SlideShare a Scribd company logo
Prepare your firm for GDPR
Thursday, October 26, 2017
Emily Mahoney
Technology Lawyer
Mason Hayes & Curran
3
10 themes
• Territorial Scope
• Financial exposure
• Consent
• Transparency
• Data protection impact assessments
• Data protection officer
• Security
• Data processors
• Accountability
• Data subject rights
4
Data Protection reform - background
• Current data protection rules:
• based upon 1995 EU Directive
• implemented separately in national laws
• not fully harmonised
• ‘GDPR’ = General Data Protection Regulation
• will apply directly in all Member States
• replaces 1995 Directive
• comes into effect 25 May 2018
5
Data Protection principles
• Same basic concepts and principles but generally tighter controls and
greater emphasis on data subject rights
• Fair, lawful and transparent processing
• Purpose limitation
• Data minimisation
• Accuracy
• Data retention
• Data security
• Accountability
How many of you are based in
the EU or outside the EU?
7
1 – Expanded Territorial Scope
• Territorial scope significantly expanded under GDPR to cover:
• offering goods or services to EU-based individuals; and
• “monitoring the behaviour” of EU-based individuals.
• GDPR will directly apply to FS firms and fintechs “established” in EU
• GDPR may directly apply to:
• FS firms and fintech established outside EU, i.e. Singapore if they target or offer services to EU-based individuals
8
2 – Increased financial exposure
• Current rules across the EU differ – DPC cannot directly impose fines
• Significant fines due under GDPR:
o up to €10m or 2% of total worldwide annual turnover =
 breaches of obligations of controller
o up to €20m or 4% of total worldwide annual turnover =
 breaches of obligations including the basic principles for processing (inc. consent), the data subjects’ rights
and data transfers
• GDPR contains a list of factors for determining level of fine (repeat offenders etc.)
• Data subject claims:
o explicit right to compensation for damage, both material and non-material (pecuniary loss?)
o possible joint and several liability
What is a data controller?
10
3 - Narrower interpretation of consent
• Consent is more tightly defined
― a statement or clear affirmative act required
― distinct consent for each operation
• Must prove you obtained consent
• Consent separate from terms and conditions
• Must be as easy to withdraw as it is to give it
11
4 - Increased transparency
• Must have transparent, clear, concise and easily accessible
privacy policy
• Intelligible language adapted to data subjects
• More information, e.g.:
― legal basis
― any specific legitimate interest relied upon
― how long you will keep data
― profiling, logic involved and effects
― implement appropriate technical / organisational measures
• Notice for further processing
12
5 -Data Protection Impact Assessments
• Must do a documented DPIA if high risk processing, eg
― systematic and extensive automated evaluation with legal effect / similarly significant affects DS
― large scale processing of sensitive data
― evaluation or scoring, including profiling and predicting
• Where appropriate, seek views of data subjects representatives
• Exclusion if based upon law that specifically regulates processing operations and DPIA already carried out for that law
• May have to seek relevant data protection commissioner opinion if DPIA shows high risks not mitigated
13
6 - Data Protection Officer
• Financial institutions/Fintechs may need to appoint a DPO
• large scale processing of sensitive data; or
• by virtue of processing, requires regular and systematic monitoring of data subjects on a large scale
• Must be expert in data protection laws and practices
• Report directly to highest management level; be properly involved with all activities dealing with personal data
• Must provide DPO with sufficient resources
• Can be group DPO
• Can perform other tasks provided no conflict of interest
• Protected role – cannot be removed or penalised for performing tasks
• Can be outsourced
14
7 - Security
• New security obligations: optional?
o Pseudonymisation and encryption
o Confidentiality, integrity, availability and resilience of IT systems
o Restore availability and access
o Testing of security measures
15
7 - Security breach
• Notify DPC without undue delay and, where feasible, within 72 hours, unless unlikely to result in a risk
• Processor must notify controller without undue delay
• Must notify data subjects if likely to result in a high risk to privacy / rights (with some exceptions)
• Must document breaches
• Should have security breach response plan in place
• Dual notification requirement may exist depending on the security breach – NCSC & DPC
16
8 – Data processors
• Obligations for data processing agreements significantly expanded
• The contract must now include:
• the subject matter and duration of the processing
• the nature and purposes of the processing
• the type of personal data
• the categories of data subjects
• Additional obligatory provisions include that the processor:
• makes information available to demonstrate compliance
• contributes to audits and inspections
• assists the controller regarding access requests, DPIAs and security breaches
What is the correct definition of personal
data under the GDPR?
18
9 - Accountability
• DC / DP must document all processing activities, e.g.:
― categories of data subjects, recipients and data
― data transfers (including details of safeguards)
― retention / erasure period
― general description of security measures (if possible)
• DC also must document purposes and (indirectly) legal bases
― AML Documentation
• Should be consistent with privacy policy
• Privacy by design/default
19
10 - Data subject rights
• Right of restriction
• accuracy contested or processing unlawful
• no longer needed for original purpose, but necessary to establish, exercise or defend legal rights
• pending verification where individual objects
• Right to be erasure – ‘right to be forgotten’
• Variety of situations where individuals can request erasure
• Subject access requests
• Changes to cost, timelines and ability to refuse requests (Right to charge or refuse request if “manifestly unfounded or excessive”)
• Right to data portability
• Provide certain data in a machine-readable format
• only applies if legitimised based upon consent or performance of a contrac
• Right of rectification
20
10 - Data subject rights
• Right to object
― applies if use legitimate interest or public interest test
― must then show overriding compelling legitimate grounds
• Must inform data subject of right to object
― explicitly brought to their attention
― present clearly and separately from other information
21
Key points
• Core principles broadly the same, but tighter controls
• Greater accountability and shift in burden of proof
• Increased records and compliance burden
• Increased financial exposure
• Broader data subject rights
• 7 months to get it right, but time to start preparing is now
22
What to do now – step 1 (what are we doing)?
• Data mapping exercise
― data flows and disclosures
― purpose and legitimisation mapping
• Audit of data transfers (remember Brexit)
• Audit of data related contracts
• GDPR gap analysis and prioritisation
23
What to do now – Step 2 (moving forward)?
• Use gap analysis to decide on key action points
• Create internal accountability records
• Update internal / external policies & contracts
• Create any necessary new policies and templates, eg
― privacy by design / default playbook
― DPIA protocol and templates
― security breach response plan
• Appoint DPO
• Education
Emily Mahoney
Technology Lawyer
Mason Hayes & Curran
25
GDPR – What it means in Practice
Q&A
27
MCO Platform
• Manage by alerts not reports
• Dashboards deliver greater oversight
• Custom questionnaire builder
• Continuous updates to the software
• Enhanced control
• 100% data capture
• 24/7/365 support
• Scalable into the future
28
Contact
MyComplianceOffice
Email: advance@mycomplianceoffice.com
Website: https://mco.mycomplianceoffice.com
emahoney@mhc.ie
Emily Mahoney
+353 1 614 2396
MCH.ie
Thank You

More Related Content

What's hot

GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
isc2-hellenic
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
Frederick Penaud
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
Richard Hogg,Global GDPR Offerings Evangelist
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
Susan Moran
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshell
Initio
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?
Christiana Kozakou
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
TrustArc
 
Post US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsPost US Election Privacy Updates & Implications
Post US Election Privacy Updates & Implications
TrustArc
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
Emily Jones
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
Tomppa Järvinen
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
►David Clarke FBCS CITP
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
Browne Jacobson LLP
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
Benoît De Nayer
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)Huub de Jong
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
TrustArc
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
Chris Gilmour
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
BrightPay Payroll and Auto Enrolment Software
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
Vertex Holdings
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
Lilian Edwards
 

What's hot (19)

GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshell
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
Post US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsPost US Election Privacy Updates & Implications
Post US Election Privacy Updates & Implications
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 

Similar to Prepare Your Firm for GDPR

What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
TAG Alliances
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
NiclasGranqvist
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
Rachel Aldighieri
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
Craig Clark ITIL, CIS LI,EU GDPR P
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
Browne Jacobson LLP
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
Financial Poise
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
NCVO - National Council for Voluntary Organisations
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
James Mulhern
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
SecurityScorecard
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
Fionnuala Hendrick
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
Vuzion
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
MRS
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
IISPEastMids
 

Similar to Prepare Your Firm for GDPR (20)

What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 

More from MyComplianceOffice

Third Party Management - The Journey Continues…
Third Party Management - The Journey Continues…Third Party Management - The Journey Continues…
Third Party Management - The Journey Continues…
MyComplianceOffice
 
Regulatory Update - SMCR
Regulatory Update - SMCRRegulatory Update - SMCR
Regulatory Update - SMCR
MyComplianceOffice
 
Is This Bribe Tax Deductible
Is This Bribe Tax DeductibleIs This Bribe Tax Deductible
Is This Bribe Tax Deductible
MyComplianceOffice
 
Best Practices to Achieve an Effective FCPA Compliance Program
Best Practices to Achieve an Effective FCPA Compliance ProgramBest Practices to Achieve an Effective FCPA Compliance Program
Best Practices to Achieve an Effective FCPA Compliance Program
MyComplianceOffice
 
The Evolving Regulatory Landscape: Insights for Compliance Officers
The Evolving Regulatory Landscape: Insights for Compliance OfficersThe Evolving Regulatory Landscape: Insights for Compliance Officers
The Evolving Regulatory Landscape: Insights for Compliance Officers
MyComplianceOffice
 
SEC & FINRA 2017 Priorities: A Midyear Update
SEC & FINRA 2017 Priorities: A Midyear UpdateSEC & FINRA 2017 Priorities: A Midyear Update
SEC & FINRA 2017 Priorities: A Midyear Update
MyComplianceOffice
 
Ready your Organisation: Senior Managers and Certification Regime
Ready your Organisation: Senior Managers and Certification RegimeReady your Organisation: Senior Managers and Certification Regime
Ready your Organisation: Senior Managers and Certification Regime
MyComplianceOffice
 
Foreign Corrupt Practices Act (FCPA) Compliance Webinar
Foreign Corrupt Practices Act (FCPA) Compliance WebinarForeign Corrupt Practices Act (FCPA) Compliance Webinar
Foreign Corrupt Practices Act (FCPA) Compliance Webinar
MyComplianceOffice
 

More from MyComplianceOffice (8)

Third Party Management - The Journey Continues…
Third Party Management - The Journey Continues…Third Party Management - The Journey Continues…
Third Party Management - The Journey Continues…
 
Regulatory Update - SMCR
Regulatory Update - SMCRRegulatory Update - SMCR
Regulatory Update - SMCR
 
Is This Bribe Tax Deductible
Is This Bribe Tax DeductibleIs This Bribe Tax Deductible
Is This Bribe Tax Deductible
 
Best Practices to Achieve an Effective FCPA Compliance Program
Best Practices to Achieve an Effective FCPA Compliance ProgramBest Practices to Achieve an Effective FCPA Compliance Program
Best Practices to Achieve an Effective FCPA Compliance Program
 
The Evolving Regulatory Landscape: Insights for Compliance Officers
The Evolving Regulatory Landscape: Insights for Compliance OfficersThe Evolving Regulatory Landscape: Insights for Compliance Officers
The Evolving Regulatory Landscape: Insights for Compliance Officers
 
SEC & FINRA 2017 Priorities: A Midyear Update
SEC & FINRA 2017 Priorities: A Midyear UpdateSEC & FINRA 2017 Priorities: A Midyear Update
SEC & FINRA 2017 Priorities: A Midyear Update
 
Ready your Organisation: Senior Managers and Certification Regime
Ready your Organisation: Senior Managers and Certification RegimeReady your Organisation: Senior Managers and Certification Regime
Ready your Organisation: Senior Managers and Certification Regime
 
Foreign Corrupt Practices Act (FCPA) Compliance Webinar
Foreign Corrupt Practices Act (FCPA) Compliance WebinarForeign Corrupt Practices Act (FCPA) Compliance Webinar
Foreign Corrupt Practices Act (FCPA) Compliance Webinar
 

Recently uploaded

Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
ssuser5750e1
 
WINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of DissolutionWINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of Dissolution
KHURRAMWALI
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
Abdul-Hakim Shabazz
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
9ib5wiwt
 
Law Commission Report. Commercial Court Act.
Law Commission Report. Commercial Court Act.Law Commission Report. Commercial Court Act.
Law Commission Report. Commercial Court Act.
Purushottam Jha
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Thomas (Tom) Jasper
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
9ib5wiwt
 
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptxRIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
OmGod1
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
MwaiMapemba
 
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptxNATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
anvithaav
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
9ib5wiwt
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptxASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
shweeta209
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
Dr. Oliver Massmann
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
9ib5wiwt
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
ssuser0576e4
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
9ib5wiwt
 
Introducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdfIntroducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdf
AHRP Law Firm
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
BRELGOSIMAT
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
BridgeWest.eu
 

Recently uploaded (20)

Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
WINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of DissolutionWINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of Dissolution
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
 
Law Commission Report. Commercial Court Act.
Law Commission Report. Commercial Court Act.Law Commission Report. Commercial Court Act.
Law Commission Report. Commercial Court Act.
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
 
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptxRIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
 
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptxNATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptxASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
 
Introducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdfIntroducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdf
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
 

Prepare Your Firm for GDPR

  • 1. Prepare your firm for GDPR Thursday, October 26, 2017
  • 3. 3 10 themes • Territorial Scope • Financial exposure • Consent • Transparency • Data protection impact assessments • Data protection officer • Security • Data processors • Accountability • Data subject rights
  • 4. 4 Data Protection reform - background • Current data protection rules: • based upon 1995 EU Directive • implemented separately in national laws • not fully harmonised • ‘GDPR’ = General Data Protection Regulation • will apply directly in all Member States • replaces 1995 Directive • comes into effect 25 May 2018
  • 5. 5 Data Protection principles • Same basic concepts and principles but generally tighter controls and greater emphasis on data subject rights • Fair, lawful and transparent processing • Purpose limitation • Data minimisation • Accuracy • Data retention • Data security • Accountability
  • 6. How many of you are based in the EU or outside the EU?
  • 7. 7 1 – Expanded Territorial Scope • Territorial scope significantly expanded under GDPR to cover: • offering goods or services to EU-based individuals; and • “monitoring the behaviour” of EU-based individuals. • GDPR will directly apply to FS firms and fintechs “established” in EU • GDPR may directly apply to: • FS firms and fintech established outside EU, i.e. Singapore if they target or offer services to EU-based individuals
  • 8. 8 2 – Increased financial exposure • Current rules across the EU differ – DPC cannot directly impose fines • Significant fines due under GDPR: o up to €10m or 2% of total worldwide annual turnover =  breaches of obligations of controller o up to €20m or 4% of total worldwide annual turnover =  breaches of obligations including the basic principles for processing (inc. consent), the data subjects’ rights and data transfers • GDPR contains a list of factors for determining level of fine (repeat offenders etc.) • Data subject claims: o explicit right to compensation for damage, both material and non-material (pecuniary loss?) o possible joint and several liability
  • 9. What is a data controller?
  • 10. 10 3 - Narrower interpretation of consent • Consent is more tightly defined ― a statement or clear affirmative act required ― distinct consent for each operation • Must prove you obtained consent • Consent separate from terms and conditions • Must be as easy to withdraw as it is to give it
  • 11. 11 4 - Increased transparency • Must have transparent, clear, concise and easily accessible privacy policy • Intelligible language adapted to data subjects • More information, e.g.: ― legal basis ― any specific legitimate interest relied upon ― how long you will keep data ― profiling, logic involved and effects ― implement appropriate technical / organisational measures • Notice for further processing
  • 12. 12 5 -Data Protection Impact Assessments • Must do a documented DPIA if high risk processing, eg ― systematic and extensive automated evaluation with legal effect / similarly significant affects DS ― large scale processing of sensitive data ― evaluation or scoring, including profiling and predicting • Where appropriate, seek views of data subjects representatives • Exclusion if based upon law that specifically regulates processing operations and DPIA already carried out for that law • May have to seek relevant data protection commissioner opinion if DPIA shows high risks not mitigated
  • 13. 13 6 - Data Protection Officer • Financial institutions/Fintechs may need to appoint a DPO • large scale processing of sensitive data; or • by virtue of processing, requires regular and systematic monitoring of data subjects on a large scale • Must be expert in data protection laws and practices • Report directly to highest management level; be properly involved with all activities dealing with personal data • Must provide DPO with sufficient resources • Can be group DPO • Can perform other tasks provided no conflict of interest • Protected role – cannot be removed or penalised for performing tasks • Can be outsourced
  • 14. 14 7 - Security • New security obligations: optional? o Pseudonymisation and encryption o Confidentiality, integrity, availability and resilience of IT systems o Restore availability and access o Testing of security measures
  • 15. 15 7 - Security breach • Notify DPC without undue delay and, where feasible, within 72 hours, unless unlikely to result in a risk • Processor must notify controller without undue delay • Must notify data subjects if likely to result in a high risk to privacy / rights (with some exceptions) • Must document breaches • Should have security breach response plan in place • Dual notification requirement may exist depending on the security breach – NCSC & DPC
  • 16. 16 8 – Data processors • Obligations for data processing agreements significantly expanded • The contract must now include: • the subject matter and duration of the processing • the nature and purposes of the processing • the type of personal data • the categories of data subjects • Additional obligatory provisions include that the processor: • makes information available to demonstrate compliance • contributes to audits and inspections • assists the controller regarding access requests, DPIAs and security breaches
  • 17. What is the correct definition of personal data under the GDPR?
  • 18. 18 9 - Accountability • DC / DP must document all processing activities, e.g.: ― categories of data subjects, recipients and data ― data transfers (including details of safeguards) ― retention / erasure period ― general description of security measures (if possible) • DC also must document purposes and (indirectly) legal bases ― AML Documentation • Should be consistent with privacy policy • Privacy by design/default
  • 19. 19 10 - Data subject rights • Right of restriction • accuracy contested or processing unlawful • no longer needed for original purpose, but necessary to establish, exercise or defend legal rights • pending verification where individual objects • Right to be erasure – ‘right to be forgotten’ • Variety of situations where individuals can request erasure • Subject access requests • Changes to cost, timelines and ability to refuse requests (Right to charge or refuse request if “manifestly unfounded or excessive”) • Right to data portability • Provide certain data in a machine-readable format • only applies if legitimised based upon consent or performance of a contrac • Right of rectification
  • 20. 20 10 - Data subject rights • Right to object ― applies if use legitimate interest or public interest test ― must then show overriding compelling legitimate grounds • Must inform data subject of right to object ― explicitly brought to their attention ― present clearly and separately from other information
  • 21. 21 Key points • Core principles broadly the same, but tighter controls • Greater accountability and shift in burden of proof • Increased records and compliance burden • Increased financial exposure • Broader data subject rights • 7 months to get it right, but time to start preparing is now
  • 22. 22 What to do now – step 1 (what are we doing)? • Data mapping exercise ― data flows and disclosures ― purpose and legitimisation mapping • Audit of data transfers (remember Brexit) • Audit of data related contracts • GDPR gap analysis and prioritisation
  • 23. 23 What to do now – Step 2 (moving forward)? • Use gap analysis to decide on key action points • Create internal accountability records • Update internal / external policies & contracts • Create any necessary new policies and templates, eg ― privacy by design / default playbook ― DPIA protocol and templates ― security breach response plan • Appoint DPO • Education
  • 25. 25 GDPR – What it means in Practice
  • 26. Q&A
  • 27. 27 MCO Platform • Manage by alerts not reports • Dashboards deliver greater oversight • Custom questionnaire builder • Continuous updates to the software • Enhanced control • 100% data capture • 24/7/365 support • Scalable into the future

Editor's Notes

  1. As we’ve seen at the start of the webinar, poor management of your risk and compliance program can be very expensive for the organization and indeed for the individuals concerned! MyComplianceOffice has been developed and refined to help you synchronize the demands of the regulators with the needs of the organization, and we do this through a range of integrated software modules that will automate and control your risk and compliance program. Risk and compliance management is a tough job and it is not easy to keep an organization compliant; one look at the fines tells us all about that. MCO can help you to automate your third party and vendor risk management program, your employee compliance program, your firms trading, and your customer management. This covers a very broad range of activities from employee trade management to gifts and entertainment and outside business activities. From vendor on-boarding to risk assessments and on-going due diligence. It is our job to enhance you reputation through better risk and compliance management across the board. If that sounds like something that you can benefit from, please let us know.