SlideShare a Scribd company logo
Why GDPR?
 The issues with how organisations manage data at
present
 What is GDPR and how will help protect
consumers?
 What do businesses need to know?
 4 steps to be GDPR compliant
Preparing for 25th May 2018
THE WORLD HAS CHANGED
Over 3 million
data records are lost or stolen
every day
Existing EU Directives are not enough to protect European Citizens
Data
Risks
Cloud-apps
Prospect
Data
Customer
Data
Marketing
Automation
Internal /
Employee
Records
Increased
Visibility /
Accessibility
Mobile
Workforce
Hackers
IoT
Suppliers
NEW RISKS
In 63% of all data breaches, third parties were implicated
 DropBox, SharePoint or Google Docs? -
 98% of cloud apps aren’t GDPR-ready
 IoT only complicates GDPR further
Source: http://www.jdsupra.com/legalnews/third-party-data-breaches-weakest-link-98330/
OVERVIEW OF EU GENERAL DATA PROTECTION
REGULATION
 General Data Protection Regulation – enforced by EU
 Expands on some parts of DPA/existing Directive;
creates other new requirements
 Determines how personal data should be processed
and used
 Comes into effect on 25 May 2018, regardless of
Brexit
What is GDPR?
SO WHAT?
 Impacts every data controller and processor dealing
with data on subjects in Europe
 79 times higher than previous fines
Potential fines of up to 4% of your organisation’s annual turnover or €20,000,000 – Whichever
is higher
Who? Means:
Data subject Any EU citizen who has entrusted a controller with
their personal data.
Customers, service users, employees
Data
controller
Who the data subject entrusts with their data.
Responsible for deciding how the data is handled.
Data
processor
Any entity that handles personal data on the data
controller's behalf.
What do businesses need to know?
What’s new?
 Expanded definition of “personal data”
 Transparency and consent
 Enhanced rights for data subjects
 Accountability
 Data protection by design
 Notifying subjects of data breaches
New rights you need to know
Rights
to
Be informed
Access
Rectification
Erasure
Restrict
Processsing
Data
Portability
Object
Personal data
Any form of automated data processing to analyse or predict:
 Performance at work
 Economic situation
 Health
 Personal preferences
 Reliability
 Behaviour
 Location
 Movements
Are you keeping, or planning to keep:
Personal or sensitive data such as
cookies, IP addresses, biometric data,
genetic data?
4 Requirements for Your Data Protection Policy
1) Legal basis for processing
2) Legitimate interests (if any)
3) Right to lodge complaint
4) How long data will be retained
Clear, concise and accessible
Consent
 Freely given, specific, informed and unambiguous
 Clear affirmative action
 Provided separately from other written agreements
 Verifiable
 As easily withdrawn as given
Hint!
Large and complex structured
organisations benefit from an
EQMS to manage policies and
procedures, approval workflows
and monitor compliance
activity.
Make employees accountable:
http://quality.eqms.co.uk/eqms
-datasheets-download
Get your policies and processes in order
Poor Passwords
Weak remote access
Unpatched flaws
Misconfigurations
Malicious Insider
http://www.computerworlduk.com/security/most-data-breaches-still-discovered-by-third-parties-3615783/
The average time between breach
and discovery is
188 DAYS
DATA BREACHES ARE USUALLY PREVENTABLE
Protect your reputation with proactive policies, employee training & robust systems
Notification of data breaches
Destroyed, lost, altered, disclosed to or accessed by
unauthorised people
Reported to:
 Supervisory authority
 Discrimination, reputational damage, financial loss,
confidentiality
 Individual(s) affected
 Same, but high risk
Report within 72 hours of breach
Accountability is key
Hint!
EQMS Workflow Manager
assigns responsibility and
manages incidents such as a
data breach through to
completion. Everyone knows
what they are doing, when.
Make employees accountable:
http://quality.eqms.co.uk/eqms
-software-demonstration
Accountability – Data protection by design
Must demonstrate compliance with GDPR - How?
 Policies and procedures (audits, HR policies)
 Staff training
 Pseudonymisation
 Data protection impact assessments
 Appointing data protection officer
Robust systems to protect employees and customers
Hint!
EQMS provides a robust
framework for managing
business processes. Manage
policies, assign responsibility
and use the audit trail function
to demonstrate compliance
activity.
Read more:
http://quality.eqms.co.uk/eqms
-software-demonstration
Enhanced rights for data subjects
Right to:
 Confirmation that data is being processed
 Receive data
 Rectify any inaccurate or incomplete data
 ‘Be forgotten’
 Restrict processing of data
 Obtain and re-use data for own purposes
Accountability is key
Example Timeline for GDPR Compliance Training
 Workshop with high interest / high power stakeholders:
 What data do we have?
 What data are we planning to have?
 How can we minimise risk? E.g. pseudonymisation.
 Make department managers accountable for the data they capture:
 Has each department manager completed a data protection impact assessment? (Use EQMS Audit
Manager & assign audit to be completed by each department manager.)
 Are the policies sufficient?
 Are controls in place to demonstrate opt-in?
 Do we need to get permission to continue using this data?
 Do we need a Data Protection Officer?
 Roll out training Train employees on the new GDPR requirements - EQMS Training Record Manager
 Employees aware & engaged with their GDPR requirements. (Use EQMS Training Manager training
matrix to easily manage which employees have outstanding training requriements)
Steps to getting GDPR-ready
ISO 27001 PROVIDES A FRAMEWORK FOR
GDPR COMPLIANCE
What might your business need to do?
Steps to compliance
 Review data protection policies
 Establish legal basis for processing
 Identify how to demonstrate compliance
 Consider whether to appoint DPO
1) Review policies
 Individuals told about right to object, at first communication
 Understanding of what constitutes “data breach” – more than loss of data
 Procedures for detecting, investigating and reporting breaches
 Insurance coverage in case of breach
2) Establish legal basis for processing
Be clear on grounds for lawful processing
If consent:
 Obtained correctly, as mentioned earlier
 Subjects informed of right to withdraw at any time, and given
simple methods to do so
3) Demonstrate compliance
New policies – data protection by design
Regular audits
Staff training
Pseudonymisation
Review and update existing information notices
4) Consider a data protection officer
Informs and advises on obligations
Monitors compliance – manages internal activities and audits, trains staff
First point of contact for supervisory authorities and data subjects
Compulsory that DPO:
 Reports to board/directors
 Independent, and not penalised for performing job
 Has resources to meet obligations
Can be existing employee as long as compatible and no conflict of interest
No qualifications, but should have professional experience and knowledge of law
25 May 2018
DOWNLOAD GDPR TOOLKIT
Q U A L I T Y . E Q M S . C O . U K / G D P R - G E N E R A L - D A T A - P R O T E C T I O N - R E G U L A T I O N - E U - T O O L K I T

More Related Content

What's hot

GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
Craig Clark ITIL, CIS LI,EU GDPR P
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
Iain Wicks MCIPR
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Cvent
 
Privacy & Data Protection in the Digital World
Privacy & Data Protection in the Digital WorldPrivacy & Data Protection in the Digital World
Privacy & Data Protection in the Digital World
Arab Federation for Digital Economy
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer Update
TrustArc
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
The Pathway Group
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
sp_krishna
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Caroline Boscher
 
Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...
Peter Procházka
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
David Erdos
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
Martin Hawksey
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentationOvationsGroup
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
Dimitri Sirota
 
DATA PROTECTION LAWS OF THE WORLD
DATA PROTECTION LAWS OF THE WORLDDATA PROTECTION LAWS OF THE WORLD
DATA PROTECTION LAWS OF THE WORLD
Jason Rusch - CISSP CGEIT CISM CISA GNSA
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
Priyab Satoshi
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
Acquia
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
CILIP Ireland
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
IT Governance Ltd
 
GDPR training
GDPR training GDPR training
GDPR training
ASL
 

What's hot (20)

GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Privacy & Data Protection in the Digital World
Privacy & Data Protection in the Digital WorldPrivacy & Data Protection in the Digital World
Privacy & Data Protection in the Digital World
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer Update
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentation
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
DATA PROTECTION LAWS OF THE WORLD
DATA PROTECTION LAWS OF THE WORLDDATA PROTECTION LAWS OF THE WORLD
DATA PROTECTION LAWS OF THE WORLD
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
GDPR training
GDPR training GDPR training
GDPR training
 

Similar to Preparing for GDPR: General Data Protection Regulation - Stakeholder Presentation

Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
Sirius
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
Nate Stockard
 
Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)
Gerson Trigueiros
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
►David Clarke FBCS CITP
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
MRS
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?
Per Norhammar
 
What is Information Governance
What is Information GovernanceWhat is Information Governance
What is Information Governance
Atle Skjekkeland
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
Vuzion
 
DLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesDLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The Challenges
Napier University
 
Setting the right GDPR priorities
Setting the right GDPR prioritiesSetting the right GDPR priorities
Setting the right GDPR priorities
Alberto Canadè
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
EQS Group
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
zayadeen2003
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protection
meritnorthwest
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
Jonathan Chilton
 
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
David Kearney
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
Ray ABOU
 
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to SuccessAddressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Sirius
 

Similar to Preparing for GDPR: General Data Protection Regulation - Stakeholder Presentation (20)

Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?
 
What is Information Governance
What is Information GovernanceWhat is Information Governance
What is Information Governance
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
DLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesDLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The Challenges
 
Setting the right GDPR priorities
Setting the right GDPR prioritiesSetting the right GDPR priorities
Setting the right GDPR priorities
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protection
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
 
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to SuccessAddressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
 

More from Qualsys Ltd

Audits, inspections and reporting -
Audits, inspections and reporting - Audits, inspections and reporting -
Audits, inspections and reporting -
Qualsys Ltd
 
Qualsys and sirus
Qualsys and sirus Qualsys and sirus
Qualsys and sirus
Qualsys Ltd
 
How to Audit Leadership
How to Audit LeadershipHow to Audit Leadership
How to Audit Leadership
Qualsys Ltd
 
Qualsys GXP presentation
Qualsys GXP  presentation Qualsys GXP  presentation
Qualsys GXP presentation
Qualsys Ltd
 
APQP Training presentation
APQP Training  presentationAPQP Training  presentation
APQP Training presentation
Qualsys Ltd
 
As 9100 D QMS Training Materials
As 9100 D QMS Training Materials As 9100 D QMS Training Materials
As 9100 D QMS Training Materials
Qualsys Ltd
 
Culture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training WorkshopCulture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training Workshop
Qualsys Ltd
 
ISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management SoftwareISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management Software
Qualsys Ltd
 
8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training 8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training
Qualsys Ltd
 
Lean six sigma explained: Beginners training
Lean six sigma explained: Beginners trainingLean six sigma explained: Beginners training
Lean six sigma explained: Beginners training
Qualsys Ltd
 
Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study
Qualsys Ltd
 
Best practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and SourcingBest practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and Sourcing
Qualsys Ltd
 
ISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentation
Qualsys Ltd
 
ISO 19011 Revision
ISO 19011 RevisionISO 19011 Revision
ISO 19011 Revision
Qualsys Ltd
 
How to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance SoftwareHow to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance Software
Qualsys Ltd
 
Embedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 FocusEmbedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 Focus
Qualsys Ltd
 
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
Qualsys Ltd
 
Equipment maintenance management: implementation
Equipment maintenance management: implementationEquipment maintenance management: implementation
Equipment maintenance management: implementation
Qualsys Ltd
 
Global Quality Survey Results 2016
Global Quality Survey Results 2016Global Quality Survey Results 2016
Global Quality Survey Results 2016
Qualsys Ltd
 
Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015
Qualsys Ltd
 

More from Qualsys Ltd (20)

Audits, inspections and reporting -
Audits, inspections and reporting - Audits, inspections and reporting -
Audits, inspections and reporting -
 
Qualsys and sirus
Qualsys and sirus Qualsys and sirus
Qualsys and sirus
 
How to Audit Leadership
How to Audit LeadershipHow to Audit Leadership
How to Audit Leadership
 
Qualsys GXP presentation
Qualsys GXP  presentation Qualsys GXP  presentation
Qualsys GXP presentation
 
APQP Training presentation
APQP Training  presentationAPQP Training  presentation
APQP Training presentation
 
As 9100 D QMS Training Materials
As 9100 D QMS Training Materials As 9100 D QMS Training Materials
As 9100 D QMS Training Materials
 
Culture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training WorkshopCulture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training Workshop
 
ISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management SoftwareISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management Software
 
8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training 8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training
 
Lean six sigma explained: Beginners training
Lean six sigma explained: Beginners trainingLean six sigma explained: Beginners training
Lean six sigma explained: Beginners training
 
Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study
 
Best practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and SourcingBest practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and Sourcing
 
ISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentation
 
ISO 19011 Revision
ISO 19011 RevisionISO 19011 Revision
ISO 19011 Revision
 
How to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance SoftwareHow to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance Software
 
Embedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 FocusEmbedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 Focus
 
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
 
Equipment maintenance management: implementation
Equipment maintenance management: implementationEquipment maintenance management: implementation
Equipment maintenance management: implementation
 
Global Quality Survey Results 2016
Global Quality Survey Results 2016Global Quality Survey Results 2016
Global Quality Survey Results 2016
 
Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015
 

Recently uploaded

Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
PaulBryant58
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
zoyaansari11365
 
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckPitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
HajeJanKamps
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
dylandmeas
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
tanyjahb
 
chapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationchapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxation
AUDIJEAngelo
 
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptxCADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
fakeloginn69
 
Attending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learnersAttending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learners
Erika906060
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
dylandmeas
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
usawebmarket
 
PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop.com LTD
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
Workforce Group
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
HARSHITHV26
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
Ben Wann
 
Role of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in MiningRole of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in Mining
Naaraayani Minerals Pvt.Ltd
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Navpack & Print
 

Recently uploaded (20)

Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
 
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckPitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
 
chapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationchapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxation
 
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptxCADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
 
Attending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learnersAttending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learners
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
 
PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Role of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in MiningRole of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in Mining
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
 

Preparing for GDPR: General Data Protection Regulation - Stakeholder Presentation

  • 1. Why GDPR?  The issues with how organisations manage data at present  What is GDPR and how will help protect consumers?  What do businesses need to know?  4 steps to be GDPR compliant Preparing for 25th May 2018
  • 2. THE WORLD HAS CHANGED Over 3 million data records are lost or stolen every day Existing EU Directives are not enough to protect European Citizens
  • 3. Data Risks Cloud-apps Prospect Data Customer Data Marketing Automation Internal / Employee Records Increased Visibility / Accessibility Mobile Workforce Hackers IoT Suppliers NEW RISKS In 63% of all data breaches, third parties were implicated  DropBox, SharePoint or Google Docs? -  98% of cloud apps aren’t GDPR-ready  IoT only complicates GDPR further Source: http://www.jdsupra.com/legalnews/third-party-data-breaches-weakest-link-98330/
  • 4. OVERVIEW OF EU GENERAL DATA PROTECTION REGULATION  General Data Protection Regulation – enforced by EU  Expands on some parts of DPA/existing Directive; creates other new requirements  Determines how personal data should be processed and used  Comes into effect on 25 May 2018, regardless of Brexit What is GDPR?
  • 5. SO WHAT?  Impacts every data controller and processor dealing with data on subjects in Europe  79 times higher than previous fines Potential fines of up to 4% of your organisation’s annual turnover or €20,000,000 – Whichever is higher Who? Means: Data subject Any EU citizen who has entrusted a controller with their personal data. Customers, service users, employees Data controller Who the data subject entrusts with their data. Responsible for deciding how the data is handled. Data processor Any entity that handles personal data on the data controller's behalf.
  • 6. What do businesses need to know?
  • 7. What’s new?  Expanded definition of “personal data”  Transparency and consent  Enhanced rights for data subjects  Accountability  Data protection by design  Notifying subjects of data breaches New rights you need to know Rights to Be informed Access Rectification Erasure Restrict Processsing Data Portability Object
  • 8. Personal data Any form of automated data processing to analyse or predict:  Performance at work  Economic situation  Health  Personal preferences  Reliability  Behaviour  Location  Movements Are you keeping, or planning to keep: Personal or sensitive data such as cookies, IP addresses, biometric data, genetic data?
  • 9. 4 Requirements for Your Data Protection Policy 1) Legal basis for processing 2) Legitimate interests (if any) 3) Right to lodge complaint 4) How long data will be retained Clear, concise and accessible
  • 10. Consent  Freely given, specific, informed and unambiguous  Clear affirmative action  Provided separately from other written agreements  Verifiable  As easily withdrawn as given Hint! Large and complex structured organisations benefit from an EQMS to manage policies and procedures, approval workflows and monitor compliance activity. Make employees accountable: http://quality.eqms.co.uk/eqms -datasheets-download Get your policies and processes in order
  • 11. Poor Passwords Weak remote access Unpatched flaws Misconfigurations Malicious Insider http://www.computerworlduk.com/security/most-data-breaches-still-discovered-by-third-parties-3615783/ The average time between breach and discovery is 188 DAYS DATA BREACHES ARE USUALLY PREVENTABLE Protect your reputation with proactive policies, employee training & robust systems
  • 12. Notification of data breaches Destroyed, lost, altered, disclosed to or accessed by unauthorised people Reported to:  Supervisory authority  Discrimination, reputational damage, financial loss, confidentiality  Individual(s) affected  Same, but high risk Report within 72 hours of breach Accountability is key Hint! EQMS Workflow Manager assigns responsibility and manages incidents such as a data breach through to completion. Everyone knows what they are doing, when. Make employees accountable: http://quality.eqms.co.uk/eqms -software-demonstration
  • 13. Accountability – Data protection by design Must demonstrate compliance with GDPR - How?  Policies and procedures (audits, HR policies)  Staff training  Pseudonymisation  Data protection impact assessments  Appointing data protection officer Robust systems to protect employees and customers Hint! EQMS provides a robust framework for managing business processes. Manage policies, assign responsibility and use the audit trail function to demonstrate compliance activity. Read more: http://quality.eqms.co.uk/eqms -software-demonstration
  • 14. Enhanced rights for data subjects Right to:  Confirmation that data is being processed  Receive data  Rectify any inaccurate or incomplete data  ‘Be forgotten’  Restrict processing of data  Obtain and re-use data for own purposes Accountability is key
  • 15. Example Timeline for GDPR Compliance Training  Workshop with high interest / high power stakeholders:  What data do we have?  What data are we planning to have?  How can we minimise risk? E.g. pseudonymisation.  Make department managers accountable for the data they capture:  Has each department manager completed a data protection impact assessment? (Use EQMS Audit Manager & assign audit to be completed by each department manager.)  Are the policies sufficient?  Are controls in place to demonstrate opt-in?  Do we need to get permission to continue using this data?  Do we need a Data Protection Officer?  Roll out training Train employees on the new GDPR requirements - EQMS Training Record Manager  Employees aware & engaged with their GDPR requirements. (Use EQMS Training Manager training matrix to easily manage which employees have outstanding training requriements) Steps to getting GDPR-ready
  • 16. ISO 27001 PROVIDES A FRAMEWORK FOR GDPR COMPLIANCE
  • 17. What might your business need to do?
  • 18. Steps to compliance  Review data protection policies  Establish legal basis for processing  Identify how to demonstrate compliance  Consider whether to appoint DPO
  • 19. 1) Review policies  Individuals told about right to object, at first communication  Understanding of what constitutes “data breach” – more than loss of data  Procedures for detecting, investigating and reporting breaches  Insurance coverage in case of breach
  • 20. 2) Establish legal basis for processing Be clear on grounds for lawful processing If consent:  Obtained correctly, as mentioned earlier  Subjects informed of right to withdraw at any time, and given simple methods to do so
  • 21. 3) Demonstrate compliance New policies – data protection by design Regular audits Staff training Pseudonymisation Review and update existing information notices
  • 22. 4) Consider a data protection officer Informs and advises on obligations Monitors compliance – manages internal activities and audits, trains staff First point of contact for supervisory authorities and data subjects Compulsory that DPO:  Reports to board/directors  Independent, and not penalised for performing job  Has resources to meet obligations Can be existing employee as long as compatible and no conflict of interest No qualifications, but should have professional experience and knowledge of law
  • 24. DOWNLOAD GDPR TOOLKIT Q U A L I T Y . E Q M S . C O . U K / G D P R - G E N E R A L - D A T A - P R O T E C T I O N - R E G U L A T I O N - E U - T O O L K I T

Editor's Notes

  1. General Data Protection Regulation Today's presentation is about the General Data Protection Regulation (GDPR), a new data protection law. First of all, bit of background information on the regulation – why it's being enforced and so on. Then go into a little more detail about what it means for businesses – how businesses will be affected, what they'll need to do to make sure they comply. Finish off by focusing on what it means for Qualsys in particular.
  2. General Data Protection Regulation
  3. General Data Protection Regulation
  4. General Data Protection Regulation It's the General Data Protection Regulation, and it's being enforced by the EU. Broadly similar to the UK Data Protection Act, deals with things such as fairness, lawfulness, transparency, data security, and confidentiality. Data protection laws in force in most EU countries for about 20 years, so many organisations already have basics in place and won’t need to make too many adjustments. It’s the first global data protection law in that any company worldwide that works with information relating to EU citizens MUST COMPLY. Not just limited to companies based in the EU. Centred around the use of “personal data”, which has always been a fairly broad definition but has changed a little in regards to GDPR. Comes into effect on 25 May 2018, regardless of Brexit.
  5. General Data Protection Regulation It's the General Data Protection Regulation, and it's being enforced by the EU. Broadly similar to the UK Data Protection Act, deals with things such as fairness, lawfulness, transparency, data security, and confidentiality. Data protection laws in force in most EU countries for about 20 years, so many organisations already have basics in place and won’t need to make too many adjustments. It’s the first global data protection law in that any company worldwide that works with information relating to EU citizens MUST COMPLY. Not just limited to companies based in the EU. Centred around the use of “personal data”, which has always been a fairly broad definition but has changed a little in regards to GDPR. Comes into effect on 25 May 2018, regardless of Brexit.
  6. General Data Protection Regulation
  7. General Data Protection Regulation Businesses will already be complying with the Data Protection Act and the existing EU Directive. But what new requirements does GDPR enforce? Expands definition of "personal data" – brings in some new categories of data that have mostly arisen due to the proliferation of the internet Transparency and consent – new requirements around obtaining permission from individuals to use their personal data, and justifying why you're using it Enhanced rights – GDPR gives data subjects several new rights, which we'll look at Accountability – holding organisations accountable is a big part of the new regulation. Organisations expected to adopt significant new measures to demonstrate that they're complying with GDPR.
  8. Expands definition set out in the DPA and the previous EU directive. "Personal data" still means things like names, ID numbers and physical information, but now also covers location data and online identifiers such as IP addresses and cookies. Data protection laws use the term "sensitive personal data" to cover things like race/ethnicity, politics, religious beliefs, sexual orientation etc. GDPR does the same, but also includes biometric and genetic data. Biometric data = any data relating to a person's physical, physiological or behavioural characteristics which allows them to be identified. Genetic data = any data relating to characteristics someone has inherited and which allows information about their health to be identified. As most organisations keep only HR records, customer lists, contact details etc., the change should make little practical difference. Can assume that if you hold information that falls within the scope of the DPA, also falls within the scope of the GDPR.
  9. General Data Protection Regulation Organisations have a duty to tell individuals how their personal data is processed. And they must do so in a format which is clear, concise and easily accessible. That information must include the legal basis for processing. For data processing to be legal under the GDPR, organisations must document why they're processing the data because this legal basis determines the individual's rights. If you're processing someone's data because they've explicitly given you their consent, for example, that person will generally have stronger rights. Other legal bases for processing data might be: Necessary to obey the law Necessary to perform a task in the public interest The information should also include details of any legitimate interests the organisation has for using the data. That could be direct marketing, preventing fraud, or making sure the IT networks are secure. The data subject should be told what right they have to lodge a complaint about how their data is stored and used, and how long their data will be retained.
  10. General Data Protection Regulation GDPR refers to both ‘consent’ and ‘explicit consent’, but is unclear as to the difference given that both forms have to be freely given, specific, informed and an unambiguous indication of the individual’s wishes. Consent under the GDPR requires some form of clear affirmative action, whether that's clicking a tick box or actively choosing a setting. Just because the person hasn't specifically said no doesn't mean they've said yes. And pre-ticked boxes are now banned. Consent to processing must be distinguishable, clear, and not “bundled” in with other written agreements. Consent must be verifiable. So some form of record must be kept of how and when the person gave their consent. Individuals have a right to withdraw consent at any time, and doing this should be as easy as it was for them to give their consent.
  11. General Data Protection Regulation At present, the average time between data breach and discover is 188 days. Under the new GDPR rules, this is not going to be acceptable. More robust systems are required to protect your organisation, customer and suppliers.
  12. General Data Protection Regulation Under GDPR, all organisations have a duty to report certain types of data breach to the relevant authority, and in some cases to the individuals affected. A personal data breach means a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. For example, a hospital could be responsible for a personal data breach if a patient’s health record is inappropriately accessed due to a lack of appropriate internal controls. So a breach is more than just losing personal data. An organisation only has to notify the relevant supervisory authority of a breach where it is likely to put people's rights and freedoms at risk – so that might be causing discrimination, reputational damage, financial loss, or a loss of confidentiality. Where a breach is likely to put people's rights and freedoms at high risk, the organisation must notify those concerned directly. So the threshold for notifying individuals is higher than for notifying the relevant supervisory authority. A breach of this kind must be reported to the relevant supervisory authority within 72 hours of the organisation becoming aware of it. If the breach is serious enough to warrant notifying the public, the organisation must do so straight away. Failing to give notice of a breach could lead to a fine of up to 10 million Euros or two per cent of the business's global turnover.
  13. General Data Protection Regulation Accountability has always been an important element of data protection law, but the GDPR gives it more significance. "Data protection by design" means promoting privacy and data protection compliance from the start when beginning a new project (might be building a new IT system, or an initiative to share data with other organisations). Under the Data Protection Act, it was always a recommendation rather than an obligation. Under GDPR, organisations must be able to demonstrate their compliance with the principles of the regulation. How to do this? Could: Build into policies and procedures – e.g. new HR policies, carrying out regular audits Implement staff training programmes Use pseudonymisation – which is processing personal data in such a way that it can no longer be attributed to a specific "data subject" without the use of additional information, which must be kept separately and subject to the same measures If processing "high risk" data, now a formal requirement to carry out a data protection impact assessment to identify risks of non-compliance. Assessment must include a description of how and why data is processed, the risks involved, and measures employed to mitigate those risks. Any organisation can appoint a data protection officer (DPO) but public authorities, and organisations who process sensitive data or criminal records on a large scale or regularly monitor data subjects (e.g. tracking online behaviour), MUST do so.
  14. General Data Protection Regulation The GDPR gives data subjects a number of new rights when it comes to their personal data. They're entitled to: confirmation that their data is being processed, and to see a copy of that data have their personal data rectified if it's inaccurate or incomplete 'be forgotten' – so they can ask for their data to be deleted or removed if there's no longer a compelling reason for it to be processed restrict their personal data from being processed – for example, they might contest its accuracy, or need it for a legal claim. If processing is restricted, the organisation can store the data, just not process it obtain and reuse their personal data as they see fit.
  15. General Data Protection Regulation Accountability has always been an important element of data protection law, but the GDPR gives it more significance. "Data protection by design" means promoting privacy and data protection compliance from the start when beginning a new project (might be building a new IT system, or an initiative to share data with other organisations). Under the Data Protection Act, it was always a recommendation rather than an obligation. Under GDPR, organisations must be able to demonstrate their compliance with the principles of the regulation. How to do this? Could: Build into policies and procedures – e.g. new HR policies, carrying out regular audits Implement staff training programmes Use pseudonymisation – which is processing personal data in such a way that it can no longer be attributed to a specific "data subject" without the use of additional information, which must be kept separately and subject to the same measures If processing "high risk" data, now a formal requirement to carry out a data protection impact assessment to identify risks of non-compliance. Assessment must include a description of how and why data is processed, the risks involved, and measures employed to mitigate those risks. Any organisation can appoint a data protection officer (DPO) but public authorities, and organisations who process sensitive data or criminal records on a large scale or regularly monitor data subjects (e.g. tracking online behaviour), MUST do so.
  16. General Data Protection Regulation
  17. General Data Protection Regulation
  18. General Data Protection Regulation
  19. General Data Protection Regulation Our data protection policies must ensure that we tell people, during our first contact with them, that they have a right to object to our processing their data. All our staff will need to understand what constitutes a data breach, and that this is more than just a loss of data. We'll need to have internal procedures in place for detecting, investigating and reporting breaches. This will help us to decide who we need to notify. If there is a data breach and someone without the correct authority gets access to it, then the IT teams need to be able to implement appropriate measures to render the data unintelligible. We might also need to review our insurance policies to assess the extent of our coverage in case of any data breaches.
  20. General Data Protection Regulation In Qualsys's case, our legal basis for processing is likely to be that we're doing so with the subject's consent. If other reasons apply, we'll need to have processes that allow us to demonstrate how we've reached decisions on how we use data. If we're using consent as our basis for lawful processing, we need to make sure it's consent we've obtained correctly, in line with the provisions mentioned earlier. So clear affirmative action, consent given separately, and so on. We also need to ensure we make data subjects’ aware of the right to withdraw their consent at any time, and provide them with simple methods to do so.
  21. General Data Protection Regulation To demonstrate our compliance with GDPR, we’ll need to draw up a data protection policy. And if we do that from a data-protection-by-design standpoint, we can make sure we’re promoting privacy and data protection compliance from the very beginning. We can also strengthen our compliance by building certain measures into the policy, so, for example, conducting regular audits, training staff in data protection principles, pseudonymisation and so on.
  22. General Data Protection Regulation If we decide to appoint a DPO, there are a number of things we need to do to make sure they can operate to the best of their ability. As part of their role, the DPO would be: informing and advising the company about our obligations to comply with GDPR and other data protection laws; monitoring our compliance – including: managing internal data protection activities advising on data protection impact assessments training staff, and conducting internal audits; and the first point of contact for supervisory authorities and for individuals whose data is processed (employees, customers etc.). It’s compulsory that the DPO: reports to the board/directors operates independently and is not penalised for doing their job has sufficient resources to meet their GDPR obligations The DPO can be recruited from our existing pool of employees, but their duties would need to be compatible and avoid any conflict of interest. Whoever was chosen would not need any special qualifications, but should have professional experience and knowledge of data protection law.
  23. General Data Protection Regulation So, to finish, we know that in a year’s time there will be a new EU regulation that determines how businesses such as ours handle people’s personal data. We know that: the regulation gives people much stronger rights over their data we’ll have to be more transparent about how we use people’s data, and we’ll have a duty to demonstrate how we’re complying with the regulation overall. To do that, we’ll need to: review our policies and procedures establish our legal basis for using people’s data, and think about whether we need to appoint a data protection officer to do all the work for us.
  24. General Data Protection Regulation