SlideShare a Scribd company logo
EU GENERAL DATA PROTECTION REGULATION
GDPR
BASICS FOR COMMUNITY ARCHIVES
J O N E L L I O T T ( AR A)
J AC K L AT I M E R ( C AH G )
Starting Point – Differentiate between personal
data in archives and data used operationally
‘Archiving Purposes in the Public Interest’
- Personal data in archives is largely exempted from GDPR so
long it doesn’t fail the ‘substantial damage and distress’ test.
- Virtually all community archives will be able to use this
derogation.
- So DO NOT AMEND, DELETE, HAND OVER, DESTROY OR
REDACT ORIGINAL ARCHIVAL MATERIAL unless a court tells
you to.
The exemption does not apply to personal data
you ‘process’ in running your organisation
For example:
- staff and membership lists, with phone numbers, email addresses, etc.
- data subjects in partner organisations, suppliers, clients, etc.
- photos, bank details, health, family or other identifying information
- Signing-in books
- IT’S NOT YOUR DATA
Other common questions:
- GDPR doesn’t cover dead people or those you can assume reasonably are
dead (eg, photo of a woman in 1970 who looks at least 60 years old).
- If people want access to personal data in your archive, offer them a copy.
- if something causes distress (right to erase), close it to public access.
- If something is ‘inaccurate’ (right to correction), put a note in the file.
- If documents contain ‘sensitive personal data’, close them to public access.
- A form that researchers sign accepting their data protection obligations.
- Unsubscribe option on newsletters, etc.
GDPR – First Priority – Avoid
Breaches
Tackle The Most Common Problems
- Operational failure: eg, mass copying of emails and not ‘bcc-ing’
emails, attaching documents containing personal data, sending a data
subject’s personal data to someone else by mistake, not having basic anti-
hacking software, sending and receiving ‘work’ personal data from home
emails and home servers, etc.
- Bad records management practice: not password-protecting
documents containing personal data; mixing sensitive data files in with
regular files, not having clear record of what you own and what you don’t.
- Weakest links: giving access to personal data to people, colleagues,
volunteers, etc. who don’t need it: the weakest link in the chain. Limit access.
Second Priority – Get organised
• Record, record, record…
• Do you have a website? If so, what and where are
your Privacy Policy, Take-down Policy and Contact
Details?
• Have clear, written retention policies for data
you hold: can be simple, eg how long you are
keeping the five main uses for personal data you hold
and when/what you destroy or keep. And why.
• Implement your policies….
Third Priority
• Tell your trustees (if you have them) what you
are doing. Get their approval, eg by
- Defining the simple legal basis you are using to process
personal data
- Doing and recording a simple information audit: what
personal data you hold, why, in what form, where you send it,
how long kept, and physical location?
- Showing how you record consent, ie ‘explicit’; ‘positive
indication of agreement.’ Cannot infer from silence/tick-box.
Subject Access Requests (SARs)
• You are unlikely to be able to charge for SARs
• Response timescale: down from 40 days to 1 month
• New option: can refuse a request if clearly excessive
(BUT: you must have credible policies/processes in
place for making such judgements and RECORD
individual decisions)
• New obligation: provide info to data subjects, eg data
retention periods and the right to ‘correction’.
• Think through operational impact.
Reporting Breaches
New, universal duty of breach notification
- obligatory to have processes to detect, report and investigate
breaches
- Not all breaches must be reported to ICO: the ‘damage’ test
- But you only have 72 hours for those that must… (won’t
include community archives unless, eg a serious breach of
sensitive personal data)
- Fines: €20 million or 4% of global turnover. BUT ICO have said
that only major breaches by major companies will fall into this
bracket
International Transfers
• Unwitting?
- Do you use mailchimp, Facebook, Eventbrite or other sites for
your activities?
- Have you read their privacy statements, eg will data you use
be exported to US servers and thereby out of GDPR
jurisdiction and protection?
- Very important that you cover this
Next steps?
• We are working with partners on a Code of Practice: Hope it
will be available end 2018. Aim to cover community archives
• Need to also consider cross-border implications in Ireland
• Training/briefing: ARA will continue to offer briefing sessions
• ARA will keep advocating improvements/interpretations with
governments and regulators.
• Wider impact: new ARA Code of Ethics (2018)
• A hunch: stand by for court cases after 2018…
A working example:
what we’ve done about
GDPR
1. We have carried out an audit of the personal data we hold.
We made a list of all the ways in which we collect or store personal data
2. We have updated and documented our personal data policy.
We asked: Do we need each type of data on our list? How long should we keep it?
3. We have deleted unnecessary personal data.
For example: we deleted old booking forms and copies of newsletter subscriptions
4. We have reviewed each process by which we collect personal data to be
sure we are obtaining the right permissions.
For example: we added a checkbox to all website forms, to ensure explicit consent
5. We have provided a method for people to find out what personal data we
hold about them or request to have it deleted.
Our privacy page now has a link to a form for requesting/deleting personal data
6. We have updated our privacy policy and published it on the website.
ANY QUESTIONS?
Introducing Community
Archives
1. Do we need to get in touch with all our members/website
contributors to get their consent to keep their contact details
on record?
2. What do we do about the details of dead or living people that
we hold in our archive? For example, in minutes of parish
meetings?
3. If somebody sends us a research request, does that person
need to give consent to us using their personal details in order
to reply?
Three common queries from community archives
Further Reading
• ARA advocacy papers to date (hand-outs)
• European Data Protection Supervisor’s blog: dry, but…
https://secure.edps.europa.eu/EDPSWEB/edps/lang/de/EDPS/P
ublications/Blog_1
• The Guardian’s ‘51 Useful Data Protection Resources’:
https://digitalguardian.com/blog/51-useful-data-protection-
resources-blogs-videos-guides-infographics-tools-more
• ICO (UK) blog and ICO guidance notes:
https://ico.org.uk/about-the-ico/news-and-events/news-and-
blogs/?facet_type=Blog&facet_date=&date_from=&date_to=

More Related Content

Similar to GDPR - Basics for Community Archives

How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
Louise Owens
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
Stewart Norriss
 
Introduction to Data Protection and Information Security
Introduction to Data Protection and Information SecurityIntroduction to Data Protection and Information Security
Introduction to Data Protection and Information Security
Jisc Scotland
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
Deeson
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
Human Capital Department
 
Ethics in Data Management.pptx
Ethics in Data Management.pptxEthics in Data Management.pptx
Ethics in Data Management.pptx
Ravindra Babu
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
Andreas Batsis
 
B2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPRB2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPR
NCVO - National Council for Voluntary Organisations
 
Social media in the workplace
Social media in the workplace Social media in the workplace
Social media in the workplace
AlphaStaff
 
pp_101_notes_eng.pdf
pp_101_notes_eng.pdfpp_101_notes_eng.pdf
pp_101_notes_eng.pdf
Abel Mutize
 
e-Marketing Policy-Building Workshop
e-Marketing Policy-Building Workshope-Marketing Policy-Building Workshop
e-Marketing Policy-Building Workshop
Matt Vernhout
 
Social media & data protection policy v1.0 141112
Social media & data protection policy v1.0 141112 Social media & data protection policy v1.0 141112
Social media & data protection policy v1.0 141112
Dave Shannon
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
Jim Kaplan CIA CFE
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
Guy Griffiths
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013
Rachel Aldighieri
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
CFG
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
Post Media
 

Similar to GDPR - Basics for Community Archives (20)

How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
Introduction to Data Protection and Information Security
Introduction to Data Protection and Information SecurityIntroduction to Data Protection and Information Security
Introduction to Data Protection and Information Security
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
Ethics in Data Management.pptx
Ethics in Data Management.pptxEthics in Data Management.pptx
Ethics in Data Management.pptx
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 
B2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPRB2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPR
 
Social media in the workplace
Social media in the workplace Social media in the workplace
Social media in the workplace
 
pp_101_notes_eng.pdf
pp_101_notes_eng.pdfpp_101_notes_eng.pdf
pp_101_notes_eng.pdf
 
e-Marketing Policy-Building Workshop
e-Marketing Policy-Building Workshope-Marketing Policy-Building Workshop
e-Marketing Policy-Building Workshop
 
Social media & data protection policy v1.0 141112
Social media & data protection policy v1.0 141112 Social media & data protection policy v1.0 141112
Social media & data protection policy v1.0 141112
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 

Recently uploaded

Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Jamesadhikaram land matter consultancy 9447464502
 
Item #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code AmendmentItem #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code Amendment
ahcitycouncil
 
2024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 382024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 38
JSchaus & Associates
 
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC CharlotteA Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
University of North Carolina at Charlotte
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Christina Parmionova
 
加急办理华威大学毕业证硕士文凭证书原版一模一样
加急办理华威大学毕业证硕士文凭证书原版一模一样加急办理华威大学毕业证硕士文凭证书原版一模一样
加急办理华威大学毕业证硕士文凭证书原版一模一样
uu1psyf6
 
Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024
Texas Alliance of Groundwater Districts
 
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
3woawyyl
 
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
Congressional Budget Office
 
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
yemqpj
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
Roger Valdez
 
IEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- StatisticsIEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- Statistics
Energy for One World
 
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
ssuser05e8f3
 
Invitation Letter for an alumni association
Invitation Letter for an alumni associationInvitation Letter for an alumni association
Invitation Letter for an alumni association
elmerdalida001
 
CFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon CanadaCFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon Canada
pmenzies
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
SERUDS INDIA
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
OECDregions
 
Researching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssssResearching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssss
DanielOliver74
 
About Potato, The scientific name of the plant is Solanum tuberosum (L).
About Potato, The scientific name of the plant is Solanum tuberosum (L).About Potato, The scientific name of the plant is Solanum tuberosum (L).
About Potato, The scientific name of the plant is Solanum tuberosum (L).
Christina Parmionova
 
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
ii2sh2v
 

Recently uploaded (20)

Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
 
Item #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code AmendmentItem #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code Amendment
 
2024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 382024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 38
 
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC CharlotteA Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
 
加急办理华威大学毕业证硕士文凭证书原版一模一样
加急办理华威大学毕业证硕士文凭证书原版一模一样加急办理华威大学毕业证硕士文凭证书原版一模一样
加急办理华威大学毕业证硕士文凭证书原版一模一样
 
Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024
 
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
 
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
 
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
 
IEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- StatisticsIEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- Statistics
 
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
 
Invitation Letter for an alumni association
Invitation Letter for an alumni associationInvitation Letter for an alumni association
Invitation Letter for an alumni association
 
CFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon CanadaCFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon Canada
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
 
Researching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssssResearching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssss
 
About Potato, The scientific name of the plant is Solanum tuberosum (L).
About Potato, The scientific name of the plant is Solanum tuberosum (L).About Potato, The scientific name of the plant is Solanum tuberosum (L).
About Potato, The scientific name of the plant is Solanum tuberosum (L).
 
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
 

GDPR - Basics for Community Archives

  • 1. EU GENERAL DATA PROTECTION REGULATION GDPR BASICS FOR COMMUNITY ARCHIVES J O N E L L I O T T ( AR A) J AC K L AT I M E R ( C AH G )
  • 2. Starting Point – Differentiate between personal data in archives and data used operationally ‘Archiving Purposes in the Public Interest’ - Personal data in archives is largely exempted from GDPR so long it doesn’t fail the ‘substantial damage and distress’ test. - Virtually all community archives will be able to use this derogation. - So DO NOT AMEND, DELETE, HAND OVER, DESTROY OR REDACT ORIGINAL ARCHIVAL MATERIAL unless a court tells you to.
  • 3. The exemption does not apply to personal data you ‘process’ in running your organisation For example: - staff and membership lists, with phone numbers, email addresses, etc. - data subjects in partner organisations, suppliers, clients, etc. - photos, bank details, health, family or other identifying information - Signing-in books - IT’S NOT YOUR DATA Other common questions: - GDPR doesn’t cover dead people or those you can assume reasonably are dead (eg, photo of a woman in 1970 who looks at least 60 years old). - If people want access to personal data in your archive, offer them a copy. - if something causes distress (right to erase), close it to public access. - If something is ‘inaccurate’ (right to correction), put a note in the file. - If documents contain ‘sensitive personal data’, close them to public access. - A form that researchers sign accepting their data protection obligations. - Unsubscribe option on newsletters, etc.
  • 4. GDPR – First Priority – Avoid Breaches Tackle The Most Common Problems - Operational failure: eg, mass copying of emails and not ‘bcc-ing’ emails, attaching documents containing personal data, sending a data subject’s personal data to someone else by mistake, not having basic anti- hacking software, sending and receiving ‘work’ personal data from home emails and home servers, etc. - Bad records management practice: not password-protecting documents containing personal data; mixing sensitive data files in with regular files, not having clear record of what you own and what you don’t. - Weakest links: giving access to personal data to people, colleagues, volunteers, etc. who don’t need it: the weakest link in the chain. Limit access.
  • 5. Second Priority – Get organised • Record, record, record… • Do you have a website? If so, what and where are your Privacy Policy, Take-down Policy and Contact Details? • Have clear, written retention policies for data you hold: can be simple, eg how long you are keeping the five main uses for personal data you hold and when/what you destroy or keep. And why. • Implement your policies….
  • 6. Third Priority • Tell your trustees (if you have them) what you are doing. Get their approval, eg by - Defining the simple legal basis you are using to process personal data - Doing and recording a simple information audit: what personal data you hold, why, in what form, where you send it, how long kept, and physical location? - Showing how you record consent, ie ‘explicit’; ‘positive indication of agreement.’ Cannot infer from silence/tick-box.
  • 7. Subject Access Requests (SARs) • You are unlikely to be able to charge for SARs • Response timescale: down from 40 days to 1 month • New option: can refuse a request if clearly excessive (BUT: you must have credible policies/processes in place for making such judgements and RECORD individual decisions) • New obligation: provide info to data subjects, eg data retention periods and the right to ‘correction’. • Think through operational impact.
  • 8. Reporting Breaches New, universal duty of breach notification - obligatory to have processes to detect, report and investigate breaches - Not all breaches must be reported to ICO: the ‘damage’ test - But you only have 72 hours for those that must… (won’t include community archives unless, eg a serious breach of sensitive personal data) - Fines: €20 million or 4% of global turnover. BUT ICO have said that only major breaches by major companies will fall into this bracket
  • 9. International Transfers • Unwitting? - Do you use mailchimp, Facebook, Eventbrite or other sites for your activities? - Have you read their privacy statements, eg will data you use be exported to US servers and thereby out of GDPR jurisdiction and protection? - Very important that you cover this
  • 10. Next steps? • We are working with partners on a Code of Practice: Hope it will be available end 2018. Aim to cover community archives • Need to also consider cross-border implications in Ireland • Training/briefing: ARA will continue to offer briefing sessions • ARA will keep advocating improvements/interpretations with governments and regulators. • Wider impact: new ARA Code of Ethics (2018) • A hunch: stand by for court cases after 2018…
  • 11. A working example: what we’ve done about GDPR 1. We have carried out an audit of the personal data we hold. We made a list of all the ways in which we collect or store personal data 2. We have updated and documented our personal data policy. We asked: Do we need each type of data on our list? How long should we keep it? 3. We have deleted unnecessary personal data. For example: we deleted old booking forms and copies of newsletter subscriptions 4. We have reviewed each process by which we collect personal data to be sure we are obtaining the right permissions. For example: we added a checkbox to all website forms, to ensure explicit consent 5. We have provided a method for people to find out what personal data we hold about them or request to have it deleted. Our privacy page now has a link to a form for requesting/deleting personal data 6. We have updated our privacy policy and published it on the website.
  • 13. 1. Do we need to get in touch with all our members/website contributors to get their consent to keep their contact details on record? 2. What do we do about the details of dead or living people that we hold in our archive? For example, in minutes of parish meetings? 3. If somebody sends us a research request, does that person need to give consent to us using their personal details in order to reply? Three common queries from community archives
  • 14. Further Reading • ARA advocacy papers to date (hand-outs) • European Data Protection Supervisor’s blog: dry, but… https://secure.edps.europa.eu/EDPSWEB/edps/lang/de/EDPS/P ublications/Blog_1 • The Guardian’s ‘51 Useful Data Protection Resources’: https://digitalguardian.com/blog/51-useful-data-protection- resources-blogs-videos-guides-infographics-tools-more • ICO (UK) blog and ICO guidance notes: https://ico.org.uk/about-the-ico/news-and-events/news-and- blogs/?facet_type=Blog&facet_date=&date_from=&date_to=

Editor's Notes

  1. It wasn’t ‘more people through the door’ (though it could be that)
  2. It wasn’t ‘more people through the door’ (though it could be that)
  3. It wasn’t ‘more people through the door’ (though it could be that)