SlideShare a Scribd company logo
1 of 40
www.emmainternational.com
GDPR in
Healthcare Industry
Need, Strategy, Implementation and
continuous monitoring
Joseph Yammine, EMEA Director
Joseph.Yammine@emmainternational.com
Leaders in Compliance
Consulting and
Enterprise Quality
Management Software
• EMMA International Consulting Group, Inc. is a global leader in
management consulting services, with headquarters in
Farmington Hills, MI, as well as offices in Grand Rapids, MI, FL,
PA, and Beirut, Lebanon. We focus on quality, regulatory, and
compliance services for the medical device industries.
Data, Data, Data, Data, …
• 1992 – 100 GB of data generated on daily basis
• 1997 – 100 GB of data generated on hourly basis
• 2002 – 100 GB of data generated on per second basis
• 2018 – 50,000 GB per second
90% of all the data in the world today has been created in the
past few years
Data, Data, Data, Data, …
2018
This is what happens in an
INTERNET MINUTE
Data, Data, Data and Data
According to the 2017 Ponemon Institute Study, What Is the Cost
of a Data Breach in the Healthcare Industry?
A. $2.2 Billion
B. $3.6 Billion
C. $4.0 Billion
D. $6.2 Billion
The Answer is D
Healthcare Data Breaches are Costly…
• When a healthcare organization experiences a breach, forensics costs
added up to $610,000.
• Breach notification costs $560,000 on average.
• Costs affiliated with lawsuits average $880,000.
• For each data breach, healthcare organizations average $3.7 million
in lost revenue.
• Healthcare organizations average $500,000 in lost brand value after
a breach.
• The average HIPAA settlement fine is approximately $1.1 million.
• Post-breach cleanup costs average $440,000.
Healthcare Data Breaches in Q3: 2018
• The first three months of 2018 have seen 77 healthcare data
breaches reported to the Department of Health and Human
Services’ Office for Civil Rights (OCR).
• Those breaches have impacted more than one million patients
and health plan members
• Almost twice the number of individuals that were impacted by healthcare data breaches in Q4, 2017.
• Between January 1 and March 31, 2018, 1,073,766 individuals had their PHI exposed, viewed, or stolen
compared to 520,141 individuals in Q4, 2017.
What we will cover today?
• What is personal data – and why it’s important for us
• What is Data Protection
• GDPR - what’s changing and what it’s all about
• GDPR Principles
• Who this will affect
• How to be ready
• What support is available
What we will cover today?
What is Personal Data?
• Personal data is defined as:
• Any information about a living individual which is capable of identifying
that individual.
• Sensitive personal data is defined as:
• Any information relating to an individual's racial or ethnic origin, political
opinions, religious beliefs, trade union membership, physical or mental health
or condition, sexual life, alleged or actual criminal activity and criminal
record.
Under GDPR sensitive personal data is referred to as “special categories of personal data”)
What is Personal Data?
What is Personal Data?
 Special Categories:
 Race / Ethnic origin
 Political opinions
 Religious or similar beliefs
 Union
 Physical / Mental health
 Sexual life
 Alleged / Actual offences / Information
What is Data Protection?
Data Protection is about avoiding harm to individuals by misusing or
mismanaging their personal data.
So if you collect, use, or store personal data then the Data Protection
Act applies to you. It sets out eight principles you have to adhere to,
which include:
• Only collect information for specific purposes and don’t then use it for other
purposes
• Only collect what you need for the specific purpose
• Keep it accurate and up to date; and safe and secure
• Process information lawfully and allow subject access in line with the Act.
What is GDPR?
It is the General Data Protection Regulation, which
supersedes the Data Protection Act on 25th May 2018. The
key changes from the current law are to strengthen rights
of individuals and place more obligations on organisations
in looking after personal data.
In order to comply with the new law:
• You must have a legitimate reason for processing data – this will cover
much processing we undertake (see later slide)
• Consent must be freely and unambiguously given and can be just as
easily withdrawn
• Data Processing activities must start with “privacy by design and default”.
What is GDPR?... continued
• Subject Access Requests – will include how you process and share data
not just what you hold and you’ll have less time to respond
• Subjects can request data deletion – “the right to be forgotten”, though
only in certain circumstances
• There will be mandatory breach reporting
• Data processors will be held liable
• You must be able to demonstrate compliance with GDPR
• While the ICO say it is a last resort, the potential fines are much greater
than at present – up to 4% of annual global turnover or €20m
• And finally – it’s happening regardless of Brexit!
Why the GDPR?
• We care - we are responsible for handling people’s most
personal information
• This is an opportunity to make privacy central to what we do
• By not handling personal data properly we could put
individuals at risk and the company / organization reputation
at stake
• Getting it wrong could result in significant fines
• We need robust systems and processes in place to make sure
we use personal information properly and comply
Who does this affect?
• All of us - we all have a responsibility to keep people’s
information safe; main industries are healthcare, banking and
educational organizations
• Particularly those involved in:
• Human Resources
• Research & Development
• Research involving personal data and/or human participants
• Finance
• Information Technology
Who does this affect?
GDPR Principles
• Lawfulness, fairness and transparency – as with Data Protection
• Purpose limitation – only collect for specific purposes and then don’t use it for other purposes
• Data minimisation – only collect the data you need for the purpose you are using it
• Accuracy – as now, keep it up to date!
• Storage limitation – don’t keep it for longer than you need to fulfil the purpose
• Integrity and confidentiality – keep it safe and secure e.g. encrypted if on a laptop or mobile
phone.
• Accountability – you must be able to prove you have complied with the above.
GDPR Principles
Examples of Processing
 Staff management and payroll administration
 Access to/consultation of a contacts database containing personal data
 Sending promotional emails
 Shredding documents containing personal data
 Posting a photo of a person on a website
 Storing IP addresses or MAC addresses
 Video recording (CCTV)
GDPR Principles
Subjects’ rights
 Confirmation of processing
 Purposes of processing
 Rectification
 Erasure (Right to be forgotten)
 Restriction of processing
 Portability
 Access to data
GDPR Stakeholders
Data Control Viewer
Data Control Viewer
Preparation for GDPR
1. Audit Data Usage
 What?
 Why?
 Where?
 Who?
 How
Preparation for GDPR
1. Audit Data Usage
 Legal Basis for processing personal data:
 Legal obligation
 Contract
 Consent
 Vital interests (of data subject)
 Necessary in public interest
 Legitimate interests (of the Controller
Preparation for GDPR
1. Audit Data Usage
 Data Security:
 Of paper records
 Physical access to data
 Locks / doors
 Security guards
 Etc.
 Technological security
 Firewall
 Anti-virus
 Software updates
 Etc.
Preparation for GDPR
1. Audit Data Usage
 Data Security:
 Data protection policy
 IT Security policy
 Breach procedure / Log
 Subject access request procedure
 Privacy notice(s) / collection notices (mandatory)
 Training programme and log
 Data protection impact assessments (mandatory)
Preparation for GDPR
1. Audit Data Usage
 Data Security: Check your contracts with data processors
 Contracts include data protection clauses
 Compliance with GPDR
 Security is up-to-date / in place
 Procedures and policies are to your satisfaction
 Will alert you to problems
 Right to audit?
Preparation for GDPR
2. Data Protection Officer
 Do you need one?
 Public authority or body
 Large scale processing operations which by their nature require
regular systematic monitoring of data subjects
 Core activities involves large scale processing of special categories
of personal data and data relating to criminal convictions and
offences
 The Role:
 To be involved in issues relating to protection of personal data
 Expert knowledge of data protection
 Not be instructed
Preparation for GDPR
2. Data Protection Officer
 Important Notes
 It’s all important!
 Security –
 IT / technology
 Physical
 Basis for processing
 Data protection impact assessments
 Breach notifications
 Subject access requests
 Register with the ICO (Information Commissioner)
Preparation for GDPR
3. Data Processing (Article 4.2)
 Collecting
 Recording
 Organising
 Structuring
 Storing
 Adapting
 Altering
 Retrieving
 Consulting
 Using
 Disclosing
 Disseminating
 Aligning or combining
 Restricting
 Erasing
 Destroying
Preparation for GDPR
3. Data Processing (Article 4.2)
Preparation for GDPR
4. Consenting Process
“the data subject has given consent to the processing of his or her
personal data for one or more specific purposes
 Consent
 must be freely given, specific, informed and unambiguous;
 by a statement or a clear affirmative action;
 cannot be inferred by silence, pre-ticked boxes or inactivity
 can be withdrawn and it must be easy to do so
 Processing of sensitive personal data requires “explicit consent”
 Records must be kept of how and when consent was given
Preparation for GDPR
5. Demonstrating Accountability
 Internal policies and procedures (data protection / retention policy; security and data breach; data subject rights)
 External privacy notice(s)
 Internal compliance measures and external controls
 Maintain records of data processing activities
 Steps when engaging data processors
 Undertake regular staff training
 Review and update policies and procedures on ongoing basis
 Internal audit of processing activities
 Appoint a Data Protection Officer (DPO), where appropriate.
 Data Protection Impact Assessments, where appropriate
 Data protection by design and by default
Preparation for GDPR
6. Data Breach Reporting
 Personal data breach – a security breach leading to “the accidental or unlawful destruction,
loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or
otherwise processed”
 Data controller must notify a personal data breach to the supervisory authority (DPC) within
72 hours of becoming aware of it.
 If notified later, must give reasons for the delay.
 Notification requires certain minimum information.
 In “high-risk” cases may have to inform affected individuals.
 Notification not required where the breach is unlikely to result in a risk to the rights of
individuals.
 Data controller must document any personal data breach, including the facts, its effects and
remedial action taken
What do I and my team need to do?
Key GDPR Take Away
 Requires a shift in culture and mindset about people’s data privacy
 It’s principles-based and risk-based
 Collecting, using and securing personal data has a cost
 Individuals have more control, with new and enhanced rights
 Privacy notices need more information and must be clear and concise
 Processing requires a legal basis and must comply with the 6 principles
 Data controllers must be able to demonstrate their accountability
 Review how you get, record and manage consent
 Data processor contracts and liability issues
 Decide if a DPO required, and document this. At minimum, appoint a lead.
 Be aware of increased regulatory sanctions and powers.
 Review your IT systems and security
 Everyone needs a data breach plan
Thank You
For further information, please do not hesitate to contact us
Joseph.Yammine@emmainternational.com
Farmington Hills, MI:
Headquarters
27600 Farmington Rd., Suite 100
Farmington Hills, MI 48334
Phone (248) 987-4497
York, PA:
320 Busser Road.,
Suite 200
Emigsville, PA 17318
Phone (717) 429-6875
Clearwater, FL:
28870 US HWY 19 North,
Suite 300
Clearwater, FL 33761
Phone (727) 614-8851
Lebanon
7TH Floor, Le Mall Building,
Dbayeh Highway, Northern Metn,
Lebanon
Grand Rapids, MI:
250 Monroe NW Suite 400
Grand Rapids, MI 49503
(616) 219-0510

More Related Content

What's hot

Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
Information governance
Information governanceInformation governance
Information governanceGerardo Medina
 
GDPR and ISO27001 mapping EL
GDPR and ISO27001 mapping ELGDPR and ISO27001 mapping EL
GDPR and ISO27001 mapping ELEugene Lee
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protectionsp_krishna
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Happiest Minds Technologies
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance Dovetail Software
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Frank Dawson
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 

What's hot (20)

Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Data Privacy & Security
Data Privacy & SecurityData Privacy & Security
Data Privacy & Security
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Information governance
Information governanceInformation governance
Information governance
 
GDPR and ISO27001 mapping EL
GDPR and ISO27001 mapping ELGDPR and ISO27001 mapping EL
GDPR and ISO27001 mapping EL
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 

Similar to GDPR in the Healthcare Industry

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteClive Rich
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyRay ABOU
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .ClinosolIndia
 
GDPR Data Life Cycle
GDPR Data Life CycleGDPR Data Life Cycle
GDPR Data Life CycleJatin Kochhar
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR ComplianceAndreas Batsis
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRCase IQ
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018Dean Evans
 
3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.Richard Kranendonk
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?Christiana Kozakou
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 

Similar to GDPR in the Healthcare Industry (20)

GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .
 
GDPR Data Life Cycle
GDPR Data Life CycleGDPR Data Life Cycle
GDPR Data Life Cycle
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
GDPR Data Lifecycle
GDPR Data LifecycleGDPR Data Lifecycle
GDPR Data Lifecycle
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018
 
3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 

More from EMMAIntl

Cartilage Regeneration Techniques
Cartilage Regeneration TechniquesCartilage Regeneration Techniques
Cartilage Regeneration TechniquesEMMAIntl
 
Stability Testing of Pharmaceuticals and Supplements
Stability Testing of Pharmaceuticals and SupplementsStability Testing of Pharmaceuticals and Supplements
Stability Testing of Pharmaceuticals and SupplementsEMMAIntl
 
Intolerance vs. Allergy
Intolerance vs. AllergyIntolerance vs. Allergy
Intolerance vs. AllergyEMMAIntl
 
Material Science in MedTech
Material Science in MedTechMaterial Science in MedTech
Material Science in MedTechEMMAIntl
 
Investigating Ketamine for Parkinson’s Disease
Investigating Ketamine for Parkinson’s DiseaseInvestigating Ketamine for Parkinson’s Disease
Investigating Ketamine for Parkinson’s DiseaseEMMAIntl
 
Aduhelm, an Accelerated Approval for Alzheimer’s
Aduhelm, an Accelerated Approval for Alzheimer’sAduhelm, an Accelerated Approval for Alzheimer’s
Aduhelm, an Accelerated Approval for Alzheimer’sEMMAIntl
 
World Blood Donor Day 2021
World Blood Donor Day 2021World Blood Donor Day 2021
World Blood Donor Day 2021EMMAIntl
 
New COVID-19 Vaccine
New COVID-19 VaccineNew COVID-19 Vaccine
New COVID-19 VaccineEMMAIntl
 
Men’s Health Week: Depression
Men’s Health Week: DepressionMen’s Health Week: Depression
Men’s Health Week: DepressionEMMAIntl
 
Celebrating Pride Month at EMMA International
Celebrating Pride Month at EMMA InternationalCelebrating Pride Month at EMMA International
Celebrating Pride Month at EMMA InternationalEMMAIntl
 
Growth and Integration of ML/AI in Biotech
Growth and Integration of ML/AI in BiotechGrowth and Integration of ML/AI in Biotech
Growth and Integration of ML/AI in BiotechEMMAIntl
 
Using QFD for Medical Device Development
Using QFD for Medical Device DevelopmentUsing QFD for Medical Device Development
Using QFD for Medical Device DevelopmentEMMAIntl
 
The Appeal and Fears of Digital Health
The Appeal and Fears of Digital HealthThe Appeal and Fears of Digital Health
The Appeal and Fears of Digital HealthEMMAIntl
 
Immune Systems After the COVID-19 Pandemic
Immune Systems After the COVID-19 PandemicImmune Systems After the COVID-19 Pandemic
Immune Systems After the COVID-19 PandemicEMMAIntl
 
Stability Testing Requirements for Pharmaceuticals
Stability Testing Requirements for PharmaceuticalsStability Testing Requirements for Pharmaceuticals
Stability Testing Requirements for PharmaceuticalsEMMAIntl
 
Staying Healthy During COVID-19
Staying Healthy During COVID-19Staying Healthy During COVID-19
Staying Healthy During COVID-19EMMAIntl
 
A History of Reproductive Health
A History of Reproductive HealthA History of Reproductive Health
A History of Reproductive HealthEMMAIntl
 
Electronic Signatures Under 21CFR§11
Electronic Signatures Under 21CFR§11Electronic Signatures Under 21CFR§11
Electronic Signatures Under 21CFR§11EMMAIntl
 
Considerations for Biocompatibility Evaluation
Considerations for Biocompatibility EvaluationConsiderations for Biocompatibility Evaluation
Considerations for Biocompatibility EvaluationEMMAIntl
 
Restoring the Earth for a Healthier Future
Restoring the Earth for a Healthier FutureRestoring the Earth for a Healthier Future
Restoring the Earth for a Healthier FutureEMMAIntl
 

More from EMMAIntl (20)

Cartilage Regeneration Techniques
Cartilage Regeneration TechniquesCartilage Regeneration Techniques
Cartilage Regeneration Techniques
 
Stability Testing of Pharmaceuticals and Supplements
Stability Testing of Pharmaceuticals and SupplementsStability Testing of Pharmaceuticals and Supplements
Stability Testing of Pharmaceuticals and Supplements
 
Intolerance vs. Allergy
Intolerance vs. AllergyIntolerance vs. Allergy
Intolerance vs. Allergy
 
Material Science in MedTech
Material Science in MedTechMaterial Science in MedTech
Material Science in MedTech
 
Investigating Ketamine for Parkinson’s Disease
Investigating Ketamine for Parkinson’s DiseaseInvestigating Ketamine for Parkinson’s Disease
Investigating Ketamine for Parkinson’s Disease
 
Aduhelm, an Accelerated Approval for Alzheimer’s
Aduhelm, an Accelerated Approval for Alzheimer’sAduhelm, an Accelerated Approval for Alzheimer’s
Aduhelm, an Accelerated Approval for Alzheimer’s
 
World Blood Donor Day 2021
World Blood Donor Day 2021World Blood Donor Day 2021
World Blood Donor Day 2021
 
New COVID-19 Vaccine
New COVID-19 VaccineNew COVID-19 Vaccine
New COVID-19 Vaccine
 
Men’s Health Week: Depression
Men’s Health Week: DepressionMen’s Health Week: Depression
Men’s Health Week: Depression
 
Celebrating Pride Month at EMMA International
Celebrating Pride Month at EMMA InternationalCelebrating Pride Month at EMMA International
Celebrating Pride Month at EMMA International
 
Growth and Integration of ML/AI in Biotech
Growth and Integration of ML/AI in BiotechGrowth and Integration of ML/AI in Biotech
Growth and Integration of ML/AI in Biotech
 
Using QFD for Medical Device Development
Using QFD for Medical Device DevelopmentUsing QFD for Medical Device Development
Using QFD for Medical Device Development
 
The Appeal and Fears of Digital Health
The Appeal and Fears of Digital HealthThe Appeal and Fears of Digital Health
The Appeal and Fears of Digital Health
 
Immune Systems After the COVID-19 Pandemic
Immune Systems After the COVID-19 PandemicImmune Systems After the COVID-19 Pandemic
Immune Systems After the COVID-19 Pandemic
 
Stability Testing Requirements for Pharmaceuticals
Stability Testing Requirements for PharmaceuticalsStability Testing Requirements for Pharmaceuticals
Stability Testing Requirements for Pharmaceuticals
 
Staying Healthy During COVID-19
Staying Healthy During COVID-19Staying Healthy During COVID-19
Staying Healthy During COVID-19
 
A History of Reproductive Health
A History of Reproductive HealthA History of Reproductive Health
A History of Reproductive Health
 
Electronic Signatures Under 21CFR§11
Electronic Signatures Under 21CFR§11Electronic Signatures Under 21CFR§11
Electronic Signatures Under 21CFR§11
 
Considerations for Biocompatibility Evaluation
Considerations for Biocompatibility EvaluationConsiderations for Biocompatibility Evaluation
Considerations for Biocompatibility Evaluation
 
Restoring the Earth for a Healthier Future
Restoring the Earth for a Healthier FutureRestoring the Earth for a Healthier Future
Restoring the Earth for a Healthier Future
 

Recently uploaded

Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...
Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...
Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...delhimodelshub1
 
Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...
Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...
Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...ggsonu500
 
Book Call Girls in Hosur - 7001305949 | 24x7 Service Available Near Me
Book Call Girls in Hosur - 7001305949 | 24x7 Service Available Near MeBook Call Girls in Hosur - 7001305949 | 24x7 Service Available Near Me
Book Call Girls in Hosur - 7001305949 | 24x7 Service Available Near Menarwatsonia7
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...Vip call girls In Chandigarh
 
Kukatpally Call Girls Services 9907093804 High Class Babes Here Call Now
Kukatpally Call Girls Services 9907093804 High Class Babes Here Call NowKukatpally Call Girls Services 9907093804 High Class Babes Here Call Now
Kukatpally Call Girls Services 9907093804 High Class Babes Here Call NowHyderabad Call Girls Services
 
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...delhimodelshub1
 
Russian Call Girls in Raipur 9873940964 Book Hot And Sexy Girls
Russian Call Girls in Raipur 9873940964 Book Hot And Sexy GirlsRussian Call Girls in Raipur 9873940964 Book Hot And Sexy Girls
Russian Call Girls in Raipur 9873940964 Book Hot And Sexy Girlsddev2574
 
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...High Profile Call Girls Chandigarh Aarushi
 
Call Girls Gurgaon Parul 9711199012 Independent Escort Service Gurgaon
Call Girls Gurgaon Parul 9711199012 Independent Escort Service GurgaonCall Girls Gurgaon Parul 9711199012 Independent Escort Service Gurgaon
Call Girls Gurgaon Parul 9711199012 Independent Escort Service GurgaonCall Girls Service Gurgaon
 
Russian Call Girls in Goa Samaira 7001305949 Independent Escort Service Goa
Russian Call Girls in Goa Samaira 7001305949 Independent Escort Service GoaRussian Call Girls in Goa Samaira 7001305949 Independent Escort Service Goa
Russian Call Girls in Goa Samaira 7001305949 Independent Escort Service Goanarwatsonia7
 
Leading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsLeading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsHelenBevan4
 
Call Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any TimeCall Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any Timedelhimodelshub1
 
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in LucknowRussian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknowgragteena
 
Call Girls Hyderabad Krisha 9907093804 Independent Escort Service Hyderabad
Call Girls Hyderabad Krisha 9907093804 Independent Escort Service HyderabadCall Girls Hyderabad Krisha 9907093804 Independent Escort Service Hyderabad
Call Girls Hyderabad Krisha 9907093804 Independent Escort Service Hyderabaddelhimodelshub1
 
Call Girls Madhapur 7001305949 all area service COD available Any Time
Call Girls Madhapur 7001305949 all area service COD available Any TimeCall Girls Madhapur 7001305949 all area service COD available Any Time
Call Girls Madhapur 7001305949 all area service COD available Any Timedelhimodelshub1
 

Recently uploaded (20)

Call Girls in Lucknow Esha 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
Call Girls in Lucknow Esha 🔝 8923113531  🔝 🎶 Independent Escort Service LucknowCall Girls in Lucknow Esha 🔝 8923113531  🔝 🎶 Independent Escort Service Lucknow
Call Girls in Lucknow Esha 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
 
Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...
Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...
Russian Call Girls in Hyderabad Ishita 9907093804 Independent Escort Service ...
 
Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...
Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...
Gurgaon Sector 90 Call Girls ( 9873940964 ) Book Hot And Sexy Girls In A Few ...
 
Book Call Girls in Hosur - 7001305949 | 24x7 Service Available Near Me
Book Call Girls in Hosur - 7001305949 | 24x7 Service Available Near MeBook Call Girls in Hosur - 7001305949 | 24x7 Service Available Near Me
Book Call Girls in Hosur - 7001305949 | 24x7 Service Available Near Me
 
College Call Girls Dehradun Kavya 🔝 7001305949 🔝 📍 Independent Escort Service...
College Call Girls Dehradun Kavya 🔝 7001305949 🔝 📍 Independent Escort Service...College Call Girls Dehradun Kavya 🔝 7001305949 🔝 📍 Independent Escort Service...
College Call Girls Dehradun Kavya 🔝 7001305949 🔝 📍 Independent Escort Service...
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
 
Kukatpally Call Girls Services 9907093804 High Class Babes Here Call Now
Kukatpally Call Girls Services 9907093804 High Class Babes Here Call NowKukatpally Call Girls Services 9907093804 High Class Babes Here Call Now
Kukatpally Call Girls Services 9907093804 High Class Babes Here Call Now
 
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
 
Russian Call Girls in Raipur 9873940964 Book Hot And Sexy Girls
Russian Call Girls in Raipur 9873940964 Book Hot And Sexy GirlsRussian Call Girls in Raipur 9873940964 Book Hot And Sexy Girls
Russian Call Girls in Raipur 9873940964 Book Hot And Sexy Girls
 
VIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service Lucknow
VIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service LucknowVIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service Lucknow
VIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service Lucknow
 
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
 
Call Girls Guwahati Aaradhya 👉 7001305949👈 🎶 Independent Escort Service Guwahati
Call Girls Guwahati Aaradhya 👉 7001305949👈 🎶 Independent Escort Service GuwahatiCall Girls Guwahati Aaradhya 👉 7001305949👈 🎶 Independent Escort Service Guwahati
Call Girls Guwahati Aaradhya 👉 7001305949👈 🎶 Independent Escort Service Guwahati
 
Call Girls Gurgaon Parul 9711199012 Independent Escort Service Gurgaon
Call Girls Gurgaon Parul 9711199012 Independent Escort Service GurgaonCall Girls Gurgaon Parul 9711199012 Independent Escort Service Gurgaon
Call Girls Gurgaon Parul 9711199012 Independent Escort Service Gurgaon
 
Russian Call Girls in Goa Samaira 7001305949 Independent Escort Service Goa
Russian Call Girls in Goa Samaira 7001305949 Independent Escort Service GoaRussian Call Girls in Goa Samaira 7001305949 Independent Escort Service Goa
Russian Call Girls in Goa Samaira 7001305949 Independent Escort Service Goa
 
Leading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsLeading transformational change: inner and outer skills
Leading transformational change: inner and outer skills
 
Call Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any TimeCall Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any Time
 
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in LucknowRussian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
 
Call Girls Hyderabad Krisha 9907093804 Independent Escort Service Hyderabad
Call Girls Hyderabad Krisha 9907093804 Independent Escort Service HyderabadCall Girls Hyderabad Krisha 9907093804 Independent Escort Service Hyderabad
Call Girls Hyderabad Krisha 9907093804 Independent Escort Service Hyderabad
 
Call Girls Madhapur 7001305949 all area service COD available Any Time
Call Girls Madhapur 7001305949 all area service COD available Any TimeCall Girls Madhapur 7001305949 all area service COD available Any Time
Call Girls Madhapur 7001305949 all area service COD available Any Time
 
Call Girl Dehradun Aashi 🔝 7001305949 🔝 💃 Independent Escort Service Dehradun
Call Girl Dehradun Aashi 🔝 7001305949 🔝 💃 Independent Escort Service DehradunCall Girl Dehradun Aashi 🔝 7001305949 🔝 💃 Independent Escort Service Dehradun
Call Girl Dehradun Aashi 🔝 7001305949 🔝 💃 Independent Escort Service Dehradun
 

GDPR in the Healthcare Industry

  • 1. www.emmainternational.com GDPR in Healthcare Industry Need, Strategy, Implementation and continuous monitoring Joseph Yammine, EMEA Director Joseph.Yammine@emmainternational.com
  • 2. Leaders in Compliance Consulting and Enterprise Quality Management Software • EMMA International Consulting Group, Inc. is a global leader in management consulting services, with headquarters in Farmington Hills, MI, as well as offices in Grand Rapids, MI, FL, PA, and Beirut, Lebanon. We focus on quality, regulatory, and compliance services for the medical device industries.
  • 3. Data, Data, Data, Data, … • 1992 – 100 GB of data generated on daily basis • 1997 – 100 GB of data generated on hourly basis • 2002 – 100 GB of data generated on per second basis • 2018 – 50,000 GB per second 90% of all the data in the world today has been created in the past few years
  • 4. Data, Data, Data, Data, … 2018 This is what happens in an INTERNET MINUTE
  • 5. Data, Data, Data and Data According to the 2017 Ponemon Institute Study, What Is the Cost of a Data Breach in the Healthcare Industry? A. $2.2 Billion B. $3.6 Billion C. $4.0 Billion D. $6.2 Billion The Answer is D
  • 6. Healthcare Data Breaches are Costly… • When a healthcare organization experiences a breach, forensics costs added up to $610,000. • Breach notification costs $560,000 on average. • Costs affiliated with lawsuits average $880,000. • For each data breach, healthcare organizations average $3.7 million in lost revenue. • Healthcare organizations average $500,000 in lost brand value after a breach. • The average HIPAA settlement fine is approximately $1.1 million. • Post-breach cleanup costs average $440,000.
  • 7. Healthcare Data Breaches in Q3: 2018 • The first three months of 2018 have seen 77 healthcare data breaches reported to the Department of Health and Human Services’ Office for Civil Rights (OCR). • Those breaches have impacted more than one million patients and health plan members • Almost twice the number of individuals that were impacted by healthcare data breaches in Q4, 2017. • Between January 1 and March 31, 2018, 1,073,766 individuals had their PHI exposed, viewed, or stolen compared to 520,141 individuals in Q4, 2017.
  • 8. What we will cover today? • What is personal data – and why it’s important for us • What is Data Protection • GDPR - what’s changing and what it’s all about • GDPR Principles • Who this will affect • How to be ready • What support is available
  • 9. What we will cover today?
  • 10. What is Personal Data? • Personal data is defined as: • Any information about a living individual which is capable of identifying that individual. • Sensitive personal data is defined as: • Any information relating to an individual's racial or ethnic origin, political opinions, religious beliefs, trade union membership, physical or mental health or condition, sexual life, alleged or actual criminal activity and criminal record. Under GDPR sensitive personal data is referred to as “special categories of personal data”)
  • 12. What is Personal Data?  Special Categories:  Race / Ethnic origin  Political opinions  Religious or similar beliefs  Union  Physical / Mental health  Sexual life  Alleged / Actual offences / Information
  • 13. What is Data Protection? Data Protection is about avoiding harm to individuals by misusing or mismanaging their personal data. So if you collect, use, or store personal data then the Data Protection Act applies to you. It sets out eight principles you have to adhere to, which include: • Only collect information for specific purposes and don’t then use it for other purposes • Only collect what you need for the specific purpose • Keep it accurate and up to date; and safe and secure • Process information lawfully and allow subject access in line with the Act.
  • 14. What is GDPR? It is the General Data Protection Regulation, which supersedes the Data Protection Act on 25th May 2018. The key changes from the current law are to strengthen rights of individuals and place more obligations on organisations in looking after personal data. In order to comply with the new law: • You must have a legitimate reason for processing data – this will cover much processing we undertake (see later slide) • Consent must be freely and unambiguously given and can be just as easily withdrawn • Data Processing activities must start with “privacy by design and default”.
  • 15. What is GDPR?... continued • Subject Access Requests – will include how you process and share data not just what you hold and you’ll have less time to respond • Subjects can request data deletion – “the right to be forgotten”, though only in certain circumstances • There will be mandatory breach reporting • Data processors will be held liable • You must be able to demonstrate compliance with GDPR • While the ICO say it is a last resort, the potential fines are much greater than at present – up to 4% of annual global turnover or €20m • And finally – it’s happening regardless of Brexit!
  • 16. Why the GDPR? • We care - we are responsible for handling people’s most personal information • This is an opportunity to make privacy central to what we do • By not handling personal data properly we could put individuals at risk and the company / organization reputation at stake • Getting it wrong could result in significant fines • We need robust systems and processes in place to make sure we use personal information properly and comply
  • 17. Who does this affect? • All of us - we all have a responsibility to keep people’s information safe; main industries are healthcare, banking and educational organizations • Particularly those involved in: • Human Resources • Research & Development • Research involving personal data and/or human participants • Finance • Information Technology
  • 18. Who does this affect?
  • 19. GDPR Principles • Lawfulness, fairness and transparency – as with Data Protection • Purpose limitation – only collect for specific purposes and then don’t use it for other purposes • Data minimisation – only collect the data you need for the purpose you are using it • Accuracy – as now, keep it up to date! • Storage limitation – don’t keep it for longer than you need to fulfil the purpose • Integrity and confidentiality – keep it safe and secure e.g. encrypted if on a laptop or mobile phone. • Accountability – you must be able to prove you have complied with the above.
  • 20. GDPR Principles Examples of Processing  Staff management and payroll administration  Access to/consultation of a contacts database containing personal data  Sending promotional emails  Shredding documents containing personal data  Posting a photo of a person on a website  Storing IP addresses or MAC addresses  Video recording (CCTV)
  • 21. GDPR Principles Subjects’ rights  Confirmation of processing  Purposes of processing  Rectification  Erasure (Right to be forgotten)  Restriction of processing  Portability  Access to data
  • 25. Preparation for GDPR 1. Audit Data Usage  What?  Why?  Where?  Who?  How
  • 26. Preparation for GDPR 1. Audit Data Usage  Legal Basis for processing personal data:  Legal obligation  Contract  Consent  Vital interests (of data subject)  Necessary in public interest  Legitimate interests (of the Controller
  • 27. Preparation for GDPR 1. Audit Data Usage  Data Security:  Of paper records  Physical access to data  Locks / doors  Security guards  Etc.  Technological security  Firewall  Anti-virus  Software updates  Etc.
  • 28. Preparation for GDPR 1. Audit Data Usage  Data Security:  Data protection policy  IT Security policy  Breach procedure / Log  Subject access request procedure  Privacy notice(s) / collection notices (mandatory)  Training programme and log  Data protection impact assessments (mandatory)
  • 29. Preparation for GDPR 1. Audit Data Usage  Data Security: Check your contracts with data processors  Contracts include data protection clauses  Compliance with GPDR  Security is up-to-date / in place  Procedures and policies are to your satisfaction  Will alert you to problems  Right to audit?
  • 30. Preparation for GDPR 2. Data Protection Officer  Do you need one?  Public authority or body  Large scale processing operations which by their nature require regular systematic monitoring of data subjects  Core activities involves large scale processing of special categories of personal data and data relating to criminal convictions and offences  The Role:  To be involved in issues relating to protection of personal data  Expert knowledge of data protection  Not be instructed
  • 31. Preparation for GDPR 2. Data Protection Officer  Important Notes  It’s all important!  Security –  IT / technology  Physical  Basis for processing  Data protection impact assessments  Breach notifications  Subject access requests  Register with the ICO (Information Commissioner)
  • 32. Preparation for GDPR 3. Data Processing (Article 4.2)  Collecting  Recording  Organising  Structuring  Storing  Adapting  Altering  Retrieving  Consulting  Using  Disclosing  Disseminating  Aligning or combining  Restricting  Erasing  Destroying
  • 33. Preparation for GDPR 3. Data Processing (Article 4.2)
  • 34. Preparation for GDPR 4. Consenting Process “the data subject has given consent to the processing of his or her personal data for one or more specific purposes  Consent  must be freely given, specific, informed and unambiguous;  by a statement or a clear affirmative action;  cannot be inferred by silence, pre-ticked boxes or inactivity  can be withdrawn and it must be easy to do so  Processing of sensitive personal data requires “explicit consent”  Records must be kept of how and when consent was given
  • 35. Preparation for GDPR 5. Demonstrating Accountability  Internal policies and procedures (data protection / retention policy; security and data breach; data subject rights)  External privacy notice(s)  Internal compliance measures and external controls  Maintain records of data processing activities  Steps when engaging data processors  Undertake regular staff training  Review and update policies and procedures on ongoing basis  Internal audit of processing activities  Appoint a Data Protection Officer (DPO), where appropriate.  Data Protection Impact Assessments, where appropriate  Data protection by design and by default
  • 36. Preparation for GDPR 6. Data Breach Reporting  Personal data breach – a security breach leading to “the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”  Data controller must notify a personal data breach to the supervisory authority (DPC) within 72 hours of becoming aware of it.  If notified later, must give reasons for the delay.  Notification requires certain minimum information.  In “high-risk” cases may have to inform affected individuals.  Notification not required where the breach is unlikely to result in a risk to the rights of individuals.  Data controller must document any personal data breach, including the facts, its effects and remedial action taken
  • 37. What do I and my team need to do?
  • 38. Key GDPR Take Away  Requires a shift in culture and mindset about people’s data privacy  It’s principles-based and risk-based  Collecting, using and securing personal data has a cost  Individuals have more control, with new and enhanced rights  Privacy notices need more information and must be clear and concise  Processing requires a legal basis and must comply with the 6 principles  Data controllers must be able to demonstrate their accountability  Review how you get, record and manage consent  Data processor contracts and liability issues  Decide if a DPO required, and document this. At minimum, appoint a lead.  Be aware of increased regulatory sanctions and powers.  Review your IT systems and security  Everyone needs a data breach plan
  • 39. Thank You For further information, please do not hesitate to contact us Joseph.Yammine@emmainternational.com
  • 40. Farmington Hills, MI: Headquarters 27600 Farmington Rd., Suite 100 Farmington Hills, MI 48334 Phone (248) 987-4497 York, PA: 320 Busser Road., Suite 200 Emigsville, PA 17318 Phone (717) 429-6875 Clearwater, FL: 28870 US HWY 19 North, Suite 300 Clearwater, FL 33761 Phone (727) 614-8851 Lebanon 7TH Floor, Le Mall Building, Dbayeh Highway, Northern Metn, Lebanon Grand Rapids, MI: 250 Monroe NW Suite 400 Grand Rapids, MI 49503 (616) 219-0510

Editor's Notes

  1. A Quick reminder - What is personal data? This often causes confusion – often people think it is simply a name and address. The law defines personal data as - Any information about a living individual which is capable of identifying that individual. The law additionally defines an extra data set which need more and better protection - Sensitive personal data  And that is - Any information relating to an individual's racial or ethnic origin, political opinions, religious beliefs, trade union membership, physical or mental health or condition, sexual life, alleged or actual criminal activity and criminal record. It doesn’t matter if that data is already in the public domain – you still have to comply with the DPA in the way in which you collect, use and store it. GDPR stretches this further and for example says that an IP address can be personal data – for the less technical among us (and that includes me) an IP address is Internet Protocol address and it is used to identify computers communicating via the internet. So if you’ve ever wondered why the ads around web pages you view are so closely related to what you recently searched for (a new sofa, flights to Italy….). Of course they may be related to what another family member has been searching for…. In summary – the definition is far broader than “name and address”.
  2. Name and surname Home address Email address such as name.surname@company.com Identification card number Location data (i.e., the location data function on a mobile #) Internet Protocol (IP) address: 10.10.103.456 Cookie ID* The advertising identifier of your phone Data held by a hospital or doctor, which could be a symbol that uniquely identifies a person
  3. So, a quick re-cap of the Data Protection Act – Data Protection is about preventing harm to individuals by misusing or failing to look after their personal data. It applies to ALL organisations in the UK through the Data Protection Act (DPA). So, if you collect, use, store personal data then the law applies to you. There are eight governing principles but I have summarised them here as: Only collect personal data for specific purposes and then only use it for those purposes. Collect just the data you need for the purpose and keep it accurate and up to date; and don’t keep it for longer than is necessary for the completion of the purpose for which it was collected. You will need consent from data subjects to process their data. You will also have to register with the Information Commissioner’s Office (ICO) as a data controller – whether you know it or not you already have ! Typically dioceses have registered in the name of the DBF; Bishops in the name of the Bishop in his or her corporate capacity and Cathedrals, the Dean and Chapter. This is a public register – you can search it via the ICO Keep the data securely whether paper or electronic. Avoid storing it outside the European Economic Area – might be an issue if your electronic data is in the cloud.  Finally, be aware of the rights of subjects to access certain data you hold about them through a Subject Access Request (SAR). Note that this does NOT necessarily mean that they can see everything you hold about them – seek advice from your registrar whenever you get a SAR.
  4. The GDPR is the most significant overhaul of data protection law in 20 years. The GDPR replaces the Data Protection Directive (Directive 95/46/EC) and thus the DPA 1998 and subordinate legislation under it. The GDPR came into force on 24 May 2016. However, due to its two-year implementation period, the GDPR will only be applicable from 25 May 2018. Builds on existing data protection rules and principles, with significant changes - increased compliance obligations for businesses and organisations - new and enhanced rights for individuals - increased regulatory powers and sanctions - Privacy by design and default
  5. 173 Recitals (not having force of law) 11 Chapters 99 Articles (having full force of law)
  6. Human Resources: All function including screening, recruitment, employment, healthcare management, assessment, personnel, etc.
  7. The law requires that in certain circumstances organisations must have a named Data Protection Officer (DPO). One of these is where there is large scale processing of “special categories of personal data”. The DPO has an education and compliance role regarding GDPR and is the first point of contact for the wider world. They must report to a senior level in the organisation and be independent – so similar to Internal Audit.
  8. First of all don’t panic! If you are complying with the Data Protection Act then you are well on the way to GDPR compliance – few steps are needed! Secondly, dust off your departmental Information Directory (which was compiled a few years ago Lists all the sensitive and confidential data you hold Check that it is up to date The Records Management team will be in touch in the new year to start working through what you and your team will need to do to prepare for GDPR compliance.