuracy Storage Limitation Integrity & Confidentiality
  • 9. What’s new in GDPR • Accountability – demonstrating compliance • Transparency – providing information pre-processing • Mandatory data breach reporting (72 hours) • DPO – Data Protection Officer • Fines – Administrative Fines, Civil Liability • Strengthened ‘Consent’ obligations • New and enhanced Data Subject rights Integrity & Confidentiality
  • 10. Demonstrating Accountability Article 24.1- “….the controller shall implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation” • Putting together an inventory of the data you currently hold and process • Complete Data Protection Impact Assesment (DPIA) • Appoint a DPO if necessary Integrity & Confidentiality
  • 11. • Details of Data Controller or DPO • Purpose and legal basis for processing • Sharing of data – internally / any third parties • Storage or transfer of data outside EEA • Retention periods • Rights of data subjects • Consent • Breach reporting / complaints to supervising authority • Any automated decision making processes • Any Special Categories processed Transparency Article 12 - “The controller shall take appropriate measures to provide any information……..relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child” At the time when personal data is obtained, the data subject must be provided with information on:
  • 12. Breach Reporting / Fines Integrity & Confidentiality
  • 13. 5. Changes to Consent Rules 1. Consent must be: - Specific, informed, unambiguous and freely given - Must be for a specified purpose 2. Where consent is obtained as part of a larger document covering other things, consent must be clearly distinguished from everything else 3. Evidence needs to be retained as to how the consent was obtained Forms, brochures signage, website screenshots etc. 4. Language must be accessible and easily understood
  • 14. 9. Enhanced Rights for Data Subjects The right to erasure The right to restrict processing The right to data portability The right to object Rights in relation to automated decision making Right to be informed The right to access The right to rectification
  • 16. Who? • Job Applicants • Existing Employees • Leaver What? • Name and address • Payroll information • Next of kin • Performance review • Health or sickness information HR and Payroll under GDPR
  • 17. Data Management Payroll and personal data must be processed lawfully, fairly and in a transparent manner. - A lawful reason for processing data must exist - All data must be kept up-to-date and only be used for purposes that have been communicated - Only hold information required for as long as it is needed. - Data needs to be protected and stored in a secure manner.
  • 18. The data subject has given consent Necessary for the performance of contract Necessary for the compliance with legal obligation In order to protect vital interests of a person Necessary for public interest or official authority For the legitimate interests of data controller or yourself the employer in this case. Lawful Processing
  • 19. • Under GDPR consent must be "freely given, specific, informed and unambiguous". • Consent can no longer be relied upon as a lawful reason for processing employee personal data Lawful Processing & Consent
  • 20. Enhanced Rights for Employees The right to be informed The right of access The right to rectification
  • 21. © NEST Corporation 2015 Recommended Self-Service Option The GDPR includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information. 24/7 Online Access Payroll Information Employee Documents Annual Leave Entitlements
  • 22. -GDPR & Payroll Processing
  • 23. Email Payslips • Yes you can email payslips • Security measures should be taken, like password protecting the payslips Postal Payslips • Yes you can post payslips • Security measures should be taken, like security sealed envelopes Distributing Payslips • It is recommended (but not mandatory) to offer a secure self-service portal to securely send and store payslips
  • 24. Recommended Self-Service Option • Password protected for each employee • Provides flexibility and full transparency for employees to retrieve and update their information at any time • Employers can login and view payslips, payroll reports and amounts due to Revenue • Distribution of payslips and reports are automated and automatically available to employees
  • 25. Securely Storing Employee Payroll Data • Password protect computers that hold personal data • Password protect software applications that hold personal data • Password protect or encrypt payslips and other documents that may be emailed to employees
  • 27. Who Processes Payroll? In-house Payroll Outsourced Payroll Data Processor Employer Payroll Bureau Data Controller Employer Employer Data Subject Employees Employees A written contract must be in place! Employees must be informed, consent is not required.
  • 28. Data Processor Agreement • Whenever a data controller uses a data processor there needs to be a written contract in place • Controllers are liable for their compliance with the GDPR and must only appoint processors who can provide ‘sufficient guarantees’ that the requirements of the GDPR will be met • Data processors will have some direct responsibilities and may be subject to fines or other sanctions if they don’t comply
  • 29. What does this contract look like? • Compliance: • Draft new Terms of Service / EULAs / Engagement Letters • Issue an Addendum to any existing contract • Contract Content • Mandatory content has expanded • Template Data Processor Agreement (DPA)
  • 31.
  • 32. - Standard Licence: £99 + VAT • One employer • Unlimited employees • Free phone & email support • Full functionality Payroll Software Bureau Licence: £229 + VAT • Unlimited employers • Unlimited employees • Free phone & email support • Full functionality
  • 33. - How can Bright Contracts help with GDPR compliance?
  • 34. - Standard Licence: £99 + VAT • One employer • Unlimited employees • Free phone & email support • Online HR templates Employment Contracts, Handbooks & Privacy Policies Bureau Licence: £199 + VAT • Unlimited employers • Unlimited employees • Free phone & email support • Online HR templates
  • 35. - How can BrightPay Connect help with GDPR compliance?
  • 36. © NEST Corporation 2015 BrightPay Connect •Automated Cloud Backup Self-Service Remote Access Password Protected Payslip Portal Secure Document Exchange Accurate Employee Records Right to Rectification User Restrictions Central Location for Documents
  • 37. - Single Employer: £49 + VAT per tax year BrightPay Connect Standard Pro Bundle: • BrightPay Payroll • BrightPay Connect • Bright Contracts Worth: £247 Bundle Price: £199
  • 38. -How have we prepared for GDPR?
  • 39. © NEST Corporation 2015 Key Changes •In-Program Customer Support Privacy Policy Internal IT Audits Secure Servers Additional Consent Staff Training & Awareness Bright Contracts Thesaurus & BrightPay Connect