SlideShare a Scribd company logo
Host: Robert Parker, Head of Communications
Presenter: Richard Syers, Senior Policy Officer
richard.syers@ico.org.uk
Data Protection
for
small and
medium-sized
enterprises
Freedom of
Information Act
2000
Environmental
Information
Regulations 2004
Upholding information rights in the public interest,
promoting openness by public authorities and data privacy
for individuals
Data Protection Act
1998
Privacy and
Electronic
Communications
(EC Directive)
Regulations 2003
…data which relate to a living
individual who can be identified –
(a) from those data, or
(b) from those data and other
information which is in the possession
of, or is likely to come into the
possession of, the data controller
Personal data
Data Protection Act 1998:
principles for processing
personal data
 Fairly and lawfully
 For specified, limited
purposes
 Adequate, relevant and not
excessive
 Accurate and kept up to date
 Not kept for longer than
necessary
 Processed in accordance with
individual’s rights
 Protected by appropriate
security
 Not transferred outside EEA
without adequate protection
Fairness, transparency and proportionality
 Clearly tell individuals what personal data you are collecting
and why
 Make sure you have a legal basis to process personal data
 Only collect what you need
“Artists-impressions-of-Lady-Justice, (statue on the Old Bailey, London)” by Lonpicman is licensed under CC BY-SA
Privacy notice
 What information is being
collected?
 Who is collecting it?
 How is it collected?
 Why is it being collected?
 How will it be used?
 Who will it be shared with?
ico.org.uk/for-organisations/guide-to-data-
protection/privacy-notices-transparency-and-
control/
Data quality
 Accurate and up to date
 Relevant
 Not excessive
 Not kept for longer than necessary
Security
 Appropriate physical security
 Appropriate electronic security
 Encryption
 Keep secure, regular backups
Get the basics right
 Train your staff
 Physical security
 Access control
 Encrypt portable devices
 Back up your data
 Cyber Essentials
ico.org.uk/media/for-organisations/documents/1575/it_security_practical_guide.pdf
https://www.cyberaware.gov.uk/cyberessentials/
Individual’s Rights
 Access personal data
 Prevent direct marketing
 Prevent processing of personal data
 Rectify, block, erase or destroy inaccurate data
 Object to automatic decision making
 Claim compensation
What if someone asks
for their information?
 Respond within 40 calendar
days
 Can ask for :
 Proof of identification
 Further information to locate
the data requested
 Fee of up to £10 in most
cases
 Must ask for these things
promptly
 Exemptions in certain
circumstances
https://ico.org.uk/for-organisations/guide-to-
data-protection/principle-6-rights/subject-
access-request/
Direct Marketing
• Privacy and Electronic Communications
Regulations
• Different rules for different channels
• Respect peoples choices
• Marketing directed at an individual
• Section 11 applies to all direct marketing
• Must comply immediately with a section 11
request in most cases
What are the rules for
electronic marketing?
Most common forms of marketing:
Can make telephone calls without
consent, unless the number is registered
with the TPS or the subscriber has asked
you not to call the number for marketing
purposes.
Must have subscribers’ prior consent
before sending electronic marketing
messages (e.g. SMS, email) unless the
“soft opt-in” applies.
Must have subscriber’s consent to make an
automated call.
https://ico.org.uk/for-organisations/guide-to-
data-protection/principle-6-rights/preventing-
direct-marketing/
DPA self assessment toolkit
DPA self assessment toolkit
Guidance for
small businesses
ico.org.uk/for-organisations/business/
Registering with the ICO
 Public register of data controllers
 Legal requirement if processing personal data
electronically
 Costs £35 per year for most organisations
 Charities, small occupational pensions schemes and
organisations that have been in existence for less than
one month all pay £35 regardless of size or turnover
 Failing to notify when not exempt, or to keep
registration up to date, is a criminal offence
Registering with the ICO
Do I need to register?
Online self assessment
ico.org.uk/for-organisations/register/self-assessment
The future of data protection
General Data Protection Regulation (GDPR)
 Same basic principles as current DP law, but
strengthened
 Accountability
 New rights for individuals, and strengthening of
existing rights
 Breach reporting
 Data Protection Impact Assessments
 Higher penalties for non-compliance
ico.org.uk/for-organisations/data-protection-reform/
@iconews
Any Questions?
Helpline: 0303 123 1113
Keep in touch by subscribing to our e-newsletter at
www.ico.org.uk or find us on…

More Related Content

What's hot

Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
Robert MacLean
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
IAB Europe
 
EU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection ChangesEU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection Changes
The International Business Structuring Association
 
IT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual PropertyIT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual Property
Charles Mok
 
3e - Data Protection
3e - Data Protection3e - Data Protection
3e - Data ProtectionMISY
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
Karel Holst
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
Karel Holst
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
legalPadmin
 
Overview of the_data_protection-act
Overview of the_data_protection-actOverview of the_data_protection-act
Overview of the_data_protection-act
RodamaeLBaccay
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
joshquarrie
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
Rachel Aldighieri
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
Tim Hyman LLB
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Werksmans Attorneys
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
Rachel Aldighieri
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection ActYizi
 
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
Fife Centre for Equalities
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal Information
Francois Naude Jr.
 
Data Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesData Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud Services
Amazon Web Services
 

What's hot (19)

Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
POPI Seminar FINAL
POPI Seminar FINALPOPI Seminar FINAL
POPI Seminar FINAL
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
 
EU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection ChangesEU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection Changes
 
IT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual PropertyIT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual Property
 
3e - Data Protection
3e - Data Protection3e - Data Protection
3e - Data Protection
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
Overview of the_data_protection-act
Overview of the_data_protection-actOverview of the_data_protection-act
Overview of the_data_protection-act
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal Information
 
Data Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesData Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud Services
 

Similar to Ico sme-webinar-slides-090217

Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
Wynthorpe
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11mrmwood
 
An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014Rachel Aldighieri
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
Data Protection Guidelines
Data Protection GuidelinesData Protection Guidelines
Data Protection Guidelines
David Scanlon
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
CharityComms
 
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake Morgan
 
An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014Rachel Aldighieri
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
Tech Trust
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
Rachel Aldighieri
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
Cliff Ashcroft
 
Chap 4 (1)
Chap 4 (1)Chap 4 (1)
Research and The Law
Research and The LawResearch and The Law
Research and The Law
Michael Bromby
 
Data protection act
Data protection act Data protection act
Data protection act Iqbal Bocus
 
CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
The CMR Agency
 
GDPR Information
GDPR InformationGDPR Information
GDPR Information
Oxford City Council
 
TPP Finance Seminar 6th October 2016
TPP Finance Seminar 6th October 2016TPP Finance Seminar 6th October 2016
TPP Finance Seminar 6th October 2016
TPP Recruitment
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Diana Maier
 
Overview of privacy and data protection considerations for DEVELOP
Overview of privacy and data protection considerations for DEVELOPOverview of privacy and data protection considerations for DEVELOP
Overview of privacy and data protection considerations for DEVELOP
Trilateral Research
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
Andreas Batsis
 

Similar to Ico sme-webinar-slides-090217 (20)

Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11
 
An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014An introduction to data protection - 26 March 2014
An introduction to data protection - 26 March 2014
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
Data Protection Guidelines
Data Protection GuidelinesData Protection Guidelines
Data Protection Guidelines
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
 
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012
 
An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Chap 4 (1)
Chap 4 (1)Chap 4 (1)
Chap 4 (1)
 
Research and The Law
Research and The LawResearch and The Law
Research and The Law
 
Data protection act
Data protection act Data protection act
Data protection act
 
CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
 
GDPR Information
GDPR InformationGDPR Information
GDPR Information
 
TPP Finance Seminar 6th October 2016
TPP Finance Seminar 6th October 2016TPP Finance Seminar 6th October 2016
TPP Finance Seminar 6th October 2016
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
Overview of privacy and data protection considerations for DEVELOP
Overview of privacy and data protection considerations for DEVELOPOverview of privacy and data protection considerations for DEVELOP
Overview of privacy and data protection considerations for DEVELOP
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 

Recently uploaded

amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
marketing317746
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Navpack & Print
 
VAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and RequirementsVAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and Requirements
uae taxgpt
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
seri bangash
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
RajPriye
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
Bojamma2
 
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdfikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
agatadrynko
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
LR1709MUSIC
 
The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...
balatucanapplelovely
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
Nicola Wreford-Howard
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
Attending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learnersAttending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learners
Erika906060
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
dylandmeas
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
anasabutalha2013
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
tanyjahb
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
Falcon Invoice Discounting
 
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
taqyed
 

Recently uploaded (20)

amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
 
VAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and RequirementsVAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and Requirements
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
 
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdfikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
 
The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
Attending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learnersAttending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learners
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
 
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
 

Ico sme-webinar-slides-090217

  • 1. Host: Robert Parker, Head of Communications Presenter: Richard Syers, Senior Policy Officer richard.syers@ico.org.uk Data Protection for small and medium-sized enterprises
  • 2. Freedom of Information Act 2000 Environmental Information Regulations 2004 Upholding information rights in the public interest, promoting openness by public authorities and data privacy for individuals Data Protection Act 1998 Privacy and Electronic Communications (EC Directive) Regulations 2003
  • 3. …data which relate to a living individual who can be identified – (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller Personal data
  • 4. Data Protection Act 1998: principles for processing personal data  Fairly and lawfully  For specified, limited purposes  Adequate, relevant and not excessive  Accurate and kept up to date  Not kept for longer than necessary  Processed in accordance with individual’s rights  Protected by appropriate security  Not transferred outside EEA without adequate protection
  • 5. Fairness, transparency and proportionality  Clearly tell individuals what personal data you are collecting and why  Make sure you have a legal basis to process personal data  Only collect what you need “Artists-impressions-of-Lady-Justice, (statue on the Old Bailey, London)” by Lonpicman is licensed under CC BY-SA
  • 6. Privacy notice  What information is being collected?  Who is collecting it?  How is it collected?  Why is it being collected?  How will it be used?  Who will it be shared with? ico.org.uk/for-organisations/guide-to-data- protection/privacy-notices-transparency-and- control/
  • 7. Data quality  Accurate and up to date  Relevant  Not excessive  Not kept for longer than necessary
  • 8. Security  Appropriate physical security  Appropriate electronic security  Encryption  Keep secure, regular backups
  • 9. Get the basics right  Train your staff  Physical security  Access control  Encrypt portable devices  Back up your data  Cyber Essentials ico.org.uk/media/for-organisations/documents/1575/it_security_practical_guide.pdf https://www.cyberaware.gov.uk/cyberessentials/
  • 10. Individual’s Rights  Access personal data  Prevent direct marketing  Prevent processing of personal data  Rectify, block, erase or destroy inaccurate data  Object to automatic decision making  Claim compensation
  • 11. What if someone asks for their information?  Respond within 40 calendar days  Can ask for :  Proof of identification  Further information to locate the data requested  Fee of up to £10 in most cases  Must ask for these things promptly  Exemptions in certain circumstances https://ico.org.uk/for-organisations/guide-to- data-protection/principle-6-rights/subject- access-request/
  • 12. Direct Marketing • Privacy and Electronic Communications Regulations • Different rules for different channels • Respect peoples choices • Marketing directed at an individual • Section 11 applies to all direct marketing • Must comply immediately with a section 11 request in most cases
  • 13. What are the rules for electronic marketing? Most common forms of marketing: Can make telephone calls without consent, unless the number is registered with the TPS or the subscriber has asked you not to call the number for marketing purposes. Must have subscribers’ prior consent before sending electronic marketing messages (e.g. SMS, email) unless the “soft opt-in” applies. Must have subscriber’s consent to make an automated call. https://ico.org.uk/for-organisations/guide-to- data-protection/principle-6-rights/preventing- direct-marketing/
  • 17. Registering with the ICO  Public register of data controllers  Legal requirement if processing personal data electronically  Costs £35 per year for most organisations  Charities, small occupational pensions schemes and organisations that have been in existence for less than one month all pay £35 regardless of size or turnover  Failing to notify when not exempt, or to keep registration up to date, is a criminal offence
  • 19. Do I need to register? Online self assessment ico.org.uk/for-organisations/register/self-assessment
  • 20. The future of data protection General Data Protection Regulation (GDPR)  Same basic principles as current DP law, but strengthened  Accountability  New rights for individuals, and strengthening of existing rights  Breach reporting  Data Protection Impact Assessments  Higher penalties for non-compliance ico.org.uk/for-organisations/data-protection-reform/
  • 21.
  • 22. @iconews Any Questions? Helpline: 0303 123 1113 Keep in touch by subscribing to our e-newsletter at www.ico.org.uk or find us on…