SlideShare a Scribd company logo
&
GDPR for your Payroll Bureau
Tuesday 14th November 2017
Agenda
• What is GDPR and Why is it being implemented
• Why employers need to take it seriously
• How it will impact payroll bureaus
• How to prepare for GDPR
• How Thesaurus is working to help you
GDPR, what is it?
General Data Protection Regulation
• Aims to provide better protection for personal data
• Current data legislation dates back to 1998
Data is getting out of hand
Data brokers collect more
than 50 trillion unique data
transactions per year
82% of Android apps track
your other
online activities
If you read all of the terms of service for all
of your apps it would take 76 days
PayPal’s Terms of Service is
36,275 words long:
that’s longer than Hamlet
GDPR D-Day
145 Working Days to go
Reasons to Pay Attention!
€20,000,000
Or
4% of turnover
€10,000,000
Or
2% of turnover
FINES
Serious breaches
- Not having sufficient customer
consent
- Violating Privacy by Design
Serious breaches
Failure to: - document &
communicate Joint Controller
relationships
- ensure contract with Data Processor
Key Terms
Data Subject
• An individual who is the subject of the personal
data
Data controller
• Controls the contents and use of personal data
Processing means:
• Operations performed on personal data whether or
not by automated means
Controller is who:
• Determines the purposes and means of the
processing of personal data
Personal data breach:
• Means a breach of security leading to the
accidental or unlawful destruction, loss, alteration,
unauthorised disclosure of, or access to, personal
data transmitted, stored or otherwise processed.
Processor is who:
• Processes personal data on behalf of the controller.
Supervising Authority
Website www.ico.org.uk
www.gov.uk
E-mail:
Phone: +44 303 123 1113
Who does it apply to?
• EU Companies that process personal data, regardless
of whether the processing takes place in the EU
• Non-EU companies who offer goods or services to
individuals in the EU, irrespective of whether payment
is required.
• Non-EU companies who monitor individual’s
behaviour that takes place in the EU.
What is Personal Data?
“Any information related on a natural person or ‘Data Subject’, that can
be used to directly or indirectly identify a person.”
 A name
 A photo
 An email address
 Bank details
 Posts on social networking websites
 Medical information
 CCTV images
 Records of websites visited
 A computer IP address
-Key areas to consider
Six Principles of GDPR
Personal data shall be:
1. Processed lawfully, fairly and in a transparent manner
2. Collected for specified, explicit and legitimate purposes and not further
processed in a manner that is incompatible with those purposes
3. Adequate, relevant and limited to what is necessary
4. Accurate and kept up-to-date
5. Kept for no longer than necessary
6. Processed in a confidential and secure manner
Accountability: demonstration of compliance
Lawful Processing
Processing is only lawful if:
• Data subject has given consent
• Necessary for the performance of a contract
• Necessary for the compliance with legal obligation
• In order to protect vital interests of a person
• Necessary for public interest or official authority
• For the legitimate interests of data controller/3rd party
Changes to Consent Rules
Consent must be:
- Specific, informed,
unambiguous and freely given
- Must be for a specified purpose
Where consent is obtained
as part of a larger document
covering other things,
consent must be clearly
distinguished from
everything else
Evidence needs to be retained
as to how the consent was
obtained
Forms, brochures signage,
website screenshots etc.
Language must be
accessible and easily
understood
Special Categories of Data
• Racial or ethnic origin
• Political opinions
• Religious or philosophical beliefs
• Trade union membership
• The processing of genetic data, biometric data for the purpose of
uniquely identifying a person
• Data concerning health, a person's sex life or sexual orientation
Children’s Personal Data
Under 16
Parental Guidance
Data Protection by Design and by Default
• Privacy by design: seeks to ensure that privacy issues are considered
at the outset of a project, rather than being an add on at a later stage
of a project.
• Privacy by default: by default only such personal data as is necessary
for the identified purposes should be processed.
Data Protection Impact Assessments (DPIA)
• A DPIA should contain:
• A description of the processing operations and the purposes
• An assessment of the necessity and proportionality of the processing in
relation to the purpose
• An assessment of the risks to the individuals
• The measures put in place to address risk, including security and to
demonstrate that you comply
• Where substantial risk is identified, you must refer to the Supervisory
Authority
Enhanced Rights for Individuals
Right to be
informed
The right to
access
The right to
rectification
The right to
erasure
The right to
restrict
processing
The right to data
portability
The right to
object
Rights in relation
to automated
decision making
Breach Reporting
 Breach:
The destruction, loss, alteration, unauthorised disclosure of or access to
personal data, human error
 Reported to Data Protection Commissioner
 Within 72 hours
Incident Response Plan
Containment and recovery
Assessment of ongoing risk
Notification of the breach
Post mortem and response
2016 Reported Breaches
Theft of IT Equipment 14
Website Security 103
Unauthorised Disclosure – Postal 570
Unauthorised Disclosure – Electronic 376
Unauthorised Disclosure – Other 1,117
Security related issues 44
The Data Protection Officer (DPO)
Mandatory for:
 Public Bodies
 Organisations engaged in “Large Scale” regular/systematic monitoring
 Organisations whose core activities consist of processing “special categories” of
data or data relating to criminal convictions
 May be mandatory in other contexts as defined by Member State Law
The DPO must:
 Have “expert knowledge” of Data Protection Law
 Must be involved in a “timely manner” in discussions of personal data processing
 Details must be provided to the DPC
Civil Liability
Individuals can claim for compensation for material loss and non-
material damage, including:
Distress
Hurt Feelings
Reputational Damage
No proven financial loss
-Start Preparing Now
1. Your Data Inventory
• Create in inventory of all personal data held
• Why are you holding the data? The legal basis?
• How is data obtained?
• Why was it originally gathered.
• How long data is held for?
• How is data saved? Securely?
• Is data shared? With whom?
2. Data Privacy Notices
 The business identity
 Contact details for the business and the DPO, if applicable
 The reasons for collecting the data
 The use(s) to which the data will be put to
 To whom the data will be disclosed
 Whether the data will be transferred outside of the EU
 The legal basis for processing the the data
 Where the processing is based on the legitimate interests of the business, the legitimate interest
concerned
 Where the processing is necessitated by a statutory or contractual requirement, the consequences for the
individual of not providing the data.
 The period of which the data will be stored, or the criteria to be used to determine retention periods
 Whether the data subject will be subject to automated decision making
 The rights of the individual under the GDPR
3. Further Preparation
• Speak to Data Controllers or Data Processors
• Processing children’s data?
• Will access requests change?
• How will you manage breaches?
• Data by Design / Data Protection Impact Assessment
• Do you require a Data Protection Officer?
GDPR from a HR Perspective
Lawful processing
• What is your reason for retaining and processing personal data?
• Consent no longer an option for HR data
• Imbalance of power between employee & employer
1. Legitimate interests of the business
2. Performance of a contract or legal obligation
Increased employee rights
• Clear policies
Delete, delete, delete
-How Thesaurus Software is Preparing
It’s your data
Keep your
password safe!
What we have done
 New in-program features
 Updated our Privacy Policies
 Internal IT audits
 Increased security – in house
 Introduced extra consent fields
 Staff training
 Bright Contracts updated policies
Thank You!
G.D.P.R.
General Data Protection Regulation
25th May 2018
BrightPay
www.brightpay.co.uk
support@brightpay.co.uk
PH +44 (0) 845 3004304
Bright Contacts
www.brightcontracts.co.uk
support@brightcontracts.co.uk
PH +44 (0) 845 3004305
-Appendix: GDPR List of Offences
2% Offences
• Breaches of provisions relating to consent of Children
• Asking for personal data, citing GDPR as basis, where you are not
processing identifiable data
• Failure to implement Privacy by Design/by Default
• Failure to document & communicate Joint Controller relationships
• Failure to appoint a representative if based outside EU
• Failure to ensure contract with Data Processor
• Engagement of a sub-processor by processor without authorisation
• Failure to include prescribe content in Processor Contracts
• Processing data by a Data Processor other than on instruction of
Data Controller
• Failure to ensure DPO does not have conflict of interest in execution
of duties
• Failure to execute tasks of the DPO under Article 39
• Failure to apply required controls or safeguards under a DP
certification scheme
• Failure to keep records of processing activities (Article 30)
• Failure to cooperate with the Supervisory Authority
• Failure to ensure appropriate level of security over personal data
• Failure to ensure ability to restore availability and access to data
• Failure to conduct regular testing of effectiveness of technical and
organisational controls for information security
• Failure to notify data breach to Supervisory Authority
• Failure to communicate data breach to Data Subjects (where
required)
• Failure to conduct Data Protection Impact Assessments (when
required)
• Failure to consult with Supervisory Authority where PIA suggests
high risk to rights of individuals
• Failure to engage DPO in a timely manner
• Failure to support DPO in performance of tasks, including provision
of resources, access to data and processing operations, and
opportunity to maintain expert knowledge
• Failure by a certification body to meet the conditions for
accreditation or where actions of the accrediting body infringe the
Regulation
4% Offences
• Breaching any of the core principles of
GDPR
• Failure to implement measures to comply
with the accountability principle
• Failure to comply with standards required
for consent, where consent only basis for
processing
• Unlawful processing of “special
categories” of personal information
• Infringement of rights under Article 12 –
22
• Transfers to 3rd countries in
contravention of provisions of Articles 44
to 49
• Failure to comply with any obligation
under Member State Law under
“Delegated Acts” under Regulation
• Non-compliance with a prohibition under
Article 58(2) on processing or data
transfers, whether temporary or
definitive
• Failure to provide access to Data
Protection Supervisory Authority to
conduct investigations as per Article 58(1)

More Related Content

What's hot

GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
Elizabeth Baker, JD, CRCMP
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
Harrison Clark Rickerbys
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
Spain-Holiday.com
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Extentia Information Technology
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
Luke Kyte
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
DipanjanDey12
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
HackerOne
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
joshquarrie
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Frank Dawson
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
Deeson
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
Ulf Mattsson
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
HackerOne
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
ImogenRutherford
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
IBB Law
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
BrightPay Payroll and Auto Enrolment Software
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
Happiest Minds Technologies
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Cvent
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
Vicky Dallas
 

What's hot (20)

GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 

Similar to GDPR for your Payroll Bureau

What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
Guy Griffiths
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
Kwanzoo Inc
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
Browne Jacobson LLP
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
James Mulhern
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
Forums financiers de Wallonie
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Rotary International
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
Sudarsan Reddy
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
Priyab Satoshi
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
SecurityScorecard
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
NiclasGranqvist
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
Financial Poise
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
MichelleSaver
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
GDPR master class accountable research organisations (january 2018)
GDPR master class   accountable research organisations (january 2018)GDPR master class   accountable research organisations (january 2018)
GDPR master class accountable research organisations (january 2018)
MRS
 

Similar to GDPR for your Payroll Bureau (20)

What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
GDPR master class accountable research organisations (january 2018)
GDPR master class   accountable research organisations (january 2018)GDPR master class   accountable research organisations (january 2018)
GDPR master class accountable research organisations (january 2018)
 

More from BrightPay Payroll and Auto Enrolment Software

Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back
BrightPay Payroll and Auto Enrolment Software
 
BrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it worksBrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it works
BrightPay Payroll and Auto Enrolment Software
 
Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022
BrightPay Payroll and Auto Enrolment Software
 
Webinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQWebinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQ
BrightPay Payroll and Auto Enrolment Software
 
Revenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for OctoberRevenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for October
BrightPay Payroll and Auto Enrolment Software
 
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker RevenueEmployment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
BrightPay Payroll and Auto Enrolment Software
 
EWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to knowEWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to know
BrightPay Payroll and Auto Enrolment Software
 
The End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term ImpactsThe End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term Impacts
BrightPay Payroll and Auto Enrolment Software
 
BrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for AccountantsBrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for Accountants
BrightPay Payroll and Auto Enrolment Software
 
BrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting SoftwareBrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay Payroll and Auto Enrolment Software
 
Furlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from JulyFurlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from July
BrightPay Payroll and Auto Enrolment Software
 
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine PolicyLeaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
BrightPay Payroll and Auto Enrolment Software
 
Take the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflowsTake the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflows
BrightPay Payroll and Auto Enrolment Software
 
Payroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule ChangesPayroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule Changes
BrightPay Payroll and Auto Enrolment Software
 
Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...
BrightPay Payroll and Auto Enrolment Software
 
Optimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve ProfitabilityOptimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve Profitability
BrightPay Payroll and Auto Enrolment Software
 
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC QuirksCJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
BrightPay Payroll and Auto Enrolment Software
 
IR35 - Are you Ready?
IR35 - Are you Ready?IR35 - Are you Ready?
The Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-HouseThe Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-House
BrightPay Payroll and Auto Enrolment Software
 
Switch to BrightPay
Switch to BrightPaySwitch to BrightPay

More from BrightPay Payroll and Auto Enrolment Software (20)

Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back
 
BrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it worksBrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it works
 
Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022
 
Webinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQWebinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQ
 
Revenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for OctoberRevenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for October
 
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker RevenueEmployment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
 
EWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to knowEWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to know
 
The End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term ImpactsThe End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term Impacts
 
BrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for AccountantsBrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for Accountants
 
BrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting SoftwareBrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting Software
 
Furlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from JulyFurlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from July
 
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine PolicyLeaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
 
Take the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflowsTake the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflows
 
Payroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule ChangesPayroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule Changes
 
Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...
 
Optimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve ProfitabilityOptimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve Profitability
 
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC QuirksCJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
 
IR35 - Are you Ready?
IR35 - Are you Ready?IR35 - Are you Ready?
IR35 - Are you Ready?
 
The Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-HouseThe Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-House
 
Switch to BrightPay
Switch to BrightPaySwitch to BrightPay
Switch to BrightPay
 

Recently uploaded

Accelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with PlatformlessAccelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with Platformless
WSO2
 
2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx
Georgi Kodinov
 
Using IESVE for Room Loads Analysis - Australia & New Zealand
Using IESVE for Room Loads Analysis - Australia & New ZealandUsing IESVE for Room Loads Analysis - Australia & New Zealand
Using IESVE for Room Loads Analysis - Australia & New Zealand
IES VE
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
Globus
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
Matt Welsh
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Shahin Sheidaei
 
Designing for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesDesigning for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web Services
KrzysztofKkol1
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke
 
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, BetterWebinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
XfilesPro
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
Paco van Beckhoven
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Globus
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
Cyanic lab
 
Corporate Management | Session 3 of 3 | Tendenci AMS
Corporate Management | Session 3 of 3 | Tendenci AMSCorporate Management | Session 3 of 3 | Tendenci AMS
Corporate Management | Session 3 of 3 | Tendenci AMS
Tendenci - The Open Source AMS (Association Management Software)
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Globus
 
How Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptxHow Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptx
wottaspaceseo
 
Visitor Management System in India- Vizman.app
Visitor Management System in India- Vizman.appVisitor Management System in India- Vizman.app
Visitor Management System in India- Vizman.app
NaapbooksPrivateLimi
 
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Globus
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
Globus
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2
 

Recently uploaded (20)

Accelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with PlatformlessAccelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with Platformless
 
2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx
 
Using IESVE for Room Loads Analysis - Australia & New Zealand
Using IESVE for Room Loads Analysis - Australia & New ZealandUsing IESVE for Room Loads Analysis - Australia & New Zealand
Using IESVE for Room Loads Analysis - Australia & New Zealand
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
 
Designing for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesDesigning for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web Services
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
 
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, BetterWebinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
 
Corporate Management | Session 3 of 3 | Tendenci AMS
Corporate Management | Session 3 of 3 | Tendenci AMSCorporate Management | Session 3 of 3 | Tendenci AMS
Corporate Management | Session 3 of 3 | Tendenci AMS
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
 
How Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptxHow Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptx
 
Visitor Management System in India- Vizman.app
Visitor Management System in India- Vizman.appVisitor Management System in India- Vizman.app
Visitor Management System in India- Vizman.app
 
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 

GDPR for your Payroll Bureau

  • 1. & GDPR for your Payroll Bureau Tuesday 14th November 2017
  • 2. Agenda • What is GDPR and Why is it being implemented • Why employers need to take it seriously • How it will impact payroll bureaus • How to prepare for GDPR • How Thesaurus is working to help you
  • 3. GDPR, what is it? General Data Protection Regulation • Aims to provide better protection for personal data • Current data legislation dates back to 1998
  • 4. Data is getting out of hand Data brokers collect more than 50 trillion unique data transactions per year 82% of Android apps track your other online activities If you read all of the terms of service for all of your apps it would take 76 days PayPal’s Terms of Service is 36,275 words long: that’s longer than Hamlet
  • 6. Reasons to Pay Attention! €20,000,000 Or 4% of turnover €10,000,000 Or 2% of turnover FINES Serious breaches - Not having sufficient customer consent - Violating Privacy by Design Serious breaches Failure to: - document & communicate Joint Controller relationships - ensure contract with Data Processor
  • 7. Key Terms Data Subject • An individual who is the subject of the personal data Data controller • Controls the contents and use of personal data Processing means: • Operations performed on personal data whether or not by automated means Controller is who: • Determines the purposes and means of the processing of personal data Personal data breach: • Means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Processor is who: • Processes personal data on behalf of the controller.
  • 9. Who does it apply to? • EU Companies that process personal data, regardless of whether the processing takes place in the EU • Non-EU companies who offer goods or services to individuals in the EU, irrespective of whether payment is required. • Non-EU companies who monitor individual’s behaviour that takes place in the EU.
  • 10. What is Personal Data? “Any information related on a natural person or ‘Data Subject’, that can be used to directly or indirectly identify a person.”  A name  A photo  An email address  Bank details  Posts on social networking websites  Medical information  CCTV images  Records of websites visited  A computer IP address
  • 11. -Key areas to consider
  • 12. Six Principles of GDPR Personal data shall be: 1. Processed lawfully, fairly and in a transparent manner 2. Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes 3. Adequate, relevant and limited to what is necessary 4. Accurate and kept up-to-date 5. Kept for no longer than necessary 6. Processed in a confidential and secure manner Accountability: demonstration of compliance
  • 13. Lawful Processing Processing is only lawful if: • Data subject has given consent • Necessary for the performance of a contract • Necessary for the compliance with legal obligation • In order to protect vital interests of a person • Necessary for public interest or official authority • For the legitimate interests of data controller/3rd party
  • 14. Changes to Consent Rules Consent must be: - Specific, informed, unambiguous and freely given - Must be for a specified purpose Where consent is obtained as part of a larger document covering other things, consent must be clearly distinguished from everything else Evidence needs to be retained as to how the consent was obtained Forms, brochures signage, website screenshots etc. Language must be accessible and easily understood
  • 15. Special Categories of Data • Racial or ethnic origin • Political opinions • Religious or philosophical beliefs • Trade union membership • The processing of genetic data, biometric data for the purpose of uniquely identifying a person • Data concerning health, a person's sex life or sexual orientation
  • 16. Children’s Personal Data Under 16 Parental Guidance
  • 17. Data Protection by Design and by Default • Privacy by design: seeks to ensure that privacy issues are considered at the outset of a project, rather than being an add on at a later stage of a project. • Privacy by default: by default only such personal data as is necessary for the identified purposes should be processed.
  • 18. Data Protection Impact Assessments (DPIA) • A DPIA should contain: • A description of the processing operations and the purposes • An assessment of the necessity and proportionality of the processing in relation to the purpose • An assessment of the risks to the individuals • The measures put in place to address risk, including security and to demonstrate that you comply • Where substantial risk is identified, you must refer to the Supervisory Authority
  • 19. Enhanced Rights for Individuals Right to be informed The right to access The right to rectification The right to erasure The right to restrict processing The right to data portability The right to object Rights in relation to automated decision making
  • 20. Breach Reporting  Breach: The destruction, loss, alteration, unauthorised disclosure of or access to personal data, human error  Reported to Data Protection Commissioner  Within 72 hours
  • 21. Incident Response Plan Containment and recovery Assessment of ongoing risk Notification of the breach Post mortem and response
  • 22. 2016 Reported Breaches Theft of IT Equipment 14 Website Security 103 Unauthorised Disclosure – Postal 570 Unauthorised Disclosure – Electronic 376 Unauthorised Disclosure – Other 1,117 Security related issues 44
  • 23. The Data Protection Officer (DPO) Mandatory for:  Public Bodies  Organisations engaged in “Large Scale” regular/systematic monitoring  Organisations whose core activities consist of processing “special categories” of data or data relating to criminal convictions  May be mandatory in other contexts as defined by Member State Law The DPO must:  Have “expert knowledge” of Data Protection Law  Must be involved in a “timely manner” in discussions of personal data processing  Details must be provided to the DPC
  • 24. Civil Liability Individuals can claim for compensation for material loss and non- material damage, including: Distress Hurt Feelings Reputational Damage No proven financial loss
  • 26. 1. Your Data Inventory • Create in inventory of all personal data held • Why are you holding the data? The legal basis? • How is data obtained? • Why was it originally gathered. • How long data is held for? • How is data saved? Securely? • Is data shared? With whom?
  • 27. 2. Data Privacy Notices  The business identity  Contact details for the business and the DPO, if applicable  The reasons for collecting the data  The use(s) to which the data will be put to  To whom the data will be disclosed  Whether the data will be transferred outside of the EU  The legal basis for processing the the data  Where the processing is based on the legitimate interests of the business, the legitimate interest concerned  Where the processing is necessitated by a statutory or contractual requirement, the consequences for the individual of not providing the data.  The period of which the data will be stored, or the criteria to be used to determine retention periods  Whether the data subject will be subject to automated decision making  The rights of the individual under the GDPR
  • 28. 3. Further Preparation • Speak to Data Controllers or Data Processors • Processing children’s data? • Will access requests change? • How will you manage breaches? • Data by Design / Data Protection Impact Assessment • Do you require a Data Protection Officer?
  • 29. GDPR from a HR Perspective Lawful processing • What is your reason for retaining and processing personal data? • Consent no longer an option for HR data • Imbalance of power between employee & employer 1. Legitimate interests of the business 2. Performance of a contract or legal obligation Increased employee rights • Clear policies Delete, delete, delete
  • 30. -How Thesaurus Software is Preparing
  • 31. It’s your data Keep your password safe!
  • 32. What we have done  New in-program features  Updated our Privacy Policies  Internal IT audits  Increased security – in house  Introduced extra consent fields  Staff training  Bright Contracts updated policies
  • 33. Thank You! G.D.P.R. General Data Protection Regulation 25th May 2018 BrightPay www.brightpay.co.uk support@brightpay.co.uk PH +44 (0) 845 3004304 Bright Contacts www.brightcontracts.co.uk support@brightcontracts.co.uk PH +44 (0) 845 3004305
  • 34. -Appendix: GDPR List of Offences
  • 35. 2% Offences • Breaches of provisions relating to consent of Children • Asking for personal data, citing GDPR as basis, where you are not processing identifiable data • Failure to implement Privacy by Design/by Default • Failure to document & communicate Joint Controller relationships • Failure to appoint a representative if based outside EU • Failure to ensure contract with Data Processor • Engagement of a sub-processor by processor without authorisation • Failure to include prescribe content in Processor Contracts • Processing data by a Data Processor other than on instruction of Data Controller • Failure to ensure DPO does not have conflict of interest in execution of duties • Failure to execute tasks of the DPO under Article 39 • Failure to apply required controls or safeguards under a DP certification scheme • Failure to keep records of processing activities (Article 30) • Failure to cooperate with the Supervisory Authority • Failure to ensure appropriate level of security over personal data • Failure to ensure ability to restore availability and access to data • Failure to conduct regular testing of effectiveness of technical and organisational controls for information security • Failure to notify data breach to Supervisory Authority • Failure to communicate data breach to Data Subjects (where required) • Failure to conduct Data Protection Impact Assessments (when required) • Failure to consult with Supervisory Authority where PIA suggests high risk to rights of individuals • Failure to engage DPO in a timely manner • Failure to support DPO in performance of tasks, including provision of resources, access to data and processing operations, and opportunity to maintain expert knowledge • Failure by a certification body to meet the conditions for accreditation or where actions of the accrediting body infringe the Regulation
  • 36. 4% Offences • Breaching any of the core principles of GDPR • Failure to implement measures to comply with the accountability principle • Failure to comply with standards required for consent, where consent only basis for processing • Unlawful processing of “special categories” of personal information • Infringement of rights under Article 12 – 22 • Transfers to 3rd countries in contravention of provisions of Articles 44 to 49 • Failure to comply with any obligation under Member State Law under “Delegated Acts” under Regulation • Non-compliance with a prohibition under Article 58(2) on processing or data transfers, whether temporary or definitive • Failure to provide access to Data Protection Supervisory Authority to conduct investigations as per Article 58(1)