INTRODUCTION TO GDPR 19/09/2018.

Slides:



Advertisements
Similar presentations
International Employment – latest Digital Employment issues Melanie Lane and Karine Audouze.
Advertisements

Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The EU General Data Protection Regulation Frank Rankin.
Key Points for a Privacy Programme for Multinationals Steve Coope.
Information Governance Support Information Governance Services
General Data Protection Regulation (EU 2016/679)
Data Protection Regulation
Tony Sheppard Mobile Guardian
General Data Protection Regulation (GDPR)
Data Protection Officer’s Overview of the GDPR
General Data Protection Regulations: The Key Changes
Accountability & Structured Privacy Management
The future of data protection: General Data Protection Regulation
GDPR (General Data Protection Regulation)
Overview General Data Protection Regulation (GDPR)
Microsoft 365 Get help with regulatory compliance
WORLD OF CLOUD COMPUTING AFTER GDPR challenges, opportunities and the unknown Matjaž Drev, MA. National Supervisor for Personal Data Protection, Information.
Presentation to GTMC on GDPR
General Data Protection Regulation (GDPR)
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
GDPR Awareness and Training Workshop
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
International Regulatory Trends
Museums + Heritage webinar, 30 November 2017
GDPR support January GDPR support January 2018.
The European Union General Data Protection Regulation (GDPR)
Data protection reform:
GDPR Road map to Compliance.
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection Reform in Local Government
Vikas Dewangan (Senior Technology Architect)
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
Go to ‘View’ menu > ‘Header and Footer…’ to edit the footers on this slide (click ‘Apply’ to change only the currently selected slide, or ‘Apply to All’
Introducing the General Data Protection Regulation 2016
ESET UK IT Security Specialist
Data protection reform – update from the ICO
State of the privacy union
Privacy: a work in progress
Information Governance
G.D.P.R General Data Protection Regulations
General Data Protection Regulation
The National Working Group
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR How does it apply to me?.
07/12/2018.
How we’ll prepare for the General Data Protection Regulation (GDPR)
Guide to overview of changes under GDPR ww.ZAKSIT.com
General Data Protection Regulations 2018
GDPR enforcement begins
The General Data Protection Regulation Six months on – What’s changed
The title: The implementation of Data Protection
General Data Protection regulation (GDPR)
What Governors need to know about GDPR
European Commission proposals for data protection
The General Data Protection Regulations 2016
Data Protection What can I do? GDPR Principles General Data Protection
GDPR: Understanding your obligations and the ongoing challenges
General Data Protection Regulation “11 months in”
Data Privacy by Design Expanding Security for bepress Users
GDPR Workshop – Partnerships for Jewish Schools
Getting Ready For GDPR Simon Marks Director
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

INTRODUCTION TO GDPR 19/09/2018

GENERAL DATA PROTECTION REGULATIONS: AN INTRODUCTION Background to the Regulations Timescale for change GDPR aims Key changes Actions to date Future plans Contacts and further information 19/09/2018

GENERAL DATA PROTECTION REGULATIONS BACKGROUND UK Data Protection Act 1998 derives from EU Data Protection Directive 95/46/EC Data Protection Act now almost 20 years old Amendments and related law have been enacted, but fundamental review required Potential changes discussed at EU level for 4 years Reform consists of 2 instruments: General Data Protection Regulations (GDPR) Data Protection Directive (for police & criminal justice sector) 19/09/2018

GDPR approved by European Parliament on 14 April 2016 Entered into force on 25 May 2016 Will apply in UK (potentially with changes) from May 2018 19/09/2018

GDPR AIMS To give citizens back control over of their personal data To simplify the regulatory environment for business To create a modern and harmonised data protection framework across the EU Reform seen as ‘key enabler’ of Digital Single Market & EU Agenda on Security 19/09/2018

GENERAL DATA PROTECTION REGULATIONS KEY CHANGES Fines – 2 tiers of fines for different offences, up to 20M EUR or 4% of global turnover Consent – more clearly defined, easier to withdraw, record keeping required Transparency – significantly more information to be provided where data are collected Right to be forgotten – new (limited) right for people to have their personal data erased without undue delay, controllers must also take reasonable steps to tell other controllers 19/09/2018

GDPR KEY CHANGES Security – risk minimisation approach, move towards certification mechanisms Data Protection Impact Assessment – (Privacy Impact Assessment) required prior to high-risk processing Data breaches – ICO and affected individuals must be informed of significant breaches. ICO notification within 72 hours 19/09/2018

GENERAL DATA PROTECTION REGULATIONS KEY CHANGES Data portability – (limited) right to receive personal data in interoperable format Subject Access Requests – no more fees, shorter 1 month timescale for response (exceptions apply to both) Data Protection Officer – required post, must have expert knowledge, be independent, report directly to ‘highest management’ Record keeping – must maintain records of processing activities, inc. storing, sharing and transfers 19/09/2018

GDPR AND DECISION TO LEAVE THE EU On 23 June 2016, the UK voted to leave the EU General view is: some short-term confusion, but GDPR will still apply (especially if UK remains a member of EEA) GDPR still applies to our processing of EU citizen data UK will still have powers to amend some parts of GDPR 19/09/2018

GENERAL DATA PROTECTION REGULATIONS WHAT WE’RE ALREADY DOING Dedicating more SPC staff resource to improving data protection compliance across University: Analysing the new legislation and its application to UEA Mapping GDPR requirements to UEA work practices Working with key contacts in departments & faculties Identifying processing risks and opportunities Identifying and reviewing privacy notices and data sharing agreements Implementing standardised data breach investigations and Privacy Impact Assessments (PIAs) Improving guidance and training materials 19/09/2018

GENERAL DATA PROTECTION REGULATIONS FUTURE DEVELOPMENTS Monitor legislation developments and ICO guidance as published Achieve certification in amended data protection practitioner training Undertake data protection audits as appropriate Work with IT Security project to ensure identified personal data is appropriately secured 19/09/2018

GENERAL DATA PROTECTION REGULATIONS CONTACTS AND FURTHER INFORMATION Email: dataprotection@uea.ac.uk Telephone: x2431 or 3523 Information Commissioner’s Office: https://ico.org.uk/for-organisations/data-protection- reform/ GDPR text (PDF): http://eur-lex.europa.eu/legal- content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN European Commission data protection reform blog: http://ec.europa.eu/justice/data- protection/reform/index_en.htm 19/09/2018 All images sourced from Pixabay, CC0 Public Domain