SlideShare a Scribd company logo
1 of 29
Download to read offline
General Data Protection Regulation
May 2017, London
Welcome
Join in today with sli.do
• type sli.do into your browser bar
• enter the conference code # and BJ_GDPR17
then ‘join’
• click on the seminar event box
• use the tabs to ask questions or take part in polls.
No download
required
Join in with sli.do
Question:
Which statement best describes your organisation’s readiness for
GDPR?
• We have not taken any steps
• We have started planning for GDPR
• We have a high level plan in place
• We are proceeding with a highly detailed plan
• We are ready for GDPR
Join in with sli.do
Question:
Who is preparing your organisation for GDPR?
• In-house resource
• Accountancy firm
• Data protection consultant
• Law firm
• Other
Join in with sli.do
Question:
What is the most significant hurdle your organisation faces in
preparing for GDPR?
• Lack of awareness/training
• Lack of budget/team
• Organisation/system complexity
• Lack of legal certainty
• Lack of senior management buy-in
• Other
Today
• Understand the obligations
• Set out a roadmap to compliance
• Practical advice and real-life examples
Beware!
GDPR
• Probably the most lobbied piece of EU law ever
• Replaces the Data Protection Directive 1995 (DPD)
• Will be enforced in Member States from 25 May
2018
• EU Member State laws implementing the DPD will
no longer apply
• Creates a level-ish playing field across EU
• Will apply post-Brexit
Data governance structure
• Who should be responsible?
– Art. 27
• Do you need a DPO?
– Art. 37 and 38
– Working party guidance
Map data and data flows
• Review and record in writing all processing
activities
– Art. 30
– 250 employee exemption
• Record international transfers and mechanism
– Art. 45 to 49
Records of Processing
Policies
• Map legal obligations
• Convert obligations into policies and procedures
• Embed into business operations
Data protection policies
• Policy
– Art. 24
– Organisation wide
– Employee
– Customer
• Maintain
Notices
• Data privacy notices
– Art. 12-14
• Provide notices to data subjects
– Art. 13-14 and 21
• Maintain
Securing data and information
• Assess security risk
• Update information security and policy
– Art. 5 and 32
• Maintain security measures
Relationships with third parties
• Assess third party relationships
– Group
– Customers
– Partners
– Processors
– Art. 28, 29 and 32
• Appropriate contracts and controls
• Undertake due diligence and audits
Complying with individuals’
rights
• Complaint management
• Requests for information
– Art. 12
• Withdrawal of consent
– Art. 7
• Subject access
– Art. 15
Complying with individuals’
rights
• Rectification
– Art. 16 and 19
• Erasure (RTBF)
– Art. 17 and 19
• Restriction on processing
– Art. 18 and 19
• Data portability
– Art. 20
Privacy practices
• Privacy by design
– Art. 25
• Privacy impact assessments
– Art. 35
• Integrate, maintain and conduct
• Consultation with supervisory authorities
– Art. 36
Practical considerations
• Who will carry out the DPIA?
• Who identifies the need for a DPIA?
• What’s the process?
• How is this documented?
• Who signs off the DPIA?
Breach
• Personal data breach – Art. 4(12)
• Other breaches
• Incident plan
• Breach notification
– Controller to individuals – Art. 34
– Controller to supervisory authority – Art. 33
– Processor to controller – Art. 33
• Document breaches – Art. 33
Maintain accountability
• Continuous assessment
– Art. 25 and 39
• Maintain evidence
– Art. 5 and 24
• Monitor legal developments
Roadmap
How we can help
Thank you
Mark Gleeson – 0207 871 8534
mark.gleeson@brownejacobson.com
Helena Wootton – 0115 976 6108
helena.wootton@brownejacobson.com
All information correct at time of production.
The information and opinions expressed within this
document are no substitute for full legal advice. It is for
guidance only and illustrates the law as at the published
date. If in doubt, please telephone us on 0370 270 6000.
© Browne Jacobson LLP 2017 – The information contained
within this document is and shall remain the property of
Browne Jacobson. This document may not be reproduced
without the prior consent of Browne Jacobson.

More Related Content

What's hot

TLG Keep Your Head IN the Cloud Webinar (05-05-15)
TLG Keep Your Head IN the Cloud Webinar (05-05-15)TLG Keep Your Head IN the Cloud Webinar (05-05-15)
TLG Keep Your Head IN the Cloud Webinar (05-05-15)
Neil Ende
 
Energy Data Privacy Presentation
Energy Data Privacy PresentationEnergy Data Privacy Presentation
Energy Data Privacy Presentation
Brian Orion
 

What's hot (17)

Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow Mapping
 
Game changing legislation
Game changing legislationGame changing legislation
Game changing legislation
 
GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOU
 
Data breaches, privacy programs and what will change for processors
Data breaches, privacy programs and what will change for processorsData breaches, privacy programs and what will change for processors
Data breaches, privacy programs and what will change for processors
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
 
TLG Keep Your Head IN the Cloud Webinar (05-05-15)
TLG Keep Your Head IN the Cloud Webinar (05-05-15)TLG Keep Your Head IN the Cloud Webinar (05-05-15)
TLG Keep Your Head IN the Cloud Webinar (05-05-15)
 
Data privacy impact assessment
Data privacy impact assessmentData privacy impact assessment
Data privacy impact assessment
 
Energy Data Privacy Presentation
Energy Data Privacy PresentationEnergy Data Privacy Presentation
Energy Data Privacy Presentation
 
IBM Domino security in a GDPR world
IBM Domino security in a GDPR worldIBM Domino security in a GDPR world
IBM Domino security in a GDPR world
 
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
 
SAP Business One
SAP Business OneSAP Business One
SAP Business One
 
How to Maintain Biometric Privacy & Avoid Liability With Confidence
How to Maintain Biometric Privacy & Avoid Liability With ConfidenceHow to Maintain Biometric Privacy & Avoid Liability With Confidence
How to Maintain Biometric Privacy & Avoid Liability With Confidence
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
ICANN Contract vs National Law
ICANN Contract vs National LawICANN Contract vs National Law
ICANN Contract vs National Law
 

Similar to General Data Protection Regulation, May 2017, London

GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
IBB Law
 

Similar to General Data Protection Regulation, May 2017, London (20)

#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
ABCON-AGM-2021-Final-2.pptx
ABCON-AGM-2021-Final-2.pptxABCON-AGM-2021-Final-2.pptx
ABCON-AGM-2021-Final-2.pptx
 

More from Browne Jacobson LLP

More from Browne Jacobson LLP (20)

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham session
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019
 
Health tech slides 12 june 2019
Health tech slides   12 june 2019Health tech slides   12 june 2019
Health tech slides 12 june 2019
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - Birmingham
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019
 
In House Lawyers, March 2019
In House Lawyers, March 2019In House Lawyers, March 2019
In House Lawyers, March 2019
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, Manchester
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, Nottingham
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...
 

Recently uploaded

Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
yogita9398
 
Article 12 of the Indian Constitution law
Article 12 of the Indian Constitution lawArticle 12 of the Indian Constitution law
Article 12 of the Indian Constitution law
yogita9398
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
Airst S
 
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
trryfxkn
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
Airst S
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
Airst S
 
一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样
一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样
一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样
doypbe
 

Recently uploaded (20)

ORane M Cornish affidavit statement for New Britain court proving Wentworth'...
ORane M Cornish affidavit statement  for New Britain court proving Wentworth'...ORane M Cornish affidavit statement  for New Britain court proving Wentworth'...
ORane M Cornish affidavit statement for New Britain court proving Wentworth'...
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
 
Article 12 of the Indian Constitution law
Article 12 of the Indian Constitution lawArticle 12 of the Indian Constitution law
Article 12 of the Indian Constitution law
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 
The Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in GreeceThe Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in Greece
 
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdfposts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptx
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
OVERVIEW OF LABOUR LAWS with Case Studies- ppt.ppt
OVERVIEW OF LABOUR LAWS with Case Studies- ppt.pptOVERVIEW OF LABOUR LAWS with Case Studies- ppt.ppt
OVERVIEW OF LABOUR LAWS with Case Studies- ppt.ppt
 
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
 
Dematerialisation of securities of private companies
Dematerialisation of securities of private companiesDematerialisation of securities of private companies
Dematerialisation of securities of private companies
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
 
Chambers Global Practice Guide - Canada M&A
Chambers Global Practice Guide - Canada M&AChambers Global Practice Guide - Canada M&A
Chambers Global Practice Guide - Canada M&A
 
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy NovicesIt’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
 
一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样
一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样
一比一原版(UC Davis毕业证书)加州大学戴维斯分校毕业证原件一模一样
 

General Data Protection Regulation, May 2017, London

  • 1. General Data Protection Regulation May 2017, London
  • 2. Welcome Join in today with sli.do • type sli.do into your browser bar • enter the conference code # and BJ_GDPR17 then ‘join’ • click on the seminar event box • use the tabs to ask questions or take part in polls. No download required
  • 3. Join in with sli.do Question: Which statement best describes your organisation’s readiness for GDPR? • We have not taken any steps • We have started planning for GDPR • We have a high level plan in place • We are proceeding with a highly detailed plan • We are ready for GDPR
  • 4. Join in with sli.do Question: Who is preparing your organisation for GDPR? • In-house resource • Accountancy firm • Data protection consultant • Law firm • Other
  • 5. Join in with sli.do Question: What is the most significant hurdle your organisation faces in preparing for GDPR? • Lack of awareness/training • Lack of budget/team • Organisation/system complexity • Lack of legal certainty • Lack of senior management buy-in • Other
  • 6. Today • Understand the obligations • Set out a roadmap to compliance • Practical advice and real-life examples
  • 8. GDPR • Probably the most lobbied piece of EU law ever • Replaces the Data Protection Directive 1995 (DPD) • Will be enforced in Member States from 25 May 2018 • EU Member State laws implementing the DPD will no longer apply • Creates a level-ish playing field across EU • Will apply post-Brexit
  • 9. Data governance structure • Who should be responsible? – Art. 27 • Do you need a DPO? – Art. 37 and 38 – Working party guidance
  • 10.
  • 11. Map data and data flows • Review and record in writing all processing activities – Art. 30 – 250 employee exemption • Record international transfers and mechanism – Art. 45 to 49
  • 12.
  • 14. Policies • Map legal obligations • Convert obligations into policies and procedures • Embed into business operations
  • 15. Data protection policies • Policy – Art. 24 – Organisation wide – Employee – Customer • Maintain
  • 16. Notices • Data privacy notices – Art. 12-14 • Provide notices to data subjects – Art. 13-14 and 21 • Maintain
  • 17. Securing data and information • Assess security risk • Update information security and policy – Art. 5 and 32 • Maintain security measures
  • 18. Relationships with third parties • Assess third party relationships – Group – Customers – Partners – Processors – Art. 28, 29 and 32 • Appropriate contracts and controls • Undertake due diligence and audits
  • 19. Complying with individuals’ rights • Complaint management • Requests for information – Art. 12 • Withdrawal of consent – Art. 7 • Subject access – Art. 15
  • 20. Complying with individuals’ rights • Rectification – Art. 16 and 19 • Erasure (RTBF) – Art. 17 and 19 • Restriction on processing – Art. 18 and 19 • Data portability – Art. 20
  • 21. Privacy practices • Privacy by design – Art. 25 • Privacy impact assessments – Art. 35 • Integrate, maintain and conduct • Consultation with supervisory authorities – Art. 36
  • 22. Practical considerations • Who will carry out the DPIA? • Who identifies the need for a DPIA? • What’s the process? • How is this documented? • Who signs off the DPIA?
  • 23.
  • 24. Breach • Personal data breach – Art. 4(12) • Other breaches • Incident plan • Breach notification – Controller to individuals – Art. 34 – Controller to supervisory authority – Art. 33 – Processor to controller – Art. 33 • Document breaches – Art. 33
  • 25. Maintain accountability • Continuous assessment – Art. 25 and 39 • Maintain evidence – Art. 5 and 24 • Monitor legal developments
  • 27. How we can help
  • 28. Thank you Mark Gleeson – 0207 871 8534 mark.gleeson@brownejacobson.com Helena Wootton – 0115 976 6108 helena.wootton@brownejacobson.com
  • 29. All information correct at time of production. The information and opinions expressed within this document are no substitute for full legal advice. It is for guidance only and illustrates the law as at the published date. If in doubt, please telephone us on 0370 270 6000. © Browne Jacobson LLP 2017 – The information contained within this document is and shall remain the property of Browne Jacobson. This document may not be reproduced without the prior consent of Browne Jacobson.