SlideShare une entreprise Scribd logo
1  sur  25
Data Protection - All Change
or More of the Same?
Paul Ticher
This presentation is intended to help you
understand aspects of the Data Protection Act
1998 and related legislation.
It is not intended to provide detailed advice on
specific points, and is not necessarily a full
statement of the law.

Data Protection - All Change or More of the Same?
What Data Protection is about: 1



Protecting data

Protecting people
Prevent harm to the individuals whose data we
hold, or other people
• Keep information in the right hands
• Hold good quality data

Data Protection - All Change or More of the Same?


What Data Protection is about: 2
Give us
more
money!

Support our
campaign!

We sold your
details to
someone else

Reassure people that we use their information
responsibly, so that they trust us
• Be transparent – open and honest, don‟t hide
things or go behind people‟s back
• Offer people a reasonable choice over how you
use their data, and what for
Data Protection - All Change or More of the Same?
What Data Protection is about: 3

Comply with specific legal requirements, such as:

Right to opt out of direct marketing



Right of Subject Access
Notification
(And others)

Data Protection - All Change or More of the Same?
The main topics for today
Top priorities
• Security
And while we‟re about it
• Transparency
• Latest developments on
• Choice
• Enforcement
• Accuracy & data quality
• Guidance
• New EU Regulation
But first:
• The Data Protection Principles
• The definition of Personal data
• Confidentiality

Data Protection - All Change or More of the Same?
The Data Protection Principles

1. Data „processing‟ must be „fair‟ and legal
2. You must limit your use of data to the purpose(s)
you obtained it for
3. Data must be adequate, relevant & not excessive
4. Data must be accurate & up to date
5. Data must not be held longer than necessary
6. Data Subjects‟ rights must be respected
7. You must have appropriate security
8. Special rules apply to transfers abroad

Data Protection - All Change or More of the Same?
Personal data

The Act applies to information that is „personal‟ and
„data‟
The personal part means that it is about:
identifiable, living individuals
The data part means that it is recorded:
• on a computer or automated system
• in a „relevant filing system‟
• with the intention of going into one of these
systems
• (others apply to public bodies)

Data Protection - All Change or More of the Same?
How DP and Confidentiality overlap

Data Protection

Confidentiality

Clear boundaries

Data Protection - All Change or More of the Same?
Taking confidentiality seriously

Gossip

Scams
Circumventing
security

Data Protection - All Change or More of the Same?
Security (Principle 7)

The Data Protection Act says you must prevent:
• unauthorised access to personal data
• accidental loss or damage of personal data
The security measures must be appropriate.
They must also be technical and organisational.

The Information Commissioner can
impose a penalty of up to £???????
for gross breaches of security (or
other Data Protection requirements)

Data Protection - All Change or More of the Same?
Key security measures

Protect „data in transit‟
• passwords, encryption on USB devices, tablets
and laptops
• extreme care when faxing, e-mailing & posting
• think about encryption on e-mails if appropriate
Network security – anti-virus, firewall, log-ons, etc.
Website security – „OWASP top ten‟ or similar
Bring Your Own Device policy
External contractors („Data Processors‟)
Secure destruction – shredding, etc.
Access controls, clear desks, locked filing cabinets
Staff DBS checks, supervision and monitoring

Data Protection - All Change or More of the Same?
‘Fair’ processing (Pr. 1): Transparency

One part of being fair to people is to make sure they
have no unpleasant surprises when you use data
about them.
This means you must always think whether you
need to tell them anything about:
• who is collecting their information
• what purposes you hold their data for
• who you might pass the data on to
• how to contact you if they want to stop you from
using their data or check what you are doing

Data Protection - All Change or More of the Same?
‘Fair’ processing (Pr. 1): Choice

The other important part of being fair is to give
people a reasonable choice over how their
information is used.
People must be given a choice over Direct
marketing
Choices can be:
• Opt out (we‟ll do it unless you say „no‟)
• Opt in (we‟ll only do it if you say „yes‟)
Be clear about what choices are offered, record
them carefully, and ensure that they are acted on.
Pre-ticked boxes are not good practice

Data Protection - All Change or More of the Same?
Conditions for fair processing

You must meet at least one of these:
• With consent of the Data Subject
(“specific, informed and freely given”)
• For a contract involving the Data Subject
• To meet a legal obligation
• To protect the Subject‟s „vital interests‟
• Government & judicial functions
• In your „legitimate interests‟ (or those you
disclose to) provided you don‟t infringe the Data
Subject‟s rights, freedoms or legitimate interests

Data Protection - All Change or More of the Same?
Data quality (Principles 3 & 4)

The Data Protection Act says that data must be:
• Adequate
• Relevant
• Not excessive
• Accurate
• Up to date (where necessary)

Data Protection - All Change or More of the Same?
Data Controller
The „person‟ legally responsible for complying with
the Data Protection Act


Staff & volunteers are part of the Data Controller
A trading company is a separate Data Controller
Organisations can be joint Data Controllers

Data Protection - All Change or More of the Same?


Data Processor
An organisation that has access to Personal Data
on your behalf for your purposes
The Data Controller remains responsible for what
happens to the data
There must be a written contract with the Data
Processor, setting out the relationship and, in
particular, their security responsibilities
Data Processors could include:
• Payroll service
• Cloud computing provider
• Tele-marketing company
• Client database maintenance & development
• Mailing house
• Contractor, delivering services
Data Protection - All Change or More of the Same?
Developments in enforcement

Recent penalties include:
• Fines for spam messaging
• Fine for breach caused by employee working
from home
• Fines for charities
Other options: enforcement notices, legally binding
undertakings
There have been a few successful challenges on
technicalities
Information Commissioner is consulting on a more
targeted approach to handling complaints

Data Protection - All Change or More of the Same?
Developments in ICO guidance

Recent publications include:
• a Code of Practice on handling Subject Access
• guidance on Bring Your Own Device policies
• a complete update of their guidance on Direct
Marketing
• guidance on Social Networking
• consultation on a review of the Privacy Notices
Code of Practice

Data Protection - All Change or More of the Same?
New EU Regulation: Rationale

1995: Directive 95/46/EC
1998: UK Data Protection Act (in force from 2000)
2003 (and earlier): Privacy & Electronic
Communications Regulations
Subsequently:
• World Wide Web
• Cloud computing
• Social media
• Profiling
• Cookies, GPS tracking ...
• Privacy awareness

Data Protection - All Change or More of the Same?
New EU Regulation: Timetable

January 2012: first draft published by Commission
2012: various EU bodies contribute views
2013: attempts to reconcile differing views, with
several conflicting drafts produced
October 2013: compromise draft agreed by
parliament
2015? Negotiations with Council
Mid-2015? Ratification of final Regulation

Data Protection - All Change or More of the Same?
New EU Regulation: Some key issues

Consent tightened up – no more pre-ticked boxes
Marketing is a „legitimate interest‟
Limited right of erasure
Right to object to profiling
More detailed privacy notices
Mandatory breach notification
Data Protection by default and by design
Mandatory Data Protection Officer
Privacy impact assessments replace Notification
Much-increased penalties (especially for multinational companies)

Data Protection - All Change or More of the Same?
Data Protection: the absolute basics

We are trying to:
• Prevent harm by
• Keeping data only in the right hands (and
being clear what „the right hands‟ are)
• Holding good quality data (accurate, up to
date and adequate)
• Reassure people so that they trust us
• Making sure people know enough about
what we are doing
• Giving people a choice where possible

Data Protection - All Change or More of the Same?
Thank you for listening

To go into more detail, join one of my webinars:
www.paulticher.com/webinars

Or contact me at:
0116 273 8191
paul@paulticher.com

Your Logo

www.paulticher.com

2 Old College Court, 29 Priory Street, Ware, Hertfordshire, SG12 0DE

Contenu connexe

Tendances

Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Harrison Leavey
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashedChris Gilmour
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudGurbir Singh
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for developmentTomppa Järvinen
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 

Tendances (20)

Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 

En vedette

Keep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection RegulationKeep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection RegulationDavid Reed
 
What's new in Vectorworks 2016
What's new in Vectorworks 2016What's new in Vectorworks 2016
What's new in Vectorworks 2016elinapaul
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Per Norhammar
 
Data Protector 9.07 what is new
Data Protector 9.07 what is new Data Protector 9.07 what is new
Data Protector 9.07 what is new Andrey Karpov
 
Data Protection overview presentation
Data Protection overview presentationData Protection overview presentation
Data Protection overview presentationAndrey Karpov
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
Annual employment law update, January 2017, Exeter
Annual employment law update, January 2017, ExeterAnnual employment law update, January 2017, Exeter
Annual employment law update, January 2017, ExeterBrowne Jacobson LLP
 
What is new in vectorworks 2017
What is new in vectorworks 2017What is new in vectorworks 2017
What is new in vectorworks 2017elinapaul
 
Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017Matheson Law Firm
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...Exove
 
DMI 2017 Mobile Trends
DMI 2017 Mobile TrendsDMI 2017 Mobile Trends
DMI 2017 Mobile TrendsDMI
 

En vedette (12)

Keep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection RegulationKeep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection Regulation
 
What's new in Vectorworks 2016
What's new in Vectorworks 2016What's new in Vectorworks 2016
What's new in Vectorworks 2016
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?
 
Data Protector 9.07 what is new
Data Protector 9.07 what is new Data Protector 9.07 what is new
Data Protector 9.07 what is new
 
Data Protection overview presentation
Data Protection overview presentationData Protection overview presentation
Data Protection overview presentation
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Annual employment law update, January 2017, Exeter
Annual employment law update, January 2017, ExeterAnnual employment law update, January 2017, Exeter
Annual employment law update, January 2017, Exeter
 
What is new in vectorworks 2017
What is new in vectorworks 2017What is new in vectorworks 2017
What is new in vectorworks 2017
 
Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
DMI 2017 Mobile Trends
DMI 2017 Mobile TrendsDMI 2017 Mobile Trends
DMI 2017 Mobile Trends
 
Design Your Career 2018
Design Your Career 2018Design Your Career 2018
Design Your Career 2018
 

Similaire à DP Act Changes and EU Regulation

Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11mrmwood
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 septRachel Aldighieri
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPRNate Stockard
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? Desynit
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteClive Rich
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Rachel Aldighieri
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015Rachel Aldighieri
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUser Vision
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesStephen Denning
 

Similaire à DP Act Changes and EU Regulation (20)

Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me?
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 

Dernier

Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxfnnc6jmgwh
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfIngrid Airi González
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfNeo4j
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Strongerpanagenda
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Farhan Tariq
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Nikki Chapple
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Mark Goldstein
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPathCommunity
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 

Dernier (20)

Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdf
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdf
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to Hero
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 

DP Act Changes and EU Regulation

  • 1. Data Protection - All Change or More of the Same? Paul Ticher
  • 2. This presentation is intended to help you understand aspects of the Data Protection Act 1998 and related legislation. It is not intended to provide detailed advice on specific points, and is not necessarily a full statement of the law. Data Protection - All Change or More of the Same?
  • 3. What Data Protection is about: 1  Protecting data Protecting people Prevent harm to the individuals whose data we hold, or other people • Keep information in the right hands • Hold good quality data Data Protection - All Change or More of the Same? 
  • 4. What Data Protection is about: 2 Give us more money! Support our campaign! We sold your details to someone else Reassure people that we use their information responsibly, so that they trust us • Be transparent – open and honest, don‟t hide things or go behind people‟s back • Offer people a reasonable choice over how you use their data, and what for Data Protection - All Change or More of the Same?
  • 5. What Data Protection is about: 3 Comply with specific legal requirements, such as: Right to opt out of direct marketing  Right of Subject Access Notification (And others) Data Protection - All Change or More of the Same?
  • 6. The main topics for today Top priorities • Security And while we‟re about it • Transparency • Latest developments on • Choice • Enforcement • Accuracy & data quality • Guidance • New EU Regulation But first: • The Data Protection Principles • The definition of Personal data • Confidentiality Data Protection - All Change or More of the Same?
  • 7. The Data Protection Principles 1. Data „processing‟ must be „fair‟ and legal 2. You must limit your use of data to the purpose(s) you obtained it for 3. Data must be adequate, relevant & not excessive 4. Data must be accurate & up to date 5. Data must not be held longer than necessary 6. Data Subjects‟ rights must be respected 7. You must have appropriate security 8. Special rules apply to transfers abroad Data Protection - All Change or More of the Same?
  • 8. Personal data The Act applies to information that is „personal‟ and „data‟ The personal part means that it is about: identifiable, living individuals The data part means that it is recorded: • on a computer or automated system • in a „relevant filing system‟ • with the intention of going into one of these systems • (others apply to public bodies) Data Protection - All Change or More of the Same?
  • 9. How DP and Confidentiality overlap Data Protection Confidentiality Clear boundaries Data Protection - All Change or More of the Same?
  • 11. Security (Principle 7) The Data Protection Act says you must prevent: • unauthorised access to personal data • accidental loss or damage of personal data The security measures must be appropriate. They must also be technical and organisational. The Information Commissioner can impose a penalty of up to £??????? for gross breaches of security (or other Data Protection requirements) Data Protection - All Change or More of the Same?
  • 12. Key security measures Protect „data in transit‟ • passwords, encryption on USB devices, tablets and laptops • extreme care when faxing, e-mailing & posting • think about encryption on e-mails if appropriate Network security – anti-virus, firewall, log-ons, etc. Website security – „OWASP top ten‟ or similar Bring Your Own Device policy External contractors („Data Processors‟) Secure destruction – shredding, etc. Access controls, clear desks, locked filing cabinets Staff DBS checks, supervision and monitoring Data Protection - All Change or More of the Same?
  • 13. ‘Fair’ processing (Pr. 1): Transparency One part of being fair to people is to make sure they have no unpleasant surprises when you use data about them. This means you must always think whether you need to tell them anything about: • who is collecting their information • what purposes you hold their data for • who you might pass the data on to • how to contact you if they want to stop you from using their data or check what you are doing Data Protection - All Change or More of the Same?
  • 14. ‘Fair’ processing (Pr. 1): Choice The other important part of being fair is to give people a reasonable choice over how their information is used. People must be given a choice over Direct marketing Choices can be: • Opt out (we‟ll do it unless you say „no‟) • Opt in (we‟ll only do it if you say „yes‟) Be clear about what choices are offered, record them carefully, and ensure that they are acted on. Pre-ticked boxes are not good practice Data Protection - All Change or More of the Same?
  • 15. Conditions for fair processing You must meet at least one of these: • With consent of the Data Subject (“specific, informed and freely given”) • For a contract involving the Data Subject • To meet a legal obligation • To protect the Subject‟s „vital interests‟ • Government & judicial functions • In your „legitimate interests‟ (or those you disclose to) provided you don‟t infringe the Data Subject‟s rights, freedoms or legitimate interests Data Protection - All Change or More of the Same?
  • 16. Data quality (Principles 3 & 4) The Data Protection Act says that data must be: • Adequate • Relevant • Not excessive • Accurate • Up to date (where necessary) Data Protection - All Change or More of the Same?
  • 17. Data Controller The „person‟ legally responsible for complying with the Data Protection Act  Staff & volunteers are part of the Data Controller A trading company is a separate Data Controller Organisations can be joint Data Controllers Data Protection - All Change or More of the Same? 
  • 18. Data Processor An organisation that has access to Personal Data on your behalf for your purposes The Data Controller remains responsible for what happens to the data There must be a written contract with the Data Processor, setting out the relationship and, in particular, their security responsibilities Data Processors could include: • Payroll service • Cloud computing provider • Tele-marketing company • Client database maintenance & development • Mailing house • Contractor, delivering services Data Protection - All Change or More of the Same?
  • 19. Developments in enforcement Recent penalties include: • Fines for spam messaging • Fine for breach caused by employee working from home • Fines for charities Other options: enforcement notices, legally binding undertakings There have been a few successful challenges on technicalities Information Commissioner is consulting on a more targeted approach to handling complaints Data Protection - All Change or More of the Same?
  • 20. Developments in ICO guidance Recent publications include: • a Code of Practice on handling Subject Access • guidance on Bring Your Own Device policies • a complete update of their guidance on Direct Marketing • guidance on Social Networking • consultation on a review of the Privacy Notices Code of Practice Data Protection - All Change or More of the Same?
  • 21. New EU Regulation: Rationale 1995: Directive 95/46/EC 1998: UK Data Protection Act (in force from 2000) 2003 (and earlier): Privacy & Electronic Communications Regulations Subsequently: • World Wide Web • Cloud computing • Social media • Profiling • Cookies, GPS tracking ... • Privacy awareness Data Protection - All Change or More of the Same?
  • 22. New EU Regulation: Timetable January 2012: first draft published by Commission 2012: various EU bodies contribute views 2013: attempts to reconcile differing views, with several conflicting drafts produced October 2013: compromise draft agreed by parliament 2015? Negotiations with Council Mid-2015? Ratification of final Regulation Data Protection - All Change or More of the Same?
  • 23. New EU Regulation: Some key issues Consent tightened up – no more pre-ticked boxes Marketing is a „legitimate interest‟ Limited right of erasure Right to object to profiling More detailed privacy notices Mandatory breach notification Data Protection by default and by design Mandatory Data Protection Officer Privacy impact assessments replace Notification Much-increased penalties (especially for multinational companies) Data Protection - All Change or More of the Same?
  • 24. Data Protection: the absolute basics We are trying to: • Prevent harm by • Keeping data only in the right hands (and being clear what „the right hands‟ are) • Holding good quality data (accurate, up to date and adequate) • Reassure people so that they trust us • Making sure people know enough about what we are doing • Giving people a choice where possible Data Protection - All Change or More of the Same?
  • 25. Thank you for listening To go into more detail, join one of my webinars: www.paulticher.com/webinars Or contact me at: 0116 273 8191 paul@paulticher.com Your Logo www.paulticher.com 2 Old College Court, 29 Priory Street, Ware, Hertfordshire, SG12 0DE