General Data Protection Regulation Q & A Session

Slides:



Advertisements
Similar presentations
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Advertisements

Data Protection.
What if my organization conducts business across borders ? Your footnote Privacy and “Personal Information” have different meanings in different countries;
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
Audiences NI Data Protection Workshop
1.1 System Performance Security Module 1 Version 5.
The Freedom of Information and Data Protection Legislation An Overview Ann McKeon November 2014.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
Regulation of Personal Information Sally Brierley & Emma Harvey.
IT Applications Theory Slideshows By Mark Kelly Vceit.com Privacy Laws.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
Understanding Privacy An Overview of our Responsibilities.
The Freedom of Information and Data Protection Legislation An Overview
Protecting PHI & PII 12/30/2017 6:45 AM
The future of data protection: General Data Protection Regulation
Data Protection: The Law
Data Protection and Confidentiality
Privacy principles Individual written policies
Issues of personal data protection in scientific research
The General Data Protection Regulation act (GDPR)
Dining with Diabetes IRB Training 2017.
IT Applications Theory Slideshows
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Overview Gydeline – October 2017
General Data Protection Regulation: Turning the black into white
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
The Rise of Privacy: Complying with GDPR in the United States
The General Data Protection Regulation (GDPR)
Internet Privacy and You
New Data Protection Legislation
State of the privacy union
G.D.P.R General Data Protection Regulations
ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know.
GENERAL DATA PROTECTION REGULATIONS (GDPR)
Data Protection and GDPR – An introduction for Baptist Churches
The new data protection rules
GDPR Overview and Use Cases.
Data Protection principles
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Finham Primary School – GDPR Practice Guidelines
Information management and communication
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
Data Protection in a Tutorial Context
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
GDPR enforcement begins
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
Information Handling Research Student Induction Day
#eaThinkData Get Ready for GDPR #eaThinkData.
General Data Protection regulation (GDPR)
GDPR – General Data Protection Regulation
Understanding Data Protection
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
Move this to online module slides 11-56
Data Protection What can I do? GDPR Principles General Data Protection
GDPR Session
An Introduction to the General Data Protection Regulation
Handling information 14 Standard.
ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know.
General Data Protection Regulation
Information Governance
The Health Insurance Portability and Accountability Act
School of Medicine Orientation Information Security Training
Presentation transcript:

General Data Protection Regulation Q & A Session Ann McKeon March 2019

What is Data Protection? It is the safeguarding of the privacy rights of individuals in relation to the processing of personal data. The Data Protection Act and GDPR confer rights on individuals as well as responsibilities on those persons processing personal data.

Why was Data Protection Legislation introduced: To regulate the collection, processing, keeping, use and disclosure of personal data To give individuals access to their data and allow them to amend it if incorrect To comply with EU Directives

General Data Protection Regulation GDPR effective from 25th May 2018 Data Protection Act 2018 Transparency, Accountability, Security Data subject rights remain basically the same New right of portability excluded from Irish legislation Definition of child changed from under 16 to under 18

Personal Data Definition information relating to: - an identified living individual, or a living individual who can be identified from the data, directly or indirectly, in particular by reference to: - An identifier such as a name, an identification number, location data or an online identifier, or One or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the individual  

Special Categories of Personal Data Definition Personal data revealing: the racial or ethnic origin of the data subject, the political opinions or the religious or philosophical beliefs of the data subject, or whether the data subject is a member of a trade union, Genetic data, Biometric data for the purposes of uniquely identifying an individual, Data concerning health Or personal data concerning an individual’s sex life or sexual orientation.

GDPR Key points Data Protection web page now updated https://www.maynoothuniversity.ie/data-protection Revised and new policies, procedures and guidelines Breaches must be notified to Data Protection Commissioner within 72 hours where feasible Be aware of what personal data we have , keep it secure and get consent if necessary

GDPR Practical Compliance Do NOT download or access personal data to any mobile device/USB key/home computer unless it is encrypted Email: Emailing large quantities of personal data internally Consider use of password protected excel spreadsheets. External email: Do Not send personal data unless the network is secure between sender and receiver Clear desk policy: Never have computer screens or manual files containing personal data visible on your desk (when you are not working on them) Remove from view if someone enters your office

Securing Personal Data Office/Department/Unit authorisation process to grant and revoke access to systems holding personal data Securing personal data: Manual - Data is in a locked filing cabinet in a locked office in a secure building Electronic - Computing policies being updated to advise on best practice Shared drives - the file, folder or document on the shared drive is password protected - Users have individual non shared passwords.

Personal Data Security Breaches Data security breach or suspected breach must be notified to the Data Protection Officer immediately What is a breach? Disclosure of confidential data to unauthorised individuals; Loss or theft of data or equipment on which data is stored; Hacking, viruses or other security attacks on IT equipment/ systems/networks; Inappropriate access controls allowing unauthorised use of information; Emails containing personal data sent in error to wrong recipient; Applies to paper and electronic records;

Contact Ann McKeon Data Protection/Freedom of Information Officer Tel: 01 7086184. Email: ann.mckeon@mu.ie Web: https://www.maynoothuniversity.ie/freedom-information https://www.maynoothuniversity.ie/data-protection