SlideShare a Scribd company logo
GDPR and
The Company Secretary
Helen Dixon
Data Protection Commissioner
@DPCIreland
1
www.dataprotection.ie
2
CLEAR RATIONALE FOR NEW DATA
PROTECTION LAWS IN EUROPE
Article 8 :
Protection of
personal data
Charter of Fundamental Rights
3
4th Industrial Revolution
5
Revolution or Evolution ?
6
GDPR Text and EU Data Protection APP
7
173 Recitals
(not having
force of law)
11 Chapters
99 Articles
(having full
force of law)
8
Focus of the GDPR
Giving Data
Subjects more
control
Making Data
Controllers/Proce
ssors more
accountable
Making
personal data
processing
more
transparent
Reducing
personal data
security
vulnerabilities
Co-operation
between
Supervisory
Authorities on
cross-border
processing
9
The 8 Principles of Data Protection
Obtain and
process
information
fairly
Keep it
only for
one or
more
specified,
explicit
and lawful
purposes
Use and
disclose it
only in
ways
compatible
with these
purposes
Keep it
safe and
secure
Keep it
accurate,
complete
and up-
to-date
Ensure
that it is
adequate,
relevant
and not
excessive
Retain it
for no
longer
than is
necessary
for the
purpose
or
purposes
Give a
copy of
his/her
personal
data to
that
individual
on
request
Data Integrity
Pseudonymisation
Anonymization
Cryptography
Accountability
Data Protection
Officer
Data Protection
Impact
Assessments
Data minimisation
Notification of
Personal Data
Breaches
11
What’s new in GDPR?
Accountability
–
demonstrating
compliance
Transparency
– providing
information
pre-processing
Risk-based
mandatory
data breach
reporting (72
hours)
Strengthened
‘Consent’
obligations
New and
enhanced Data
Subject rights
Administrative
Fines
Data
Protection
Officer (DPO)
for certain
organisations
12
Article 24.1
“….the controller shall implement appropriate technical and
organizational measures to ensure and to be able to
demonstrate that processing is performed in accordance with
this Regulation”
Article 24.3
“Adherence to approved codes of conduct as referred to in
Article 40 or approved certification mechanisms as referred to
in Article 42 may be used as an element by which to
demonstrate compliance with the obligations of the controller”
13
Data Protection Officer (Articles 37, 38 & 39)
 Public Authority or Body
 Core activities consist of processing
operations which require regular
and systematic monitoring of data
subjects on a large scale
 Processing on a large scale of
special categories of data (Articles
9 and 10)
14
Demonstrating Accountability
Privacy by Design
Privacy by Default
Data Protection Impact
Assessment (DPIA)
Codes of Conduct
Certification
15
Notification to Supervising Authority
Notification to
Supervising
Authority
within 72 hours
Unless “unlikely to
result in a risk to the
rights and freedoms
of natural persons”
‘Risk’ might include, for
example, a risk of
identity theft or
anything likely to lead
to a financial loss for
the data subject
16
Breach Communication to Data Subject
 “when the personal data breach is likely
to result in a high risk to the rights and
freedoms of natural persons”
 “the data controller shall communicate
the personal data breach to the data
subject without undue delay”
 ‘High Risk’ – higher threshold than report
to SA
17
New and Enhanced Data Subject Rights
Right to data portability
Right to be informed
Right to rectification
Right of access
Right of erasure
Right to be forgotten (search engine de-indexing)
Right to restrict processing
Right to object to processing
18
Transparency Requirements
• Identity of controller and DPO
• Purpose of processing and legal basis
• Recipients of the data
• Data transfer arrangements
• Retention period
• Right of access
• Right to withdraw consent
• Right to lodge complaint with SA
• Details of the contractual or statutory
basis
• Details of automated decision-making
At the time
when
personal
data are
obtained
provide the
data subject
with
information
on; 19
Transparency
Article 12
“The controller shall take appropriate
measures to provide any
information……..relating to processing
to the data subject in a concise,
transparent, intelligible and easily
accessible form, using clear and plain
language, in particular for any
information addressed specifically to a
child”
20
Administrative Fines
Article 83
Up to €20m or
4% of global
turnover for
the preceding
financial year
21
A Resourced and Effective Regulator
22
Get
Data
Protection
Ready
Thank you
www.dataprotection.ie
Q&A – Guest Panel
• Helen Dixon, Data Protection Commissioner of Ireland
• Denis Kelleher, Senior Legal Counsel, the Central Bank of Ireland
• David Cullen, Partner and Head of Technology, William Fry
Closing Address
• Ruairí Cosgrove President of the Irish Council of ICSA

More Related Content

What's hot

What does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businessesWhat does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businesses
iFactory Digital
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Cvent
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Caroline Boscher
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
Acquia
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year on
Insight Data
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017
Aoife Flynn
 
Revision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptxRevision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptx
Breach_P
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
TAG Alliances
 
SAP Business One
SAP Business OneSAP Business One
SAP Business One
AGSanePLDTCompany
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
Elizabeth Baker, JD, CRCMP
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
Ulf Mattsson
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research community
ARDC
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
Tim Hyman LLB
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
Trish McGinity, CCSK
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
Fintan Swanton
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Qualsys Ltd
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
Vicky Dallas
 
Data protection policy alex clapson 20-11-17
Data protection policy   alex clapson 20-11-17Data protection policy   alex clapson 20-11-17
Data protection policy alex clapson 20-11-17
Alex Clapson
 
Gdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework ELGdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework EL
Eugene Lee
 

What's hot (20)

What does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businessesWhat does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businesses
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year on
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017
 
Revision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptxRevision of Legal issues for Unit 11.pptx
Revision of Legal issues for Unit 11.pptx
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
SAP Business One
SAP Business OneSAP Business One
SAP Business One
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research community
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Data protection policy alex clapson 20-11-17
Data protection policy   alex clapson 20-11-17Data protection policy   alex clapson 20-11-17
Data protection policy alex clapson 20-11-17
 
Gdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework ELGdpr and ISMS Quick Map Framework EL
Gdpr and ISMS Quick Map Framework EL
 

Similar to ICSA Irish Region General Data Protection Regulation event, 10 October 2017

My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
zayadeen2003
 
Transparency gdpr
Transparency    gdprTransparency    gdpr
Transparency gdpr
Mathew Chacko
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
Ernest Staats
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
Cliff Ashcroft
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
The Pathway Group
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
The Pathway Group
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
Olivier Vandeputte
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
JakeAldrinDegala1
 
Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018
Surabhi Jain
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
Niall Rooney
 
GDPR
GDPRGDPR
GDPR
Gopi PD
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
Anubhav Dhiman
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Priyanka Aash
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
Andrew Sharpe
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
Paul Jacobson
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
Wynthorpe
 

Similar to ICSA Irish Region General Data Protection Regulation event, 10 October 2017 (20)

My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
Transparency gdpr
Transparency    gdprTransparency    gdpr
Transparency gdpr
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018Critical regulations governing data privacy and data protection 20 dec2018
Critical regulations governing data privacy and data protection 20 dec2018
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
GDPR
GDPRGDPR
GDPR
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
 

More from Institute of Chartered Secretaries and Administrators

Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Institute of Chartered Secretaries and Administrators
 
ICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slidesICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slides
Institute of Chartered Secretaries and Administrators
 
ICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slidesICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slides
Institute of Chartered Secretaries and Administrators
 
Risk Management and the Company Secretary
Risk Management and the Company Secretary Risk Management and the Company Secretary
Risk Management and the Company Secretary
Institute of Chartered Secretaries and Administrators
 
Board effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluationBoard effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluation
Institute of Chartered Secretaries and Administrators
 
ICSA qualifying programme update 2019
ICSA qualifying programme update 2019 ICSA qualifying programme update 2019
ICSA qualifying programme update 2019
Institute of Chartered Secretaries and Administrators
 
ICSA CPD - Cyber breaches
ICSA CPD -   Cyber breachesICSA CPD -   Cyber breaches
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
Institute of Chartered Secretaries and Administrators
 
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
Institute of Chartered Secretaries and Administrators
 
ICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight TechnologiesICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight Technologies
Institute of Chartered Secretaries and Administrators
 
ICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 MayICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 May
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
Institute of Chartered Secretaries and Administrators
 
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Institute of Chartered Secretaries and Administrators
 
Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017
Institute of Chartered Secretaries and Administrators
 
Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017 Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017
Institute of Chartered Secretaries and Administrators
 

More from Institute of Chartered Secretaries and Administrators (20)

Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
 
ICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slidesICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slides
 
ICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slidesICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slides
 
Risk Management and the Company Secretary
Risk Management and the Company Secretary Risk Management and the Company Secretary
Risk Management and the Company Secretary
 
Board effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluationBoard effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluation
 
ICSA qualifying programme update 2019
ICSA qualifying programme update 2019 ICSA qualifying programme update 2019
ICSA qualifying programme update 2019
 
ICSA CPD - Cyber breaches
ICSA CPD -   Cyber breachesICSA CPD -   Cyber breaches
ICSA CPD - Cyber breaches
 
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
 
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
 
ICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight TechnologiesICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight Technologies
 
ICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 MayICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 May
 
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
 
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
 
ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018
 
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
 
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
 
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
 
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
 
Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017
 
Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017 Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017
 

Recently uploaded

PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptxPD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
RIDPRO11
 
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
ehbuaw
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Congressional Budget Office
 
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
ehbuaw
 
一比一原版(WSU毕业证)西悉尼大学毕业证成绩单
一比一原版(WSU毕业证)西悉尼大学毕业证成绩单一比一原版(WSU毕业证)西悉尼大学毕业证成绩单
一比一原版(WSU毕业证)西悉尼大学毕业证成绩单
evkovas
 
The Role of a Process Server in real estate
The Role of a Process Server in real estateThe Role of a Process Server in real estate
The Role of a Process Server in real estate
oklahomajudicialproc1
 
PACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdfPACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdf
Mohammed325561
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
850fcj96
 
Russian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale warRussian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale war
Antti Rautiainen
 
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
ukyewh
 
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
ehbuaw
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
Get Government Grants
 
PPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way StopPPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way Stop
ahcitycouncil
 
Understanding the Challenges of Street Children
Understanding the Challenges of Street ChildrenUnderstanding the Challenges of Street Children
Understanding the Challenges of Street Children
SERUDS INDIA
 
NHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdfNHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdf
AjayVejendla3
 
What is the point of small housing associations.pptx
What is the point of small housing associations.pptxWhat is the point of small housing associations.pptx
What is the point of small housing associations.pptx
Paul Smith
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
JSchaus & Associates
 
PPT Item # 7 - BB Inspection Services Agmt
PPT Item # 7 - BB Inspection Services AgmtPPT Item # 7 - BB Inspection Services Agmt
PPT Item # 7 - BB Inspection Services Agmt
ahcitycouncil
 
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptxMHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
ILC- UK
 
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
ehbuaw
 

Recently uploaded (20)

PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptxPD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
 
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
 
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
 
一比一原版(WSU毕业证)西悉尼大学毕业证成绩单
一比一原版(WSU毕业证)西悉尼大学毕业证成绩单一比一原版(WSU毕业证)西悉尼大学毕业证成绩单
一比一原版(WSU毕业证)西悉尼大学毕业证成绩单
 
The Role of a Process Server in real estate
The Role of a Process Server in real estateThe Role of a Process Server in real estate
The Role of a Process Server in real estate
 
PACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdfPACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdf
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
 
Russian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale warRussian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale war
 
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
 
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
 
PPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way StopPPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way Stop
 
Understanding the Challenges of Street Children
Understanding the Challenges of Street ChildrenUnderstanding the Challenges of Street Children
Understanding the Challenges of Street Children
 
NHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdfNHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdf
 
What is the point of small housing associations.pptx
What is the point of small housing associations.pptxWhat is the point of small housing associations.pptx
What is the point of small housing associations.pptx
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
 
PPT Item # 7 - BB Inspection Services Agmt
PPT Item # 7 - BB Inspection Services AgmtPPT Item # 7 - BB Inspection Services Agmt
PPT Item # 7 - BB Inspection Services Agmt
 
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptxMHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
 
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
 

ICSA Irish Region General Data Protection Regulation event, 10 October 2017

  • 1. GDPR and The Company Secretary Helen Dixon Data Protection Commissioner @DPCIreland 1 www.dataprotection.ie
  • 2. 2
  • 3. CLEAR RATIONALE FOR NEW DATA PROTECTION LAWS IN EUROPE Article 8 : Protection of personal data Charter of Fundamental Rights 3
  • 5. 5
  • 7. GDPR Text and EU Data Protection APP 7
  • 8. 173 Recitals (not having force of law) 11 Chapters 99 Articles (having full force of law) 8
  • 9. Focus of the GDPR Giving Data Subjects more control Making Data Controllers/Proce ssors more accountable Making personal data processing more transparent Reducing personal data security vulnerabilities Co-operation between Supervisory Authorities on cross-border processing 9
  • 10. The 8 Principles of Data Protection Obtain and process information fairly Keep it only for one or more specified, explicit and lawful purposes Use and disclose it only in ways compatible with these purposes Keep it safe and secure Keep it accurate, complete and up- to-date Ensure that it is adequate, relevant and not excessive Retain it for no longer than is necessary for the purpose or purposes Give a copy of his/her personal data to that individual on request
  • 11. Data Integrity Pseudonymisation Anonymization Cryptography Accountability Data Protection Officer Data Protection Impact Assessments Data minimisation Notification of Personal Data Breaches 11
  • 12. What’s new in GDPR? Accountability – demonstrating compliance Transparency – providing information pre-processing Risk-based mandatory data breach reporting (72 hours) Strengthened ‘Consent’ obligations New and enhanced Data Subject rights Administrative Fines Data Protection Officer (DPO) for certain organisations 12
  • 13. Article 24.1 “….the controller shall implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation” Article 24.3 “Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller” 13
  • 14. Data Protection Officer (Articles 37, 38 & 39)  Public Authority or Body  Core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale  Processing on a large scale of special categories of data (Articles 9 and 10) 14
  • 15. Demonstrating Accountability Privacy by Design Privacy by Default Data Protection Impact Assessment (DPIA) Codes of Conduct Certification 15
  • 16. Notification to Supervising Authority Notification to Supervising Authority within 72 hours Unless “unlikely to result in a risk to the rights and freedoms of natural persons” ‘Risk’ might include, for example, a risk of identity theft or anything likely to lead to a financial loss for the data subject 16
  • 17. Breach Communication to Data Subject  “when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons”  “the data controller shall communicate the personal data breach to the data subject without undue delay”  ‘High Risk’ – higher threshold than report to SA 17
  • 18. New and Enhanced Data Subject Rights Right to data portability Right to be informed Right to rectification Right of access Right of erasure Right to be forgotten (search engine de-indexing) Right to restrict processing Right to object to processing 18
  • 19. Transparency Requirements • Identity of controller and DPO • Purpose of processing and legal basis • Recipients of the data • Data transfer arrangements • Retention period • Right of access • Right to withdraw consent • Right to lodge complaint with SA • Details of the contractual or statutory basis • Details of automated decision-making At the time when personal data are obtained provide the data subject with information on; 19
  • 20. Transparency Article 12 “The controller shall take appropriate measures to provide any information……..relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child” 20
  • 21. Administrative Fines Article 83 Up to €20m or 4% of global turnover for the preceding financial year 21
  • 22. A Resourced and Effective Regulator 22
  • 24. Q&A – Guest Panel • Helen Dixon, Data Protection Commissioner of Ireland • Denis Kelleher, Senior Legal Counsel, the Central Bank of Ireland • David Cullen, Partner and Head of Technology, William Fry
  • 25. Closing Address • Ruairí Cosgrove President of the Irish Council of ICSA