SlideShare a Scribd company logo
1 of 20
General Data Protection
Regulations: The Key Changes
Craig Clark Information Security & Compliance Manager
Topics
• What is the GDPR?
• European Law
• Key Dates for the GDPR
• Key changes from Data Protection Act
- Harmonisation
- Enforcement
- Off Shore Processing
- Governance
- One Stop Shop
- Consent
- Transparency
- Data Portability
- Data Processors
• Next Steps
What is the GDPR?
• A complete overhaul of data protection regulation with extensive updates of what can
be considered identifiable information
• Applies across all member states of the European Union
• Applies to all organisations processing the data of EU data subjects –wherever the
organisation is geographically based
• Specific and significant rights for data subjects to seek compensation, rights to erasure
and accurate representation
• Compensation can be sought against organisations and individuals employed by them
• Fines of up €20,000,00 or 4% global annual turnover
• Significant reduction in that amount based on the implementation of technical, or
organisational controls implemented
European Law Landscape
EU Legislation can be separated into two main branches:
Directives
• Require individual implementation in each Member State (Each State can
implement rules in their own way)
• Implemented by the creation of national laws approved by the parliaments of
each Member State
• European Directive 95/46/EC is a Directive
• Sets out a goal that a member state must achieve –room for tailoring
• UK Data Protection Act 1998
European Law Landscape
EU Legislation can be separated into two main branches:
Regulations:
• Immediately applicable in each Member State in a uniform manner
• Binding legislative Act
• Require no local implementing legislation – no tailoring
• EU GDPR is a Regulation
• Regulations are not negotiable by member states
• Regulations may apply to countries outside the EU if they affect EU subjects
(people who are originally from the EU)
Key Dates for GDPR
8 April 2016 the European Council adopted the Regulation.
14 April 2016 the Regulation was adopted by the European
Parliament.
4 May 2016, the official text of the Regulation was published
in the EU Official Journal in all the official languages.
The Regulation entered into force on 24 May 2016, and
applies from 25 May 2018.
This Regulation shall be binding in its entirety and directly
applicable in all Member States.
GDPR Structure
European Data Protection Board
Lead Supervising Authority
(Information Commissioners Office)
Data Processor
Data Controller
(Organisation)
Data Subject
(Individuals)
3rd Countries 3rd Party
GDPR Structure
• The European Data Protection Board will issue guidance for
controllers and processors
• They will facilitate the use of Data Protection Impact Assessments
• The ICO will oversee both Data Controllers and Data Processors
• Breaches and Notifications will be made to the ICO
• 3rd Countries – countries to which data is transferred
• At the centre of the GDPR is the protection of Personally
Identifiable Information
Key Changes Between DPA and GDPR
Harmonisation Across Member States:
• Adoption of a single set of rules on data protection, directly applicable in all
EU Member States: Even if the UK leave the EU the GDPR will apply for all EU
Data Subjects
• Each Member State has previously implemented data protection laws locally
which transpose the EU Data Protection Directive leading to fragmentation
in terms of compliance requirements across Member States.
• The GDPR is intended to adopt a harmonised approach to compliance across
all Member States by implementing legislation that will be directly applicable
in all 28 Member States. There will be no opportunity for local transposition.
Key Changes Between DPA and GDPR
Enforcement:
• A revised enforcement regime underpinned by power for supervising
authorities to levy heavy financial sanctions of up to 4% of the annual
worldwide turnover of the organisation or €20 Million, whichever is greater.
• Fines are designed to be effective and dissuasive and ensure that which will
non compliance is considered a significant risk for businesses.
• Supervisory authorities will have the power to impose these sanctions from
where the data subject habitually resides or in the territory that the breach
occurs. These changes will significantly increase the risk associated with
privacy non-compliance.
Key Changes Between DPA and GDPR
Off Shore Processing:
• Application of the GDPR to companies established outside the EU, if
they target EU citizens e.g. international students.
• The new rules have a broader territorial scope since they apply to non-
EU established companies targeting the EU market by either offering
their goods or services to EU citizens or by monitoring their behaviour.
• Currently, EU Data Protection legislation only applies to non-EU
established controllers if they make use of equipment on EU territory
for the purposes of processing personal data, and to processing taking
place in the EU.
Key Changes Between DPA and GDPR
Governance:
Area of major change
• Increased responsibility and accountability on organisations to manage how they
control and process personal data.
• Controllers must ensure all personal data is processed in compliance with the
Regulation and be able to demonstrate compliance to a supervisory authority if
requested.
• There is now a requirement to keep extensive and detailed records of processing
operations.
• Organisations must perform Data Privacy Assessments for all high risk activities.
• A Data Protection Officer must be formally appointed and recognised with a
number of stipulations added for ensuring impartiality.
Key Changes Between DPA and GDPR
Governance Continued:
• When notifying the regulator of data breaches, Controllers will be required to notify
the Information Commissioners Office, and in some cases the data subjects
involved of significant data breaches within 72 Hours.
• Privacy by design - taking privacy risk into account throughout the process of
designing a new product or service, rather than treating it as an afterthought. Now
required to assess and implement appropriate technical and organisational
measures and procedures from the outset to ensure that processing complies with
the Regulation and protects the rights of the data subjects.
• Privacy by default - ensuring mechanisms are applied retrospectively to ensure
that, by default, only as much personal data is collected, used and retained for each
processing task, both in terms of the amount of data collated and time for which it
is kept.
Key Changes Between DPA and GDPR
One Stop Shop:
• Ability to nominate a single national data protection authority as the
lead regulator for all compliance issues in the EU, where the
organisation has multiple points of presence across the EU
Key Changes Between DPA and GDPR
Consent:
Area of major change
• The DPA allows a controller to lawfully process data with the "consent"
of the data subject. Consent can be either express or implied consent -
or where the processing is necessary for the "legitimate interests" of
the controller in circumstances that do not cause undue prejudice to
the individual.
• GDPR redefines consent. Now, consent must be freely given, specific,
informed and unambiguous. Implied consent, (e.g., by just staying on a
website or not responding to a request) will not be sufficient.
Key Changes Between DPA and GDPR
Consent Continued:
• Requiring consent from an end user in order to give that person access to a service,
where these personal data are not necessary to perform the contract, will no longer
be allowed.
• Controllers will be expected to provide much more consideration in their working
practices as to what the data subject would like and expect their data to be used
for.
• Consent can be withdrawn any time, and as easy to withdraw consent as give it
• Data subject must give consent for specific purposes - blanket consent no longer
allowed –This has significant implications in information sharing, processing and
retention
• One month to respond to subject access and no charges can be applied
• Must be able to supply evidence that consent for each specific purpose was given
Key Changes Between DPA and GDPR
Transparency:
• Any communications with a data subject must be concise, transparent,
intelligible
• Controller must be transparent in providing information about itself and the
purposes of the processing
• Controller must provide data subject with information about their rights.
• Policies must explain to data subjects both how their personal data will be
processed and what their individual rights are and how they may be
exercised.
• This must be provided in an intelligible form, using clear and plain language
that will be understood by the target audience.
Key Changes Between DPA and GDPR
Data Portability:
• The Regulation introduces a new right to data portability, which grants
data subjects the right to receive personal data concerning him or her,
which he or she has provided to a controller, in a structured and
commonly used and machine-readable format.
• The data subject is also entitled to have the data transmitted directly
from one controller to another, where this is technically feasible.
• A statutory "right to be forgotten" has been included which will allow
individuals the right to require a controller to delete data files relating
to them if there are no legitimate grounds for retaining it – including
when a subject has withdrawn consent.
Key Changes Between DPA and GDPR
Data Processors:
• The GDPR directly regulates Data Processors
• Processors will be required to comply with a number of specific obligations,
including to maintain adequate documentation, implement appropriate
security standards, carry out routine data protection impact assessments,
appoint a data protection officer, comply with rules on international data
transfers and cooperate with national supervisory authorities.
• Processors will be liable to sanctions at the same level as controllers if they
fail to meet these criteria.
• Information Sharing Agreements will help ensure that Controllers give clear
instructions to processors on how they expect and require their data to be
handled.
Next Steps
• Meet with top management and form a Working Group to ensure that
compliance with GDPR before it is enforced.
• Follow the ICO’s ‘12 Point Plan’ for actions to take prior to introduction.
• Obtain specialist knowledge in the implementation of changes required
and ongoing compliance with GDPR.
• ITIBGQ offer Foundation and Practitioner certification in EU GDPR – in
my view these certifications are essential for Information Security
managers so that they can provide the skills and advice required to
ensure compliance.

More Related Content

What's hot

EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshellInitio
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Stephanie Vasey
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR OverviewGydeline Ltd
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017isc2-hellenic
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 

What's hot (20)

GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshell
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 

Viewers also liked

Jump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data ClassificationJump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data ClassificationWatchful Software
 
delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1Jes Breslaw
 
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_IstanbulGDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_IstanbulIgor
 
White-Paper_Security-DBSec_EU-GDPR_06-2016
White-Paper_Security-DBSec_EU-GDPR_06-2016White-Paper_Security-DBSec_EU-GDPR_06-2016
White-Paper_Security-DBSec_EU-GDPR_06-2016stefanjung
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Major changes brought in by companies bill 2012
Major changes brought in by companies bill 2012Major changes brought in by companies bill 2012
Major changes brought in by companies bill 2012Vinay Singhania
 
EPA RFS2
EPA RFS2EPA RFS2
EPA RFS2mattn4
 
The Competition Amendment Act No. 1 of 2009 - by director Dominique Arteiro
The Competition Amendment Act No. 1 of 2009 - by director Dominique ArteiroThe Competition Amendment Act No. 1 of 2009 - by director Dominique Arteiro
The Competition Amendment Act No. 1 of 2009 - by director Dominique ArteiroWerksmans Attorneys
 
Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...
Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...
Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...Polsinelli PC
 
Presentation for Rockend\'s Melbourne Strata Users Day - June 2011
Presentation for Rockend\'s Melbourne Strata Users Day - June 2011Presentation for Rockend\'s Melbourne Strata Users Day - June 2011
Presentation for Rockend\'s Melbourne Strata Users Day - June 2011francescoandreone
 
Changes to the Condominium Property Act and Regulations in Saskatchewan
Changes to the Condominium Property Act and Regulations in SaskatchewanChanges to the Condominium Property Act and Regulations in Saskatchewan
Changes to the Condominium Property Act and Regulations in SaskatchewanMarc Kelly
 
THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?
THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?
THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?telosaes
 
Direct Tax Amendments Applicable From 1st April 2017
Direct Tax Amendments Applicable From 1st April 2017Direct Tax Amendments Applicable From 1st April 2017
Direct Tax Amendments Applicable From 1st April 2017Amarpal Jakhar
 

Viewers also liked (16)

Jump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data ClassificationJump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data Classification
 
delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1
 
Hacking the Helpdesk: Social Engineering Risks
Hacking the Helpdesk: Social Engineering RisksHacking the Helpdesk: Social Engineering Risks
Hacking the Helpdesk: Social Engineering Risks
 
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_IstanbulGDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
 
White-Paper_Security-DBSec_EU-GDPR_06-2016
White-Paper_Security-DBSec_EU-GDPR_06-2016White-Paper_Security-DBSec_EU-GDPR_06-2016
White-Paper_Security-DBSec_EU-GDPR_06-2016
 
Gdpr security services
Gdpr security servicesGdpr security services
Gdpr security services
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Bill of Rights
Bill of RightsBill of Rights
Bill of Rights
 
Major changes brought in by companies bill 2012
Major changes brought in by companies bill 2012Major changes brought in by companies bill 2012
Major changes brought in by companies bill 2012
 
EPA RFS2
EPA RFS2EPA RFS2
EPA RFS2
 
The Competition Amendment Act No. 1 of 2009 - by director Dominique Arteiro
The Competition Amendment Act No. 1 of 2009 - by director Dominique ArteiroThe Competition Amendment Act No. 1 of 2009 - by director Dominique Arteiro
The Competition Amendment Act No. 1 of 2009 - by director Dominique Arteiro
 
Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...
Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...
Back to the Future... Will CMS' Proposed Provider-Based Rules Reshape the Fut...
 
Presentation for Rockend\'s Melbourne Strata Users Day - June 2011
Presentation for Rockend\'s Melbourne Strata Users Day - June 2011Presentation for Rockend\'s Melbourne Strata Users Day - June 2011
Presentation for Rockend\'s Melbourne Strata Users Day - June 2011
 
Changes to the Condominium Property Act and Regulations in Saskatchewan
Changes to the Condominium Property Act and Regulations in SaskatchewanChanges to the Condominium Property Act and Regulations in Saskatchewan
Changes to the Condominium Property Act and Regulations in Saskatchewan
 
THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?
THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?
THE LABOUR MARKET IN ITALY: WILL REFORMS ALONE CREATE EMPLOYMENT?
 
Direct Tax Amendments Applicable From 1st April 2017
Direct Tax Amendments Applicable From 1st April 2017Direct Tax Amendments Applicable From 1st April 2017
Direct Tax Amendments Applicable From 1st April 2017
 

Similar to GDPRR: The Key Changes

Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRBartLieben
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protectionMRS
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterBrowne Jacobson LLP
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection RegulationGrittyCC
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPRNeha Patel
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance IT Governance Ltd
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationIBM Security
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...m-hance
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterBigDataExpo
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 

Similar to GDPRR: The Key Changes (20)

GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de Poorter
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 

Recently uploaded

Illinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideIllinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideillinoisworknet11
 
Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...shubhuc963
 
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTSTHE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTSRoshniSingh312153
 
昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书
昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书
昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书1k98h0e1
 
Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791BlayneRush1
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
Hungarian legislation made by Robert Miklos
Hungarian legislation made by Robert MiklosHungarian legislation made by Robert Miklos
Hungarian legislation made by Robert Miklosbeduinpower135
 
The Patents Act 1970 Notes For College .pptx
The Patents Act 1970 Notes For College .pptxThe Patents Act 1970 Notes For College .pptx
The Patents Act 1970 Notes For College .pptxAdityasinhRana4
 
Attestation presentation under Transfer of property Act
Attestation presentation under Transfer of property ActAttestation presentation under Transfer of property Act
Attestation presentation under Transfer of property Act2020000445musaib
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiBlayneRush1
 
Presentation1.pptx on sedition is a good legal point
Presentation1.pptx on sedition is a good legal pointPresentation1.pptx on sedition is a good legal point
Presentation1.pptx on sedition is a good legal pointMohdYousuf40
 
Conditions Restricting Transfer Under TPA,1882
Conditions Restricting Transfer Under TPA,1882Conditions Restricting Transfer Under TPA,1882
Conditions Restricting Transfer Under TPA,18822020000445musaib
 
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdfWurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdfssuser3e15612
 
citizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicablecitizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicableSaraSantiago44
 
Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.2020000445musaib
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceMichael Cicero
 
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksUnderstanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksFinlaw Associates
 
Rights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaRights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaAbheet Mangleek
 
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxSarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxAnto Jebin
 
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeAlexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeBlayneRush1
 

Recently uploaded (20)

Illinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideIllinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guide
 
Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...
 
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTSTHE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
 
昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书
昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书
昆士兰科技大学毕业证学位证成绩单-补办步骤澳洲毕业证书
 
Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
Hungarian legislation made by Robert Miklos
Hungarian legislation made by Robert MiklosHungarian legislation made by Robert Miklos
Hungarian legislation made by Robert Miklos
 
The Patents Act 1970 Notes For College .pptx
The Patents Act 1970 Notes For College .pptxThe Patents Act 1970 Notes For College .pptx
The Patents Act 1970 Notes For College .pptx
 
Attestation presentation under Transfer of property Act
Attestation presentation under Transfer of property ActAttestation presentation under Transfer of property Act
Attestation presentation under Transfer of property Act
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
 
Presentation1.pptx on sedition is a good legal point
Presentation1.pptx on sedition is a good legal pointPresentation1.pptx on sedition is a good legal point
Presentation1.pptx on sedition is a good legal point
 
Conditions Restricting Transfer Under TPA,1882
Conditions Restricting Transfer Under TPA,1882Conditions Restricting Transfer Under TPA,1882
Conditions Restricting Transfer Under TPA,1882
 
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdfWurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
 
citizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicablecitizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicable
 
Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
 
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksUnderstanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
 
Rights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaRights of under-trial Prisoners in India
Rights of under-trial Prisoners in India
 
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxSarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
 
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeAlexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
 

GDPRR: The Key Changes

  • 1. General Data Protection Regulations: The Key Changes Craig Clark Information Security & Compliance Manager
  • 2. Topics • What is the GDPR? • European Law • Key Dates for the GDPR • Key changes from Data Protection Act - Harmonisation - Enforcement - Off Shore Processing - Governance - One Stop Shop - Consent - Transparency - Data Portability - Data Processors • Next Steps
  • 3. What is the GDPR? • A complete overhaul of data protection regulation with extensive updates of what can be considered identifiable information • Applies across all member states of the European Union • Applies to all organisations processing the data of EU data subjects –wherever the organisation is geographically based • Specific and significant rights for data subjects to seek compensation, rights to erasure and accurate representation • Compensation can be sought against organisations and individuals employed by them • Fines of up €20,000,00 or 4% global annual turnover • Significant reduction in that amount based on the implementation of technical, or organisational controls implemented
  • 4. European Law Landscape EU Legislation can be separated into two main branches: Directives • Require individual implementation in each Member State (Each State can implement rules in their own way) • Implemented by the creation of national laws approved by the parliaments of each Member State • European Directive 95/46/EC is a Directive • Sets out a goal that a member state must achieve –room for tailoring • UK Data Protection Act 1998
  • 5. European Law Landscape EU Legislation can be separated into two main branches: Regulations: • Immediately applicable in each Member State in a uniform manner • Binding legislative Act • Require no local implementing legislation – no tailoring • EU GDPR is a Regulation • Regulations are not negotiable by member states • Regulations may apply to countries outside the EU if they affect EU subjects (people who are originally from the EU)
  • 6. Key Dates for GDPR 8 April 2016 the European Council adopted the Regulation. 14 April 2016 the Regulation was adopted by the European Parliament. 4 May 2016, the official text of the Regulation was published in the EU Official Journal in all the official languages. The Regulation entered into force on 24 May 2016, and applies from 25 May 2018. This Regulation shall be binding in its entirety and directly applicable in all Member States.
  • 7. GDPR Structure European Data Protection Board Lead Supervising Authority (Information Commissioners Office) Data Processor Data Controller (Organisation) Data Subject (Individuals) 3rd Countries 3rd Party
  • 8. GDPR Structure • The European Data Protection Board will issue guidance for controllers and processors • They will facilitate the use of Data Protection Impact Assessments • The ICO will oversee both Data Controllers and Data Processors • Breaches and Notifications will be made to the ICO • 3rd Countries – countries to which data is transferred • At the centre of the GDPR is the protection of Personally Identifiable Information
  • 9. Key Changes Between DPA and GDPR Harmonisation Across Member States: • Adoption of a single set of rules on data protection, directly applicable in all EU Member States: Even if the UK leave the EU the GDPR will apply for all EU Data Subjects • Each Member State has previously implemented data protection laws locally which transpose the EU Data Protection Directive leading to fragmentation in terms of compliance requirements across Member States. • The GDPR is intended to adopt a harmonised approach to compliance across all Member States by implementing legislation that will be directly applicable in all 28 Member States. There will be no opportunity for local transposition.
  • 10. Key Changes Between DPA and GDPR Enforcement: • A revised enforcement regime underpinned by power for supervising authorities to levy heavy financial sanctions of up to 4% of the annual worldwide turnover of the organisation or €20 Million, whichever is greater. • Fines are designed to be effective and dissuasive and ensure that which will non compliance is considered a significant risk for businesses. • Supervisory authorities will have the power to impose these sanctions from where the data subject habitually resides or in the territory that the breach occurs. These changes will significantly increase the risk associated with privacy non-compliance.
  • 11. Key Changes Between DPA and GDPR Off Shore Processing: • Application of the GDPR to companies established outside the EU, if they target EU citizens e.g. international students. • The new rules have a broader territorial scope since they apply to non- EU established companies targeting the EU market by either offering their goods or services to EU citizens or by monitoring their behaviour. • Currently, EU Data Protection legislation only applies to non-EU established controllers if they make use of equipment on EU territory for the purposes of processing personal data, and to processing taking place in the EU.
  • 12. Key Changes Between DPA and GDPR Governance: Area of major change • Increased responsibility and accountability on organisations to manage how they control and process personal data. • Controllers must ensure all personal data is processed in compliance with the Regulation and be able to demonstrate compliance to a supervisory authority if requested. • There is now a requirement to keep extensive and detailed records of processing operations. • Organisations must perform Data Privacy Assessments for all high risk activities. • A Data Protection Officer must be formally appointed and recognised with a number of stipulations added for ensuring impartiality.
  • 13. Key Changes Between DPA and GDPR Governance Continued: • When notifying the regulator of data breaches, Controllers will be required to notify the Information Commissioners Office, and in some cases the data subjects involved of significant data breaches within 72 Hours. • Privacy by design - taking privacy risk into account throughout the process of designing a new product or service, rather than treating it as an afterthought. Now required to assess and implement appropriate technical and organisational measures and procedures from the outset to ensure that processing complies with the Regulation and protects the rights of the data subjects. • Privacy by default - ensuring mechanisms are applied retrospectively to ensure that, by default, only as much personal data is collected, used and retained for each processing task, both in terms of the amount of data collated and time for which it is kept.
  • 14. Key Changes Between DPA and GDPR One Stop Shop: • Ability to nominate a single national data protection authority as the lead regulator for all compliance issues in the EU, where the organisation has multiple points of presence across the EU
  • 15. Key Changes Between DPA and GDPR Consent: Area of major change • The DPA allows a controller to lawfully process data with the "consent" of the data subject. Consent can be either express or implied consent - or where the processing is necessary for the "legitimate interests" of the controller in circumstances that do not cause undue prejudice to the individual. • GDPR redefines consent. Now, consent must be freely given, specific, informed and unambiguous. Implied consent, (e.g., by just staying on a website or not responding to a request) will not be sufficient.
  • 16. Key Changes Between DPA and GDPR Consent Continued: • Requiring consent from an end user in order to give that person access to a service, where these personal data are not necessary to perform the contract, will no longer be allowed. • Controllers will be expected to provide much more consideration in their working practices as to what the data subject would like and expect their data to be used for. • Consent can be withdrawn any time, and as easy to withdraw consent as give it • Data subject must give consent for specific purposes - blanket consent no longer allowed –This has significant implications in information sharing, processing and retention • One month to respond to subject access and no charges can be applied • Must be able to supply evidence that consent for each specific purpose was given
  • 17. Key Changes Between DPA and GDPR Transparency: • Any communications with a data subject must be concise, transparent, intelligible • Controller must be transparent in providing information about itself and the purposes of the processing • Controller must provide data subject with information about their rights. • Policies must explain to data subjects both how their personal data will be processed and what their individual rights are and how they may be exercised. • This must be provided in an intelligible form, using clear and plain language that will be understood by the target audience.
  • 18. Key Changes Between DPA and GDPR Data Portability: • The Regulation introduces a new right to data portability, which grants data subjects the right to receive personal data concerning him or her, which he or she has provided to a controller, in a structured and commonly used and machine-readable format. • The data subject is also entitled to have the data transmitted directly from one controller to another, where this is technically feasible. • A statutory "right to be forgotten" has been included which will allow individuals the right to require a controller to delete data files relating to them if there are no legitimate grounds for retaining it – including when a subject has withdrawn consent.
  • 19. Key Changes Between DPA and GDPR Data Processors: • The GDPR directly regulates Data Processors • Processors will be required to comply with a number of specific obligations, including to maintain adequate documentation, implement appropriate security standards, carry out routine data protection impact assessments, appoint a data protection officer, comply with rules on international data transfers and cooperate with national supervisory authorities. • Processors will be liable to sanctions at the same level as controllers if they fail to meet these criteria. • Information Sharing Agreements will help ensure that Controllers give clear instructions to processors on how they expect and require their data to be handled.
  • 20. Next Steps • Meet with top management and form a Working Group to ensure that compliance with GDPR before it is enforced. • Follow the ICO’s ‘12 Point Plan’ for actions to take prior to introduction. • Obtain specialist knowledge in the implementation of changes required and ongoing compliance with GDPR. • ITIBGQ offer Foundation and Practitioner certification in EU GDPR – in my view these certifications are essential for Information Security managers so that they can provide the skills and advice required to ensure compliance.

Editor's Notes

  1. This is a rather dry, formal definition but useful.
  2. This is a rather dry, formal definition but useful.