SlideShare a Scribd company logo
www.nexsenpruet.comto Upstate Alliance
INTRODUCTION
2
• What do we mean by “privacy”?
• The American approach to privacy regulation
• GDPR: An overview
• GDPR: The shape of things to come?
www.nexsenpruet.comto Upstate Alliance 3
‣ 1937
‣ 1890
‣ 1985
‣ 1964
When was the first major publication advocating a right to privacy published?
POP QUIZ!
www.nexsenpruet.comto Upstate Alliance 4
Louis Brandeis & Samuel Warren, “The Right to Privacy,”
Harvard Law Review (1890)
Defining “privacy” as “the right to be let alone.”
When was the first major publication advocating a right to privacy published?
1890
www.nexsenpruet.comto Upstate Alliance
HOW DO WE DEFINE PRIVACY IN THE 21ST CENTURY?
5
“Privacy encompasses the rights and obligations of individuals and organizations
with respect to the collection, use, retention, disclosure, and disposal of personal
information.” – American Institute of Certified Public Accountants
• Two key principles:
• The appropriate use of personal information under the circumstances.
• The individual’s right to control the collection, use, and disclosure of personal
information.
www.nexsenpruet.comto Upstate Alliance
HOW DO WE DEFINE PRIVACY IN THE 21ST CENTURY?
6
Rights
Of the individual
Of the organization
Obligations
Of the Individual
Of the organization
www.nexsenpruet.comto Upstate Alliance
U.S. vs. EU Treatment of Privacy
7
United States
Some constitutional protection
Commercial processing of personal
information accepted (“Opt Out”)
Controls on processing are sectoral
European Union
Privacy as a human right
Default = No processing (“opt in”)
Uniform, across-the-board regulation
www.nexsenpruet.comto Upstate Alliance
U.S. vs. EU Treatment of Privacy
8
United States
“Sensitive Personal Information”
• Social Security Number
• Financial Information (account
numbers, etc.)
• Driver’s License Number
• Medical Records
European Union
“Special Categories of Data”
• Racial or Ethnic Origin
• Political Opinions
• Trade Union Membership
• Criminal Convictions
www.nexsenpruet.comto Upstate Alliance
U.S. = Sectoral Approach
aka “Land of the Acronym”
9
• CAN-SPAM
• VPPA
• COPPA
• FERPA
• FCRA
• FACTA
• GLBA
• HIPAA
• HI-TECH
• GINA
Medical Financial
ConsumerEducational
www.nexsenpruet.comto Upstate Alliance
EU Approach: Across-the-Board Regulation
10
OECD Guidelines - 1980
Collection Limitation
Data Quality
Purpose Specification
Use Limitation
Security Safeguards
Openness
Individual Participation
Accountability
www.nexsenpruet.comto Upstate Alliance
EU Approach: Across-the-Board Regulation
11
Council of Europe
Convention for the Protection of Individuals with regard to
Automatic Processing of Personal Data, 1981
Public/Private Sectors
Trans-border Data Flows
Mutual Assistance
www.nexsenpruet.comto Upstate Alliance
EU Approach: Across-the-Board Regulation
12
European Data Directive (Directive 94/95/EC), 1995
Encompasses many principles now found in
the GDPR
Intended to encourage uniformity within the
EU, but
Not binding on member states
www.nexsenpruet.comto Upstate Alliance
EU Approach: Across-the-Board Regulation
13
www.nexsenpruet.comto Upstate Alliance
GDPR
14
• Adopted 14 April 2016
• Effective 25 May 2018
• Binding on EU countries (no enabling
legislation necessary)
• Britain is not Brexiting from GDPR
www.nexsenpruet.comto Upstate Alliance
GDPR
15
• Data Subject: A living, natural person who is in the EU, regardless of residence or nationality.
• Personal Data: Any information relating to an identified or identifiable Data Subject (“PII”).
• Sensitive Personal Data: Origin, beliefs, opinions, union membership, biometric data, sex life/orientation
• Processing: Any operation performed on PII, from collection through disposal.
• Controller: The person (natural or legal) who decides what PII will be collected and how it will be processed.
• Processor: The person (natural or legal) who processes PII on behalf of a controller
GDPR Glossary
www.nexsenpruet.comto Upstate Alliance
GDPR
16
• Data Protection by Design & Default
• Transparency
• Minimization
• Lawful Basis for Processing
• Data Subjects’ Rights
• Accountability
Key Points
www.nexsenpruet.comto Upstate Alliance
GDPR
17
• Data Protection by Design
• Address information security at the front end of software development,
not as an afterthought;
• De-identification of PII;
• Standards for international transfers
• Data Protection by Default
• Privacy settings “on” by default
• Opt-in, not opt-out
Data Protection
www.nexsenpruet.comto Upstate Alliance
GDPR
18
• Disclosure: Data subjects are entitled to know:
• What PII is being collected & how long it will be kept
• How PII is being used
• The specific legal basis for each and every use of PII
• Their rights, and how to exercise them
• Accessibility: Disclosures must be:
• Written in “clear and plain language”
• Easy to locate
Transparency
www.nexsenpruet.comto Upstate Alliance
GDPR
19
• Collection of PII should be:
• Limited in scope to the data that is adequate and relevant to
the intended use
• Limited in time to the period necessary to achieve the
purpose for which the data was collected
• As accurate as reasonably possible
Minimization
www.nexsenpruet.comto Upstate Alliance
GDPR
20
• Consent
• Genuine choice
• Affirmative opt-in
• Specific and granular
• Contract
• Provide information
• Fulfill a contract
• Legal obligation
• Vital Interests
Lawful Basis for Processing
• Public Tasks
• Legitimate Interests of the
Controller
• Consider data subject’s expectations
• Requires assessment/analysis
• For example:
• Security/network integrity
• Analytics
• Performance improvement
• B2B marketing
www.nexsenpruet.comto Upstate Alliance
GDPR
21
• To Be Informed
• To Object
• To Restrict Processing
• To Access
Data Subjects’ Rights
• To Correction
• To Portability
• To Erasure (aka “the right
to be forgotten”)
www.nexsenpruet.comto Upstate Alliance
GDPR
22
• Compliance
• Documentation of Legitimate Interests Analysis, Data
Protection Impact Assessment
• Designated Privacy Officer
• Supervising Processors
• Enforcement
• Data Protection Authority (each EU member state)
• Remedies range from reprimand to fine of 4% of worldwide
revenue or €20,000,000 – whichever is higher
Accountability
www.nexsenpruet.comto Upstate Alliance
GDPR
23
• Controller or processor with an establishment in the EU
• Controller or processor not in the EU, but
• Offering goods or services (regardless of payment) in the EU; or
• Monitoring behavior of data subjects in the EU
Who is subject to the GDPR?
www.nexsenpruet.comto Upstate Alliance
GDPR
24
• A controller or processor outside the EU but subject to the GDPR must:
• Comply with GDPR requirements; and
• Appoint a Designated Privacy Officer in the EU, *unless*
• “Occasional” processing that
• Doesn’t involve large-scale processing of special categories of data or data
related to criminal convictions; and
• Is unlikely to result in a risk to the rights and freedoms of natural persons
Who is subject to the GDPR?
www.nexsenpruet.comto Upstate Alliance 25
California Consumer Privacy Act

More Related Content

What's hot

Privacy 101
Privacy 101Privacy 101
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
Karel Holst
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
Karel Holst
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
Ulf Mattsson
 
Data protection-training
Data protection-trainingData protection-training
Data protection-training
James Wright
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
CILIPScotland
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360
DataStax
 
All You Need To Know About Data Law Changes in 2018
All You Need To Know About Data Law Changes in 2018All You Need To Know About Data Law Changes in 2018
All You Need To Know About Data Law Changes in 2018
The Drum
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
Niall Rooney
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
CloudWATCH Consortium
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
IAB Europe
 
Guernsey Data Protection Legislation
Guernsey Data Protection LegislationGuernsey Data Protection Legislation
Guernsey Data Protection Legislation
jonbarclay
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson LLP
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Burton Lee
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth Boardman
Krowdthink
 
SAP Business One
SAP Business OneSAP Business One
SAP Business One
AGSanePLDTCompany
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
Krowdthink
 

What's hot (17)

Privacy 101
Privacy 101Privacy 101
Privacy 101
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
Data protection-training
Data protection-trainingData protection-training
Data protection-training
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360
 
All You Need To Know About Data Law Changes in 2018
All You Need To Know About Data Law Changes in 2018All You Need To Know About Data Law Changes in 2018
All You Need To Know About Data Law Changes in 2018
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
 
Guernsey Data Protection Legislation
Guernsey Data Protection LegislationGuernsey Data Protection Legislation
Guernsey Data Protection Legislation
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth Boardman
 
SAP Business One
SAP Business OneSAP Business One
SAP Business One
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 

Similar to What is the GDPR & What does it mean for YOUR business?

GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Atif Ghauri
 
Privacy and missing persons
Privacy and missing personsPrivacy and missing persons
Privacy and missing persons
mpcislides
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
Stefan Schippers
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
Priyab Satoshi
 
Thierer Internet Privacy Regulation
Thierer Internet Privacy RegulationThierer Internet Privacy Regulation
Thierer Internet Privacy Regulation
Mercatus Center
 
ethcpp04-Unit 3.ppt
ethcpp04-Unit 3.pptethcpp04-Unit 3.ppt
ethcpp04-Unit 3.ppt
Anil Yadav
 
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
AltheimPrivacy
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert
 
ethcpp04-Unit 3.ppt
ethcpp04-Unit 3.pptethcpp04-Unit 3.ppt
ethcpp04-Unit 3.ppt
Anil Yadav
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
SecurityScorecard
 
Privacy & the Internet: An Overview of Key Issues
Privacy & the Internet: An Overview of Key IssuesPrivacy & the Internet: An Overview of Key Issues
Privacy & the Internet: An Overview of Key Issues
Adam Thierer
 
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
AltheimPrivacy
 
Dataprotectionpackage 2015pptx
Dataprotectionpackage 2015pptxDataprotectionpackage 2015pptx
Dataprotectionpackage 2015pptx
Marco Gioanola
 
Privacy, Drones, and IoT
Privacy, Drones, and IoTPrivacy, Drones, and IoT
Privacy, Drones, and IoT
LAURA VIVET
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
Case IQ
 
Privacy in simple
Privacy in simplePrivacy in simple
Privacy in simple
Aurora Computer Studies
 
GDPR and Blockchain
GDPR and BlockchainGDPR and Blockchain
GDPR and Blockchain
Salman Baset
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacy
TechSoup Canada
 
Data breach protection from a DB2 perspective
Data breach protection from a  DB2 perspectiveData breach protection from a  DB2 perspective
Data breach protection from a DB2 perspective
Craig Mullins
 
Chapter1 Cyber security Law & policy.pptx
Chapter1 Cyber security Law & policy.pptxChapter1 Cyber security Law & policy.pptx
Chapter1 Cyber security Law & policy.pptx
Nargis Parveen
 

Similar to What is the GDPR & What does it mean for YOUR business? (20)

GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Privacy and missing persons
Privacy and missing personsPrivacy and missing persons
Privacy and missing persons
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Thierer Internet Privacy Regulation
Thierer Internet Privacy RegulationThierer Internet Privacy Regulation
Thierer Internet Privacy Regulation
 
ethcpp04-Unit 3.ppt
ethcpp04-Unit 3.pptethcpp04-Unit 3.ppt
ethcpp04-Unit 3.ppt
 
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
 
ethcpp04-Unit 3.ppt
ethcpp04-Unit 3.pptethcpp04-Unit 3.ppt
ethcpp04-Unit 3.ppt
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Privacy & the Internet: An Overview of Key Issues
Privacy & the Internet: An Overview of Key IssuesPrivacy & the Internet: An Overview of Key Issues
Privacy & the Internet: An Overview of Key Issues
 
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
 
Dataprotectionpackage 2015pptx
Dataprotectionpackage 2015pptxDataprotectionpackage 2015pptx
Dataprotectionpackage 2015pptx
 
Privacy, Drones, and IoT
Privacy, Drones, and IoTPrivacy, Drones, and IoT
Privacy, Drones, and IoT
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
Privacy in simple
Privacy in simplePrivacy in simple
Privacy in simple
 
GDPR and Blockchain
GDPR and BlockchainGDPR and Blockchain
GDPR and Blockchain
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacy
 
Data breach protection from a DB2 perspective
Data breach protection from a  DB2 perspectiveData breach protection from a  DB2 perspective
Data breach protection from a DB2 perspective
 
Chapter1 Cyber security Law & policy.pptx
Chapter1 Cyber security Law & policy.pptxChapter1 Cyber security Law & policy.pptx
Chapter1 Cyber security Law & policy.pptx
 

More from Nexsen Pruet

Job Tax Credit in Tier III & IV South Carolina Counties
Job Tax Credit in Tier III & IV South Carolina CountiesJob Tax Credit in Tier III & IV South Carolina Counties
Job Tax Credit in Tier III & IV South Carolina Counties
Nexsen Pruet
 
Are Hospital Physician Networks Ready for TPE Audits?
Are Hospital Physician Networks Ready for TPE Audits?Are Hospital Physician Networks Ready for TPE Audits?
Are Hospital Physician Networks Ready for TPE Audits?
Nexsen Pruet
 
Current Payor Audits & Defending Them
Current Payor Audits & Defending ThemCurrent Payor Audits & Defending Them
Current Payor Audits & Defending Them
Nexsen Pruet
 
UPIC Revolution: CMS Integrity Auditors 2.0
UPIC Revolution: CMS Integrity Auditors 2.0UPIC Revolution: CMS Integrity Auditors 2.0
UPIC Revolution: CMS Integrity Auditors 2.0
Nexsen Pruet
 
Opportunity Zones Update - November 2018
Opportunity Zones Update - November 2018Opportunity Zones Update - November 2018
Opportunity Zones Update - November 2018
Nexsen Pruet
 
False Claims Act Cases: Laboratories
False Claims Act Cases: LaboratoriesFalse Claims Act Cases: Laboratories
False Claims Act Cases: Laboratories
Nexsen Pruet
 
Title IX Breakfast Briefing: FERPA 101
Title IX Breakfast Briefing: FERPA 101Title IX Breakfast Briefing: FERPA 101
Title IX Breakfast Briefing: FERPA 101
Nexsen Pruet
 
Textile Revitalization Credits
Textile Revitalization CreditsTextile Revitalization Credits
Textile Revitalization Credits
Nexsen Pruet
 
Multi-Lot Discount
Multi-Lot DiscountMulti-Lot Discount
Multi-Lot Discount
Nexsen Pruet
 
Municipal Improvement Districts
Municipal Improvement DistrictsMunicipal Improvement Districts
Municipal Improvement Districts
Nexsen Pruet
 
City of Columbia and Mast General Store Case Study
City of Columbia and Mast General Store Case StudyCity of Columbia and Mast General Store Case Study
City of Columbia and Mast General Store Case Study
Nexsen Pruet
 
Infrastructure Tax Credit
Infrastructure Tax CreditInfrastructure Tax Credit
Infrastructure Tax Credit
Nexsen Pruet
 
Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...
Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...
Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...
Nexsen Pruet
 
Retail Facilities "Closed Big Box" Revitalization Credit
Retail Facilities "Closed Big Box" Revitalization CreditRetail Facilities "Closed Big Box" Revitalization Credit
Retail Facilities "Closed Big Box" Revitalization Credit
Nexsen Pruet
 
Brownfields Voluntary Cleanup Incentives
Brownfields Voluntary Cleanup IncentivesBrownfields Voluntary Cleanup Incentives
Brownfields Voluntary Cleanup Incentives
Nexsen Pruet
 
Nmtcs
NmtcsNmtcs
Angus Macaulay, May 3, 2012
Angus Macaulay, May 3, 2012Angus Macaulay, May 3, 2012
Angus Macaulay, May 3, 2012Nexsen Pruet
 
FLSA: Exempt or Not Exempt, That is the Question
FLSA: Exempt or Not Exempt, That is the QuestionFLSA: Exempt or Not Exempt, That is the Question
FLSA: Exempt or Not Exempt, That is the Question
Nexsen Pruet
 
Responding to Grand Jury: Subpoenas & Search Warrants
Responding to Grand Jury: Subpoenas & Search WarrantsResponding to Grand Jury: Subpoenas & Search Warrants
Responding to Grand Jury: Subpoenas & Search Warrants
Nexsen Pruet
 
Compliance Internal Investigation
Compliance Internal Investigation Compliance Internal Investigation
Compliance Internal Investigation
Nexsen Pruet
 

More from Nexsen Pruet (20)

Job Tax Credit in Tier III & IV South Carolina Counties
Job Tax Credit in Tier III & IV South Carolina CountiesJob Tax Credit in Tier III & IV South Carolina Counties
Job Tax Credit in Tier III & IV South Carolina Counties
 
Are Hospital Physician Networks Ready for TPE Audits?
Are Hospital Physician Networks Ready for TPE Audits?Are Hospital Physician Networks Ready for TPE Audits?
Are Hospital Physician Networks Ready for TPE Audits?
 
Current Payor Audits & Defending Them
Current Payor Audits & Defending ThemCurrent Payor Audits & Defending Them
Current Payor Audits & Defending Them
 
UPIC Revolution: CMS Integrity Auditors 2.0
UPIC Revolution: CMS Integrity Auditors 2.0UPIC Revolution: CMS Integrity Auditors 2.0
UPIC Revolution: CMS Integrity Auditors 2.0
 
Opportunity Zones Update - November 2018
Opportunity Zones Update - November 2018Opportunity Zones Update - November 2018
Opportunity Zones Update - November 2018
 
False Claims Act Cases: Laboratories
False Claims Act Cases: LaboratoriesFalse Claims Act Cases: Laboratories
False Claims Act Cases: Laboratories
 
Title IX Breakfast Briefing: FERPA 101
Title IX Breakfast Briefing: FERPA 101Title IX Breakfast Briefing: FERPA 101
Title IX Breakfast Briefing: FERPA 101
 
Textile Revitalization Credits
Textile Revitalization CreditsTextile Revitalization Credits
Textile Revitalization Credits
 
Multi-Lot Discount
Multi-Lot DiscountMulti-Lot Discount
Multi-Lot Discount
 
Municipal Improvement Districts
Municipal Improvement DistrictsMunicipal Improvement Districts
Municipal Improvement Districts
 
City of Columbia and Mast General Store Case Study
City of Columbia and Mast General Store Case StudyCity of Columbia and Mast General Store Case Study
City of Columbia and Mast General Store Case Study
 
Infrastructure Tax Credit
Infrastructure Tax CreditInfrastructure Tax Credit
Infrastructure Tax Credit
 
Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...
Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...
Fee-in-Lieu Tax and Multi-County Park / Special Source Revenue Credit Arrange...
 
Retail Facilities "Closed Big Box" Revitalization Credit
Retail Facilities "Closed Big Box" Revitalization CreditRetail Facilities "Closed Big Box" Revitalization Credit
Retail Facilities "Closed Big Box" Revitalization Credit
 
Brownfields Voluntary Cleanup Incentives
Brownfields Voluntary Cleanup IncentivesBrownfields Voluntary Cleanup Incentives
Brownfields Voluntary Cleanup Incentives
 
Nmtcs
NmtcsNmtcs
Nmtcs
 
Angus Macaulay, May 3, 2012
Angus Macaulay, May 3, 2012Angus Macaulay, May 3, 2012
Angus Macaulay, May 3, 2012
 
FLSA: Exempt or Not Exempt, That is the Question
FLSA: Exempt or Not Exempt, That is the QuestionFLSA: Exempt or Not Exempt, That is the Question
FLSA: Exempt or Not Exempt, That is the Question
 
Responding to Grand Jury: Subpoenas & Search Warrants
Responding to Grand Jury: Subpoenas & Search WarrantsResponding to Grand Jury: Subpoenas & Search Warrants
Responding to Grand Jury: Subpoenas & Search Warrants
 
Compliance Internal Investigation
Compliance Internal Investigation Compliance Internal Investigation
Compliance Internal Investigation
 

Recently uploaded

Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
MasoudZamani13
 
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
gjsma0ep
 
Incometax Compliance_PF_ ESI- June 2024
Incometax  Compliance_PF_ ESI- June 2024Incometax  Compliance_PF_ ESI- June 2024
Incometax Compliance_PF_ ESI- June 2024
EbizfilingIndia
 
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
bhavenpr
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
osenwakm
 
The Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in ItalyThe Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in Italy
BridgeWest.eu
 
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
ssuser559494
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
PelayoGilbert
 
Energizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining FuturesEnergizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining Futures
USDAReapgrants.com
 
Search Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement OfficersSearch Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement Officers
RichardTheberge
 
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence LawyersDefending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
HarpreetSaini48
 
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
SKshi
 
Tax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th semTax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th sem
azizurrahaman17
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
osenwakm
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
ssusera97a2f
 
Lifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point PresentationLifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point Presentation
seri bangash
 
fnaf lore.pptx ...................................
fnaf lore.pptx ...................................fnaf lore.pptx ...................................
fnaf lore.pptx ...................................
20jcoello
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Massimo Talia
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
MattGardner52
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
lawyersonia
 

Recently uploaded (20)

Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
 
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
 
Incometax Compliance_PF_ ESI- June 2024
Incometax  Compliance_PF_ ESI- June 2024Incometax  Compliance_PF_ ESI- June 2024
Incometax Compliance_PF_ ESI- June 2024
 
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
 
The Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in ItalyThe Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in Italy
 
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
 
Energizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining FuturesEnergizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining Futures
 
Search Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement OfficersSearch Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement Officers
 
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence LawyersDefending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
 
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
 
Tax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th semTax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th sem
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
 
Lifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point PresentationLifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point Presentation
 
fnaf lore.pptx ...................................
fnaf lore.pptx ...................................fnaf lore.pptx ...................................
fnaf lore.pptx ...................................
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
 

What is the GDPR & What does it mean for YOUR business?

  • 1.
  • 2. www.nexsenpruet.comto Upstate Alliance INTRODUCTION 2 • What do we mean by “privacy”? • The American approach to privacy regulation • GDPR: An overview • GDPR: The shape of things to come?
  • 3. www.nexsenpruet.comto Upstate Alliance 3 ‣ 1937 ‣ 1890 ‣ 1985 ‣ 1964 When was the first major publication advocating a right to privacy published? POP QUIZ!
  • 4. www.nexsenpruet.comto Upstate Alliance 4 Louis Brandeis & Samuel Warren, “The Right to Privacy,” Harvard Law Review (1890) Defining “privacy” as “the right to be let alone.” When was the first major publication advocating a right to privacy published? 1890
  • 5. www.nexsenpruet.comto Upstate Alliance HOW DO WE DEFINE PRIVACY IN THE 21ST CENTURY? 5 “Privacy encompasses the rights and obligations of individuals and organizations with respect to the collection, use, retention, disclosure, and disposal of personal information.” – American Institute of Certified Public Accountants • Two key principles: • The appropriate use of personal information under the circumstances. • The individual’s right to control the collection, use, and disclosure of personal information.
  • 6. www.nexsenpruet.comto Upstate Alliance HOW DO WE DEFINE PRIVACY IN THE 21ST CENTURY? 6 Rights Of the individual Of the organization Obligations Of the Individual Of the organization
  • 7. www.nexsenpruet.comto Upstate Alliance U.S. vs. EU Treatment of Privacy 7 United States Some constitutional protection Commercial processing of personal information accepted (“Opt Out”) Controls on processing are sectoral European Union Privacy as a human right Default = No processing (“opt in”) Uniform, across-the-board regulation
  • 8. www.nexsenpruet.comto Upstate Alliance U.S. vs. EU Treatment of Privacy 8 United States “Sensitive Personal Information” • Social Security Number • Financial Information (account numbers, etc.) • Driver’s License Number • Medical Records European Union “Special Categories of Data” • Racial or Ethnic Origin • Political Opinions • Trade Union Membership • Criminal Convictions
  • 9. www.nexsenpruet.comto Upstate Alliance U.S. = Sectoral Approach aka “Land of the Acronym” 9 • CAN-SPAM • VPPA • COPPA • FERPA • FCRA • FACTA • GLBA • HIPAA • HI-TECH • GINA Medical Financial ConsumerEducational
  • 10. www.nexsenpruet.comto Upstate Alliance EU Approach: Across-the-Board Regulation 10 OECD Guidelines - 1980 Collection Limitation Data Quality Purpose Specification Use Limitation Security Safeguards Openness Individual Participation Accountability
  • 11. www.nexsenpruet.comto Upstate Alliance EU Approach: Across-the-Board Regulation 11 Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, 1981 Public/Private Sectors Trans-border Data Flows Mutual Assistance
  • 12. www.nexsenpruet.comto Upstate Alliance EU Approach: Across-the-Board Regulation 12 European Data Directive (Directive 94/95/EC), 1995 Encompasses many principles now found in the GDPR Intended to encourage uniformity within the EU, but Not binding on member states
  • 13. www.nexsenpruet.comto Upstate Alliance EU Approach: Across-the-Board Regulation 13
  • 14. www.nexsenpruet.comto Upstate Alliance GDPR 14 • Adopted 14 April 2016 • Effective 25 May 2018 • Binding on EU countries (no enabling legislation necessary) • Britain is not Brexiting from GDPR
  • 15. www.nexsenpruet.comto Upstate Alliance GDPR 15 • Data Subject: A living, natural person who is in the EU, regardless of residence or nationality. • Personal Data: Any information relating to an identified or identifiable Data Subject (“PII”). • Sensitive Personal Data: Origin, beliefs, opinions, union membership, biometric data, sex life/orientation • Processing: Any operation performed on PII, from collection through disposal. • Controller: The person (natural or legal) who decides what PII will be collected and how it will be processed. • Processor: The person (natural or legal) who processes PII on behalf of a controller GDPR Glossary
  • 16. www.nexsenpruet.comto Upstate Alliance GDPR 16 • Data Protection by Design & Default • Transparency • Minimization • Lawful Basis for Processing • Data Subjects’ Rights • Accountability Key Points
  • 17. www.nexsenpruet.comto Upstate Alliance GDPR 17 • Data Protection by Design • Address information security at the front end of software development, not as an afterthought; • De-identification of PII; • Standards for international transfers • Data Protection by Default • Privacy settings “on” by default • Opt-in, not opt-out Data Protection
  • 18. www.nexsenpruet.comto Upstate Alliance GDPR 18 • Disclosure: Data subjects are entitled to know: • What PII is being collected & how long it will be kept • How PII is being used • The specific legal basis for each and every use of PII • Their rights, and how to exercise them • Accessibility: Disclosures must be: • Written in “clear and plain language” • Easy to locate Transparency
  • 19. www.nexsenpruet.comto Upstate Alliance GDPR 19 • Collection of PII should be: • Limited in scope to the data that is adequate and relevant to the intended use • Limited in time to the period necessary to achieve the purpose for which the data was collected • As accurate as reasonably possible Minimization
  • 20. www.nexsenpruet.comto Upstate Alliance GDPR 20 • Consent • Genuine choice • Affirmative opt-in • Specific and granular • Contract • Provide information • Fulfill a contract • Legal obligation • Vital Interests Lawful Basis for Processing • Public Tasks • Legitimate Interests of the Controller • Consider data subject’s expectations • Requires assessment/analysis • For example: • Security/network integrity • Analytics • Performance improvement • B2B marketing
  • 21. www.nexsenpruet.comto Upstate Alliance GDPR 21 • To Be Informed • To Object • To Restrict Processing • To Access Data Subjects’ Rights • To Correction • To Portability • To Erasure (aka “the right to be forgotten”)
  • 22. www.nexsenpruet.comto Upstate Alliance GDPR 22 • Compliance • Documentation of Legitimate Interests Analysis, Data Protection Impact Assessment • Designated Privacy Officer • Supervising Processors • Enforcement • Data Protection Authority (each EU member state) • Remedies range from reprimand to fine of 4% of worldwide revenue or €20,000,000 – whichever is higher Accountability
  • 23. www.nexsenpruet.comto Upstate Alliance GDPR 23 • Controller or processor with an establishment in the EU • Controller or processor not in the EU, but • Offering goods or services (regardless of payment) in the EU; or • Monitoring behavior of data subjects in the EU Who is subject to the GDPR?
  • 24. www.nexsenpruet.comto Upstate Alliance GDPR 24 • A controller or processor outside the EU but subject to the GDPR must: • Comply with GDPR requirements; and • Appoint a Designated Privacy Officer in the EU, *unless* • “Occasional” processing that • Doesn’t involve large-scale processing of special categories of data or data related to criminal convictions; and • Is unlikely to result in a risk to the rights and freedoms of natural persons Who is subject to the GDPR?
  • 25. www.nexsenpruet.comto Upstate Alliance 25 California Consumer Privacy Act

Editor's Notes

  1. Brandeis - Associate Justice of the US Supreme Court 1916-1939 Brandeis & Warren graduated 1st & 2d in their class at Harvard Law in 1877, then went out and practiced law together. Article prompted by increasing newspaper coverage of peoples’ private lives (specifically, the wedding of Warren’s daughter). “The press is overstepping in every direction the obvious bounds of propriety and of decency. Gossip is no longer the resource of the idle and of the vicious, but has become a trade, which is pursued with industry as well as effrontery. To satisfy a prurient taste the details of sexual relations are spread broadcast in the columns of the daily papers. To occupy the indolent, column upon column is filled with idle gossip, which can only be procured by intrusion upon the domestic circle.” The law protected the right of the creator of the content to keep the profit (e.g., copyright protection) but not the right of the subject to avoid the publication.
  2. Processing: Does not apply to purely personal or household activity; also excludes certain activities of EU member states in the area of foreign policy/national security. Controller/processor are not mutually exclusive roles.
  3. Accessibility: There must be clarity as to who is collecting the information Easy to Locate: “unsubscribe” links; cookie policy pop-ups
  4. Scope limitation: If you want to send an electronic newsletter to a customer, what do you need? Time limitation: Are you keeping subscribers’ information after they have unsubscribed? Employees’ information after they have left the company? Accuracy: What are you doing to avoid corruption or inaccurate cross-linking of data?
  5. Legal Obligation: Not just to perform a contract; must be a specific, documented obligation (subpoena, EEOC compliance). Vital Interests: “to protect an interest which is essential to the life of the data subject” – think medical emergency, mandated reporters (maybe), suicide hotlines Public Tasks: Primarily applicable to government agencies, affiliates, contractors. Authority doesn’t need to be as specific as under “legal obligation,” but must have a clear foundation in law. Legitimate Interest: The most flexible basis, but care is required. Data subject’s expectations based on relationship with the controller. --Legitimate Interest Analysis (record of your reasoning) - what is the legitimate interest (purpose test) - Is the processing necessary to achieve it (necessity test) - Balance against the individual’s rights and freedoms (balancing test). Examples – remember the balancing test. This is not an exception that swallows the rule.
  6. To be informed: The right to know what data is being collected and what is being done with it. The flip side of the controller’s disclosure obligation. Included in the right to be informed is the right of choice. Can deny access; it’s okay if certain features of your site don’t work as well. Notify before collection of information Consent—we’ll talk more about this in a few slides. To Object: The right to stop processing of data for marketing purposes. Must be notified of right in every communication, and once objection is made, full stop on use. None of this “it takes 90 days to get you off the list” To Restrict Processing: This is the right to limit the way the controller uses your data. Tied to disclosure/consent. Specific/granular. To Access: Data subjects have the right to see the data a controller has collected about him/her. “Subject access request” can be written (incl. electronic) or verbal. 30 days to respond, can’t charge a fee. To Correction: Data subject has the right to have inaccurate or incomplete data corrected or completed. Verbal or written request; respond w/in 30 days; no fees To Portability: This is the right to re-use data across difference services without loss of functionality Think QuickBooks to Peachtree – it’s your information so they have to let you move it. To Be Forgotten: Same as others: written or verbal, 30 days (but can get an extension), no charge. This right is only available in specific circumstances: 1. PII no longer necessary for the purpose for which it was collected; 2. Consent has been withdrawn and there is no other legal ground; 3. Data subject objects and there are no overriding legitimate grounds to process; 4. Unlawfully processed PII; 5. Compliance with a legal obligation; 6. PII collected for “information society services” offered to children (younger than 16)
  7. EU Establishment: Doesn’t matter if data processing occurs in the EU. Monitoring: It’s not entirely clear what this means, not much official guidance. The EU Commission has suggested a broad definition: ““[i]n order to determine whether a processing activity can be considered to monitor the behavior of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analyzing or predicting her or his personal preferences, behaviors and attitudes.” That definition is potentially so broad that it probably won’t become regulatory reality. But, it points in the direction of tracking technologies (geo-location data, persistent cookies).
  8. Designated Privacy Officer: Must be in one of the member states where the data subjects whose activities are being monitored are located. “Unlikely to result in a risk” must take context into account; must apply EU conception of “rights and freedoms.”
  9. CCPA is the result of a game of chicken between the CA legislature and a group called “Californians for Consumer Privacy.” CCP got 600,000 signatures for a ballot initiative (1.5% of population) that enacted in late June by legislature to avoid more stringent ballot initiative. CCPA and AB-375 provide a lot of the same protections as the GDPR – right to know what information is being collected about you; the right to opt-out of the sale of your personal information; right of access; right to equal service. What the CCPA would have done, which AB-375 does not do, is give consumers extensive rights to sue (individually or collectively) to sue for violations of the act or for data breaches where information was not reasonably protected. AB-375 tempers those aspects of the bill, including by creating a 30-day right to cure a violation.