The Data Protection Audit How to prepare What to expect The end results Dublin Chamber of Commerce, March 24 th.

Slides:



Advertisements
Similar presentations
Principle 1 Principle 1 Processed fairly and lawfully + only with a legitimate basis There should be no surprises, so … inform data subjects why you are.
Advertisements

PIPA PRESENTATION PERSONAL INFORMATION PROTECTION ACT.
Privacy and the Right to Know Grayson Barber, Esq. Grayson Barber, LLC.
Data Protection.
Marketing: Comply with the Law 28 th February 2007 Liz Rowe.
The Do Not Call Register Act 2006 and The Spam Act 2003 Jane Cole Manager, Telemarketing Investigations Section Julia Cornwell McKean Manager, Anti Spam.
TEEC Company Confidential Call E-Marketing Backgrounder! Prepared by TEEC.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Marketing - Best Practice from a Legal Point of View Yvonne Cunnane - Information Technology Law Group 30 November 2006.
Practical Information Management
Cookie compliance: your 5 day emergency action plan Claire Walker.
Mobile Payments & Alert Communications: Changing Your Bottom Line Art Coutcher Utility Sales Manager direct:
Spam Act 2003 Consumer Education and Awareness. About the ACA Independent government regulator Ensures industry compliance with legislation (Telecommunications.
3 Opting out. Lesson 3 Opting out If you tick the box, what will happen?
Data Protection STFC Presentation to PPD Senior Staff 26/11/2009 FoI/DP team.
The wonderful job at KIMEP High average salary range KIMEP tuition discounts for employees Trainings & seminars for your self-development Annual performance.
Rules of Engagement Mark Dwyer. AGENDA 1.Spam and Consent 2.Privacy 3.Advice Warnings and Notices 4.Disclosures 5.Other Matters.
Serving the Public. Regulating the Profession. CANADA’S ANTI-SPAM LEGISLATION (CASL) Training for Chapters Based on Guidelines for Chapters First published.
Current risk and compliance priorities for law firms PETER SCOTT CONSULTING.
The EU General Data Protection Regulation Frank Rankin.
Data protection—training materials [Name and details of speaker]
[ Direct marketing – an introduction to data protection and privacy] For [insert name of organisation] presented by [insert name of presenter] on [date]
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
General Data Protection Regulation (EU 2016/679)
Political campaigning: data protection & electronic marketing
Key changes with the GDPR
Fundraising Regulation: What does it mean for charities?
Registering for patient access
WELCOME.
Understanding EU GDPR from an Office 365 perspective
GDPR – What’s it all about???
General Data Protection Regulations: what you really need to know
Data Protection The Current Regime
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Overview Gydeline – October 2017
Conducting Compliant Marketing & SARs Workshop - CMG Events
GDPR Overview Gydeline – October 2017
General Data Protection Regulations
GENERAL DATA PROTECTION REGULATION (GDPR)
GDPR is There, Are you Ready?
The Circle of Trust Greg Hungerford.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
GDPR and Health and Safety
Information Governance
Current Privacy Issues That May Affect Your Credit Union
Data protection in the Education Sector - understanding the impact of GDPR Tuesday 23rd January 2018.
Data Protection and GDPR – An introduction for Baptist Churches
General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR (General Data Protection Regulation)
Preparing for GDPR Sharing experiences of the process and using the British Canoeing Toolkit bit.ly/BCGDPRToolkit
How we’ll prepare for the General Data Protection Regulation (GDPR)
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Quiz Today’s trainer: Click here to use Kahoot! 1
GDPR, PCS UG 15th May 2018, Vienna.
Dr. Sarah Quinton, UREC Chair,
#eaThinkData Get Ready for GDPR #eaThinkData.
GDPR Dashboard General Data Protection Regulation 06/02/2018
The General Data Protection Regulations 2016
GDPR Dashboard General Data Protection Regulation 06/02/2018
Data Privacy by Design Expanding Security for bepress Users
Is your medico-legal practice GDPR compliant?
GDPR Workshop – Partnerships for Jewish Schools
National data opt-out - Preparing for implementation
Disclosures Right to Consent You have a right to consent to how Innovative Results Group / IRG Consulting uses your data. Below is a list of the data.
Getting Ready For GDPR Simon Marks Director
GDPR what do we need to do?
Presentation transcript:

The Data Protection Audit How to prepare What to expect The end results Dublin Chamber of Commerce, March 24 th

ENGAGE AND COOPERATE Letter confirming the audit Average six week’s notice Triggered as random or subject to complaints Watch list in Ireland

Prepare! Key Considerations: Are you a Data Controller or Data Processor? Both? Do you need external help and advice? All focus is around the eight pillars of Data Protection Paper work and process Your knowledge/Employee knowledge DP Handbook

Consent: Should be Clear and Transparent Unambiguous consent (ODPC will endorse a consent process) Opt in for , sms and mobile Opt out for postal and landline? Pre-ticked box is not sufficient Referring to a Privacy Policy or T&C’s is not sufficient Eventual data usage is relevant to original consent

Consent Statement endorsed by ODPC: ‘’ By ticking this box you understand and agree to all the terms and conditions and our privacy policy.terms and conditionsprivacy policy By registering with XYZ, you agree to be contacted by XYZ and by carefully selected third parties for marketing purposes and understand you can be contacted by telephone, mobile, and postal. You can unsubscribe from such communications at any time.

UK Example - Fair Processing and Legitimate Consent Example in preparation for EU GDPR By ticking this box you agree to our terms and conditions and privacy policy and to receive information from [Brand Name] *terms and conditionsprivacy policy I agree that other companies in the retail, personal finance, insurance, travel or lifestyle sectors may contact me by post, , telephone or SMS. I agree that they may contact me by: Post Phone SMS You can opt-out of these messages at any time. For more details please see our Privacy Policy which also explains the types of companies who may contact you and the way they will use the information you have provided today as well as in the past. Be assured that any such parties will use your data in accordance with the UK Data Protection Act 1998 and other applicable law relating to privacy.Privacy Policy

Results - Learnings 1 ODPC are there to help, not act as a threat to the business Getting your organisation ready for ‘GDPR’ A Data Processor agreement is very important Self-assessment regularly to adapt and update your compliance process is now vital Train and educate your team to be compliant aware

Learnings - 2 Compliance is not difficult – Review your legacy data Data subject access requests currently 40 days to be reduced to 30 Don’t be afraid to ask ODPC the questions Experts are available in the ODPC to answer any question Over 120 staff - so call them! The 12 month rule Get ready now for the EU wide GDPR - two years to implement

Final Thoughts: Data Compliance in Ireland is one of the biggest barriers for Marketers to Direct Marketing It doesn’t have to be like this! We asked the ODPC: if a person is not on the NDD, could we include them in marketing ODPC said: ‘’ Yes. If a consumer is not on the NDD, a brand can call them. (There is also a requirement to ensure the consumer is not on the brand’s own DNC list).’’ We asked the ODPC: can we use SMS as a channel for marketing ODPC said: ‘’ Yes. SMS campaigns using mobile data are possible, providing the sender has the unambiguous consent of the phone owner for the sending of the marketing messages and that the consent is up to date (within the 12 month rule)’’

Creation Of National Suppression File - MPS - Objective Central file - consumers can register for free not to receive Direct Mail - Currently 11k records grows by circa 20 to 30 per month - Rebuilt In late 2015 to allow consumers to register online and eircode will be the data match key - MPS Only available to IDMA members - Access through a secure log in process and can download data by date to screen against in house files - Seeking ODPC endorsement Plan to extend to include deceased register and third party data feeds. for key data providers in Ireland Est scale: 100k to 300k records – It will become a National Screening File

Focus On