SlideShare a Scribd company logo
1 of 23
Sirius Legal
eTrade Summit
27 September 2016
2016’s Marketing buzz…
eTrade Summit
27 September 2016
New “Privacy Law” coming your way…
General Data Protection Regulation 2016/679 (GDPR/AVGB)
Regulation instead of Directive – 1 law for 28 states
Agreement reached last December 2015
Enters into force on 1 May 2018 (without grace period!)
New rules are MUCH stricter than current law and impact EVERYONE present
here today
eTrade Summit
27 September 2016
General Data Protection Regulation
Heavily influenced by consumer protection activists in EP
Result:
Consumer friendly, but serious restraints for direct marketing sector, e-
commerce sector and especially personalisation, profiling, real time
marketing and (big) data processing
Applicable on ALL data processing, except personal (private) contact lists (e.g.
private Outlook account)
eTrade Summit
27 September 2016
Don’t be this guy, be prepared…
eTrade Summit
27 September 2016
All e-commerce and online marketing run on personal data
GDPR applies to ALL databases (marketing, sales, HR, purchasing, accounting, …)
In the words of the European Commission: “data has become a currency” (cfr. Draft Directive
2015/0287 on digital content delivery contracts)
Fines up to 4% of annual turnover or 20 mio euro
Security & internal processes
1. Working with subcontractors that process data
Obligation to work only with subcontractors that guarantee sufficient data security
Obligation to have written contracts wth all subcontractors
List of mandatory clauses in such contracts
= Need to audit/map all existing subcontracting/service contracts
eTrade Summit
27 September 2016
Security & internal processes
2. Record of processing activities
Obligation to maintain a “record of processing activities”
Holding ID of processor, processed data, categories, transfers, time limits, security
measures
In writing at the seat of your company
eTrade Summit
27 September 2016
Security & internal processes
3. Data security measures
“Processor shall implement appropriate technical and organizational measures, to
ensure an appropriate level of security”
Pseudonymisation where possible, confidentiality, security, back ups in place,
security testing protocols, …
= Need to audit/map data within company
eTrade Summit
27 September 2016
Security & internal processes
4. Data Protection Impact Assessment
If possible high impact on data subject privacy rights
Obligation to run prior (documented) impact assessment
Advice of DPO required if DPO is present in the organization
Should be used as basis to ensure adequate security levels
Privacy Commission to specify when DPIA is required
If DPIA shows high risk: obtain Prior Assessment from Privacy Commission
eTrade Summit
27 September 2016
Security & internal processes
5. Data breach notification
Obligation to notify any data security breach to the Privacy Commission
Asap or at least within 72 hours
Nature of breach, possible consequences, measures taken, etc… (= obligation to
document data breach)
= Need to have data breach procedure in place
If possible consequences for data subjects: obligation to notify them in person!
eTrade Summit
27 September 2016
Security & internal processes
5. Data Protection Officer
If core activity of processor
Requires large scale data monitoring
Consists of large scale data monitoring
Series of requirements and conditions
Details to be specified
Inform & advise, monitor compliance, SPOC for authorities
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
1. Lawfulness of processing (“on which grounds can I proces data?”) (art. 6
GDPR)
Prior opt-in remains the basic rule (+ proof required)
“Processing is required for the execution of a contract”
“Legitimate grounds”
DM “may be considered” legitimate, but “Personal data should be processed
only if the purpose of the processing could not reasonably be fulfilled by other
means”
If existing client relationship: OK, otherwise not so evidently OK
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
2. Processing of data belonging to minor (-13 Y/O, -16 Y/O) (art. 8 GDPR)
Always requires explicit authorisation by parents!
“Reasonable efforts” to check age and obtain authorisation
eID?, Facebook login?, credit card data?, live chat, …?
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
3. Information obligations
Obligation to notify data subject of the fact that his data is being / has been
collected (or transferred) without his explicit consent (art. 14 GDPR)
Within 30 days or upon first contact
= Data obtained from data brokers, partner organisations, online collection…
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
3. Information obligations (art. 14 GDPR)
Obligation falls if
Data subject already knows
or
Information provision requires disproportionate effort
(= open door to creativity…)
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
4. Right not to be submitted to profiling (art. 21 GDPR)
If the person has a legitimate interest to do so, he has a right to object against
Processing/profiling based on
public interest / official authority
or
legitimate interest
Objection against processing/profiling for direct marketing purposes is always
possible
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
5. Right to object to automatic decision taking (art. 22 GDPR)
Right
Not to be subject to a decision (or profiling) – Exceptions (e.g. contracts)
Producing legal effects / significantly affects
Solely based on automated processing of data
Intended to evaluate certain personal aspects
Examples
Performance of work, creditworthiness reliability and conduct
Also applies to DM “decisions” (e.g. send offer or not)
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
6. Right to be forgotten (art. 17)
Upon request by data subject, processor has to take all reasonable measures to
permantently delete data
+ to ensure that third parties that have copies of or links to data are warned of
the request and are asked to do the same
eTrade Summit
27 September 2016
Information obligations & rights of data subjects
7. “Pseudonymous data”
8. “Privacy by design”
9. “privacy by default” (cfr. recent Telenet “personalized advertising…”)
10. …
eTrade Summit
27 September 2016
Helping hand
Code of Conduct
= “ethical code” of associations
Contain rules on how to handle data for their members
Can be approved by authorities
Association has to provide control/supervision
Advantage: once approved can create presumption of compliance with series of
obligations for association members
SafeShops is currently investigating possibility to draft code and apply for approval
eTrade Summit
27 September 2016
Be prepared…
Follow up on discussion (e.g. through our website www.siriuslegal.be)
Start audit om data use within your organisation
Start review vendor contracts (in view of data security obligation)
Start to prepare for full update of policies, contracts, business processes
Put in place data breach notification procedure
Appoint (temporary) data security officer
Put in place impact assessment and/or risk analyses policy
Create compliance statements for annual business reports
Train staff
Sit back and wait for final text of regulation for final details…
eTrade Summit
27 September 2016
Be prepared…
Those who are not prepared face trouble…
Provisions of highest importance (cfr. profiling = high risk processing)
Fines up to 20 million euro
Fines up to 4% of worldwide annual turnover (for undertakings)
Reform of Privacy Commission will lead to actual enforcement…
+ Remedies for data subject
eTrade Summit
27 September 2016
Sirius Legal
Media & advertisement law
IP law
Internet & e-commerce
Privacy & cookies
Gambling law
Travel & consumer protection
Commercial contracts
Corporate tax labour real estate
bart@siriuslegal.be
www.siriuslegal.be
@BartVdBrande
Linkedin.com/in/bartvdb

More Related Content

What's hot

The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Bart Van Den Brande
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Stephanie Vasey
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!Fintan Swanton
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshellInitio
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer IT Governance Ltd
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...eHealth Forum
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...TrustArc
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 

What's hot (20)

The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshell
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 

Viewers also liked

Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)Exove
 
Challenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. Gawad
Challenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. GawadChallenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. Gawad
Challenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. GawadNephroTube - Dr.Gawad
 
Wholesale jackets manufacturer
Wholesale jackets manufacturerWholesale jackets manufacturer
Wholesale jackets manufacturerSophia Wright
 
GDPR and technology - details matter
GDPR and technology - details matterGDPR and technology - details matter
GDPR and technology - details matterExove
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
تسلية المصاب عند فقد الأقربين والأصحاب
تسلية المصاب عند فقد الأقربين والأصحابتسلية المصاب عند فقد الأقربين والأصحاب
تسلية المصاب عند فقد الأقربين والأصحابغايتي الجنة
 
Ibra trai qua
Ibra trai quaIbra trai qua
Ibra trai quabongda100
 
Are your pictures worth 1,000 words? (Eric Beteille)
Are your pictures worth 1,000 words?  (Eric Beteille)Are your pictures worth 1,000 words?  (Eric Beteille)
Are your pictures worth 1,000 words? (Eric Beteille)Eric Beteille
 
Overcoming the Top 3 SMB Challenges with Marketing Automation
Overcoming the Top 3 SMB Challenges with Marketing AutomationOvercoming the Top 3 SMB Challenges with Marketing Automation
Overcoming the Top 3 SMB Challenges with Marketing AutomationPardot
 
Apports de la systémique à la gestion des organisations et des institutions p...
Apports de la systémique à la gestion des organisations et des institutions p...Apports de la systémique à la gestion des organisations et des institutions p...
Apports de la systémique à la gestion des organisations et des institutions p...Université Paris-Dauphine
 

Viewers also liked (13)

Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)
 
Challenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. Gawad
Challenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. GawadChallenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. Gawad
Challenges in Diagnosis and Management of Diabetic Kidney Disease - Dr. Gawad
 
Wholesale jackets manufacturer
Wholesale jackets manufacturerWholesale jackets manufacturer
Wholesale jackets manufacturer
 
GDPR and technology - details matter
GDPR and technology - details matterGDPR and technology - details matter
GDPR and technology - details matter
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Induction of labor
Induction of laborInduction of labor
Induction of labor
 
80310cur
80310cur80310cur
80310cur
 
تسلية المصاب عند فقد الأقربين والأصحاب
تسلية المصاب عند فقد الأقربين والأصحابتسلية المصاب عند فقد الأقربين والأصحاب
تسلية المصاب عند فقد الأقربين والأصحاب
 
Ibra trai qua
Ibra trai quaIbra trai qua
Ibra trai qua
 
Are your pictures worth 1,000 words? (Eric Beteille)
Are your pictures worth 1,000 words?  (Eric Beteille)Are your pictures worth 1,000 words?  (Eric Beteille)
Are your pictures worth 1,000 words? (Eric Beteille)
 
Overcoming the Top 3 SMB Challenges with Marketing Automation
Overcoming the Top 3 SMB Challenges with Marketing AutomationOvercoming the Top 3 SMB Challenges with Marketing Automation
Overcoming the Top 3 SMB Challenges with Marketing Automation
 
Analytics for CMOs on the Rise
Analytics for CMOs on the RiseAnalytics for CMOs on the Rise
Analytics for CMOs on the Rise
 
Apports de la systémique à la gestion des organisations et des institutions p...
Apports de la systémique à la gestion des organisations et des institutions p...Apports de la systémique à la gestion des organisations et des institutions p...
Apports de la systémique à la gestion des organisations et des institutions p...
 

Similar to Impact on e-commerce of the GDPR- Etrade Summit 2016

Abto ledenvergadering: gdpr impact on the travel industry 2017
Abto ledenvergadering:  gdpr impact on the travel industry 2017Abto ledenvergadering:  gdpr impact on the travel industry 2017
Abto ledenvergadering: gdpr impact on the travel industry 2017Bart Van Den Brande
 
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Bart Van Den Brande
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
How to implement gdpr in your document repository
How to implement gdpr in your document repository How to implement gdpr in your document repository
How to implement gdpr in your document repository XeniT Solutions nv
 
Privacy and data protection - Presentation for Bdma real time and trigger bas...
Privacy and data protection - Presentation for Bdma real time and trigger bas...Privacy and data protection - Presentation for Bdma real time and trigger bas...
Privacy and data protection - Presentation for Bdma real time and trigger bas...Bart Van Den Brande
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)Napier University
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessEversheds Sutherland
 
CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeersThe CMR Agency
 
Automatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy StandardsAutomatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy Standardsautomatskicorporation
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-LatemAnn Van den Bunder
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical OverviewErnest Staats
 

Similar to Impact on e-commerce of the GDPR- Etrade Summit 2016 (20)

Abto ledenvergadering: gdpr impact on the travel industry 2017
Abto ledenvergadering:  gdpr impact on the travel industry 2017Abto ledenvergadering:  gdpr impact on the travel industry 2017
Abto ledenvergadering: gdpr impact on the travel industry 2017
 
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
 
Materializing dataprivacy in SAP - How?
Materializing dataprivacy in SAP - How?Materializing dataprivacy in SAP - How?
Materializing dataprivacy in SAP - How?
 
Materializing dataprivacy in sap .. how?
Materializing dataprivacy in sap .. how?Materializing dataprivacy in sap .. how?
Materializing dataprivacy in sap .. how?
 
Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
 
Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
 
How to implement gdpr in your document repository
How to implement gdpr in your document repository How to implement gdpr in your document repository
How to implement gdpr in your document repository
 
Privacy and data protection - Presentation for Bdma real time and trigger bas...
Privacy and data protection - Presentation for Bdma real time and trigger bas...Privacy and data protection - Presentation for Bdma real time and trigger bas...
Privacy and data protection - Presentation for Bdma real time and trigger bas...
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your business
 
CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
 
Automatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy StandardsAutomatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy Standards
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 

More from Bart Van Den Brande

Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing Bart Van Den Brande
 
Data export after the Google Analytics decision
Data export after the Google Analytics decisionData export after the Google Analytics decision
Data export after the Google Analytics decisionBart Van Den Brande
 
UBA legal changes in marketing automation
UBA legal changes in marketing automation UBA legal changes in marketing automation
UBA legal changes in marketing automation Bart Van Den Brande
 
20220211 Data export after the Google Analytics decision
20220211 Data export after the Google Analytics decision 20220211 Data export after the Google Analytics decision
20220211 Data export after the Google Analytics decision Bart Van Den Brande
 
20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websites20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websitesBart Van Den Brande
 
20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...
20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...
20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...Bart Van Den Brande
 
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021Bart Van Den Brande
 
20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for Comeos20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for ComeosBart Van Den Brande
 
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...Bart Van Den Brande
 
20201214 schrems II webinar politeia
20201214 schrems II webinar politeia20201214 schrems II webinar politeia
20201214 schrems II webinar politeiaBart Van Den Brande
 
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020Bart Van Den Brande
 
Direct marketing and data protection in fundraising
Direct marketing and data protection in fundraisingDirect marketing and data protection in fundraising
Direct marketing and data protection in fundraisingBart Van Den Brande
 
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)Bart Van Den Brande
 
fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)Bart Van Den Brande
 
The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...Bart Van Den Brande
 
Omgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacyOmgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacyBart Van Den Brande
 
Omgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en PrivacyOmgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en PrivacyBart Van Den Brande
 

More from Bart Van Den Brande (20)

Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing
 
Data export after the Google Analytics decision
Data export after the Google Analytics decisionData export after the Google Analytics decision
Data export after the Google Analytics decision
 
UBA legal changes in marketing automation
UBA legal changes in marketing automation UBA legal changes in marketing automation
UBA legal changes in marketing automation
 
20220211 Data export after the Google Analytics decision
20220211 Data export after the Google Analytics decision 20220211 Data export after the Google Analytics decision
20220211 Data export after the Google Analytics decision
 
20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websites20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websites
 
20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...
20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...
20211118 BAM webinar: Hoe kies ik veilige (marketing automation) tools in tij...
 
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
 
20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for Comeos20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for Comeos
 
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
 
20201211 DPIA webinar
20201211 DPIA webinar20201211 DPIA webinar
20201211 DPIA webinar
 
20201214 schrems II webinar politeia
20201214 schrems II webinar politeia20201214 schrems II webinar politeia
20201214 schrems II webinar politeia
 
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
 
Schrems II, wat nu?
Schrems II, wat nu?Schrems II, wat nu?
Schrems II, wat nu?
 
Direct marketing and data protection in fundraising
Direct marketing and data protection in fundraisingDirect marketing and data protection in fundraising
Direct marketing and data protection in fundraising
 
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
 
fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)
 
Sirius Friday Corona Webinar
Sirius Friday Corona WebinarSirius Friday Corona Webinar
Sirius Friday Corona Webinar
 
The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...
 
Omgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacyOmgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacy
 
Omgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en PrivacyOmgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en Privacy
 

Recently uploaded

PPT on information technology laws description
PPT on information technology laws descriptionPPT on information technology laws description
PPT on information technology laws descriptionranaanish11062001
 
QUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptx
QUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptxQUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptx
QUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptxnibresliezel23
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGPRAKHARGUPTA419620
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书FS LS
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书FS LS
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书SD DS
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxsrikarna235
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 

Recently uploaded (20)

PPT on information technology laws description
PPT on information technology laws descriptionPPT on information technology laws description
PPT on information technology laws description
 
QUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptx
QUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptxQUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptx
QUASI-JUDICIAL-FUNCTION AND QUASI JUDICIAL AGENCY.pptx
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKING
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to Service
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 

Impact on e-commerce of the GDPR- Etrade Summit 2016

  • 2. 2016’s Marketing buzz… eTrade Summit 27 September 2016
  • 3. New “Privacy Law” coming your way… General Data Protection Regulation 2016/679 (GDPR/AVGB) Regulation instead of Directive – 1 law for 28 states Agreement reached last December 2015 Enters into force on 1 May 2018 (without grace period!) New rules are MUCH stricter than current law and impact EVERYONE present here today eTrade Summit 27 September 2016
  • 4. General Data Protection Regulation Heavily influenced by consumer protection activists in EP Result: Consumer friendly, but serious restraints for direct marketing sector, e- commerce sector and especially personalisation, profiling, real time marketing and (big) data processing Applicable on ALL data processing, except personal (private) contact lists (e.g. private Outlook account) eTrade Summit 27 September 2016
  • 5. Don’t be this guy, be prepared… eTrade Summit 27 September 2016 All e-commerce and online marketing run on personal data GDPR applies to ALL databases (marketing, sales, HR, purchasing, accounting, …) In the words of the European Commission: “data has become a currency” (cfr. Draft Directive 2015/0287 on digital content delivery contracts) Fines up to 4% of annual turnover or 20 mio euro
  • 6. Security & internal processes 1. Working with subcontractors that process data Obligation to work only with subcontractors that guarantee sufficient data security Obligation to have written contracts wth all subcontractors List of mandatory clauses in such contracts = Need to audit/map all existing subcontracting/service contracts eTrade Summit 27 September 2016
  • 7. Security & internal processes 2. Record of processing activities Obligation to maintain a “record of processing activities” Holding ID of processor, processed data, categories, transfers, time limits, security measures In writing at the seat of your company eTrade Summit 27 September 2016
  • 8. Security & internal processes 3. Data security measures “Processor shall implement appropriate technical and organizational measures, to ensure an appropriate level of security” Pseudonymisation where possible, confidentiality, security, back ups in place, security testing protocols, … = Need to audit/map data within company eTrade Summit 27 September 2016
  • 9. Security & internal processes 4. Data Protection Impact Assessment If possible high impact on data subject privacy rights Obligation to run prior (documented) impact assessment Advice of DPO required if DPO is present in the organization Should be used as basis to ensure adequate security levels Privacy Commission to specify when DPIA is required If DPIA shows high risk: obtain Prior Assessment from Privacy Commission eTrade Summit 27 September 2016
  • 10. Security & internal processes 5. Data breach notification Obligation to notify any data security breach to the Privacy Commission Asap or at least within 72 hours Nature of breach, possible consequences, measures taken, etc… (= obligation to document data breach) = Need to have data breach procedure in place If possible consequences for data subjects: obligation to notify them in person! eTrade Summit 27 September 2016
  • 11. Security & internal processes 5. Data Protection Officer If core activity of processor Requires large scale data monitoring Consists of large scale data monitoring Series of requirements and conditions Details to be specified Inform & advise, monitor compliance, SPOC for authorities eTrade Summit 27 September 2016
  • 12. Information obligations & rights of data subjects 1. Lawfulness of processing (“on which grounds can I proces data?”) (art. 6 GDPR) Prior opt-in remains the basic rule (+ proof required) “Processing is required for the execution of a contract” “Legitimate grounds” DM “may be considered” legitimate, but “Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means” If existing client relationship: OK, otherwise not so evidently OK eTrade Summit 27 September 2016
  • 13. Information obligations & rights of data subjects 2. Processing of data belonging to minor (-13 Y/O, -16 Y/O) (art. 8 GDPR) Always requires explicit authorisation by parents! “Reasonable efforts” to check age and obtain authorisation eID?, Facebook login?, credit card data?, live chat, …? eTrade Summit 27 September 2016
  • 14. Information obligations & rights of data subjects 3. Information obligations Obligation to notify data subject of the fact that his data is being / has been collected (or transferred) without his explicit consent (art. 14 GDPR) Within 30 days or upon first contact = Data obtained from data brokers, partner organisations, online collection… eTrade Summit 27 September 2016
  • 15. Information obligations & rights of data subjects 3. Information obligations (art. 14 GDPR) Obligation falls if Data subject already knows or Information provision requires disproportionate effort (= open door to creativity…) eTrade Summit 27 September 2016
  • 16. Information obligations & rights of data subjects 4. Right not to be submitted to profiling (art. 21 GDPR) If the person has a legitimate interest to do so, he has a right to object against Processing/profiling based on public interest / official authority or legitimate interest Objection against processing/profiling for direct marketing purposes is always possible eTrade Summit 27 September 2016
  • 17. Information obligations & rights of data subjects 5. Right to object to automatic decision taking (art. 22 GDPR) Right Not to be subject to a decision (or profiling) – Exceptions (e.g. contracts) Producing legal effects / significantly affects Solely based on automated processing of data Intended to evaluate certain personal aspects Examples Performance of work, creditworthiness reliability and conduct Also applies to DM “decisions” (e.g. send offer or not) eTrade Summit 27 September 2016
  • 18. Information obligations & rights of data subjects 6. Right to be forgotten (art. 17) Upon request by data subject, processor has to take all reasonable measures to permantently delete data + to ensure that third parties that have copies of or links to data are warned of the request and are asked to do the same eTrade Summit 27 September 2016
  • 19. Information obligations & rights of data subjects 7. “Pseudonymous data” 8. “Privacy by design” 9. “privacy by default” (cfr. recent Telenet “personalized advertising…”) 10. … eTrade Summit 27 September 2016
  • 20. Helping hand Code of Conduct = “ethical code” of associations Contain rules on how to handle data for their members Can be approved by authorities Association has to provide control/supervision Advantage: once approved can create presumption of compliance with series of obligations for association members SafeShops is currently investigating possibility to draft code and apply for approval eTrade Summit 27 September 2016
  • 21. Be prepared… Follow up on discussion (e.g. through our website www.siriuslegal.be) Start audit om data use within your organisation Start review vendor contracts (in view of data security obligation) Start to prepare for full update of policies, contracts, business processes Put in place data breach notification procedure Appoint (temporary) data security officer Put in place impact assessment and/or risk analyses policy Create compliance statements for annual business reports Train staff Sit back and wait for final text of regulation for final details… eTrade Summit 27 September 2016
  • 22. Be prepared… Those who are not prepared face trouble… Provisions of highest importance (cfr. profiling = high risk processing) Fines up to 20 million euro Fines up to 4% of worldwide annual turnover (for undertakings) Reform of Privacy Commission will lead to actual enforcement… + Remedies for data subject eTrade Summit 27 September 2016
  • 23. Sirius Legal Media & advertisement law IP law Internet & e-commerce Privacy & cookies Gambling law Travel & consumer protection Commercial contracts Corporate tax labour real estate bart@siriuslegal.be www.siriuslegal.be @BartVdBrande Linkedin.com/in/bartvdb