SlideShare une entreprise Scribd logo
1  sur  29
Wednesday 10th June 2015 – DMA House, London
Janine Paterson, Solicitor & Legal Manager, DMA
An introduction to data protection
Agenda
8.30am Registration and welcome
9.00am Why is data protection important?
9.05am Understanding the law
The Data Protection Act 1998
Key terms
8 Principles
10.00am Break
10.10am Understanding the law
The Privacy and Electronic Communications Regulation 2003
Key rules
Key points
10.30am Practical tips for marketers
10.50am Questions
11.00am Close
Why is it important?
• It helps us to protect information about ourselves and others
• It helps us avoid damage to the reputation of our organisation
• It makes good business sense – it can increase efficiency and
effectiveness
• It helps us avoid enforcement action by the Information
Commissioner
– both employers and employees can be prosecuted
– companies can face a monetary penalty of up to £500,000 for
major breaches
Agenda
8.30am Registration and welcome
9.00am Why is data protection important?
9.05am Understanding the law
The Data Protection Act 1998
Key terms
8 Principles
10.00am Break
10.10am Understanding the law
The Privacy and Electronic Communications Regulation 2003
Key rules
Key points
10.30am Practical tips for marketers
10.50am Summary and questions
11.00am Close
Agenda
8.30am Registration and welcome
9.00am Why is data protection important?
9.05am Understanding the law
The Data Protection Act 1998
Key terms
8 Principles
10.00am Break
10.10am Understanding the law
The Privacy and Electronic Communications Regulation 2003
Key rules
Key points
10.30am Practical tips for marketers
10.50am Summary and questions
11.00am Close
Understanding the law 1
• Data Protection Act 1998 (DPA)
– Came into force 1 March 2000
– Replaced 1984 Act
– Covers doing anything with data
– Applies electronic records and some manual records
Key terms
• Personal data
– any data that can be used to identify a living individual
– Examples of personal data can include:
• Name and address
• Email address (even business email addresses if they are non generic)
• Name and telephone number
• Photographs
– Only personal data is protected by the DPA
• Sensitive personal data
– any data relating to:
• Health
• Race or ethnic origin
• Political opinions
• Religious beliefs
• Trade union membership
• Sex life
• Criminal proceedings or convictions
Key terms
• Processing
– obtaining, recording or holding information or carrying out any
operation on the information including
• Organising
• Adapting
• Retrieving
• Disclosing
• Blocking
• Destroying
• Data subject
– a living identifiable individual to whom the personal data relates
Key terms
• Data controller
- Determines how data will be used
- Usually owns or rents the data (may be done by 3rd party on their
behalf)
- Required to notify (register) as a controller with the ICO
- May be fined by ICO if any data breaches arise
• Data processor
- Processes data on behalf of controller or other processor
- Processing can be anything from data storage to
advanced data manipulation and modelling
- Includes companies that manage / broker / collect data on
behalf of others
The 8 principles
• Fairly and lawfully collected
• Processed for specified and limited purposes
• Adequate, relevant and not excessive
• Accurate and kept up to date
• Not kept for longer than necessary
• Processed in accordance with Individuals’ rights
• Security – appropriate technical and organisational measures
• Not transferred outside the European Economic Area (EEA) unless
adequate protections are in place
• (EEA: The 28 member states of the EU, plus Iceland, Liechtenstein
and Norway)
Principle 1: Fairly and lawfully
collected
• Fair processing information provided
• Organisation’s identity given
• Purpose of collection made clear
• Further information necessary
• Correct permissions obtained
- Implied consent: opt-out mechanism provided
- Express consent: opt-in mechanism provided
• Sensitive personal data only captured if strictly necessary
Principle 2: Processed for limited
purposes
• Only process data for the purpose(s) you told the individual
• Make the purpose(s) clear at the point of data collection
• Change of circumstances – what happens to the data then?
• Subsequent use of data for direct marketing purposes
• Data cleansing – regular and ad hoc
Principle 3: Adequate, relevant and
not excessive
• Minimum amount of information required
• Additional information for specific individuals
• Collect data that you will use now
• Collection of data that ‘may be useful’ in the future is not permitted
Principle 4: Accurate and kept up to
date
• Take reasonable steps to ensure accuracy (but what is ‘reasonable’?)
• Ensure data is not incorrect or misleading
• Undertake regular data cleansing
• Clean data against the relevant preference service files and other
appropriate cleansing files
Principle 5: Not kept for longer than
necessary
• Keep for as long as purpose collected for
• Suppression lists
Principle 6: Processed in
accordance with the right of data
subjects
• Subject access requests
• ‘Where did you get my data from?’
• Right to prevent direct marketing
• Customer service / legally required communications – no opt-out
provision required
• Right to have inaccurate data corrected
Principle 7: Technological and
organisational security
• Data security must be appropriate – take account of:
– Current state of technological development
– Cost of implementing security measures
– Potential harm that could result from a data breach
– Nature of data to be protected – non/sensitive?
• Need for risk assessment and risk management techniques
• Record your findings and assessments
Principle 7: Technological and
organisational security (continued)
• Ensure adequate organisational data security measures
• Prevent unauthorised as well as unlawful processing or disclosure of
data
• Security measures by data controller and data processor
• Data processing and transfer agreements in place
• Staff training
• Data access on a ‘need to know’ basis – individual log-ins only
• Secure disposal of data – internally/externally - keep records
Principle 8: Processed within the
EEA unless adequate protection in
place
• Data can be freely transferred within the EEA (providing data transfer
agreements are in place)
• Do not transfer data unless the country (destination and countries
data is routed via) have an adequate level of data protection
• Need to inform individuals before transferring their data outside the
EEA but do not need their consent
Understanding the law 2
• Privacy and Electronic Communications Regulations 2003 (PECR)
– Came into force 11 December 2003
– Covers electronic communications – email, telephone, SMS
Key rules
• Sender must not conceal their identity
• Communication must have valid address where opt-outs can be sent
• Opt-in required for individuals (B2C)
• Soft opt-in/existing customer exemption – available:
– When you are collecting the address/mobile number in the sale or
negotiations for the sale of a product or service;
– You only send communications about similar products and
services;
– You provided an opportunity at time of collection to opt-out.
Key points
• Existing customer exemption: Not an excuse for unsolicited contact
where correct permissions were never obtained
• B2B – Opt-out and marketing message needs to directly relate to the
work they do.
• Subject headers in emails must be clear and accurate
• Free and simple-to-use opt-out method must always be provided
• Action unsubscribe requests promptly – add to internal suppression
file
• Maintain different flags for different types of communication – helps to
avoid general opt-outs for all channels
Practical tips for marketers
• Data capture forms
• Marketing permissions
• Sourcing data
• Regaining lost permission
Data capture forms
• Key information to include;
– Why the data is being requested
– What the data will be used for
– Provision of an opt-in/out for marketing
– Marketing channels to be used
– Link to privacy policy
• Key information to include in privacy policy
– How the data subject can opt-out of marketing
– If the data will be processed outside the EEA
– How long the data will be kept for
– How to make a subject access request
– How to make a complaint regarding use of data
Marketing permissions
Own marketing 3rd party marketing Own marketing 3rd party marketing
Mail opt-out
opt-out (MPS
screening) opt-out opt-out
Telephone opt-out
opt-out (TPS
screening) opt-out
opt-out (TPS/ CTPS
screening)
Email
opt-in/ soft opt-
in opt-in
opt-in (unless
corporate
subscriber
exemption)
opt-in (unless
corporate subscriber
exemption)
SMS
opt-in/ soft opt-
in opt-in opt-in opt-in
Fax opt-in opt-in opt-out
opt-out (FPS
screening)
B2C B2B
Sourcing data/ due diligence
• Who compiled the list? When? Has it been amended or updated
since?
• When was consent obtained?
• Who obtained consent and what was the context?
• Was it opt-in or opt-out?
• Was information provided clearly and intelligibly? How was it
provided?
• Did it list organisations by name, by description, or any third party?
Regaining lost permissions
• Why was permission lost:
– Poor customer service?
– Poor communications timing?
– Inappropriate offers?
– In-house technical issues – permissions not recorded on CRM
system
• Revalidation exercise – obtaining up-to-date data
• Can very occasionally include request regarding marketing update in
a service message providing it is a minor part of the message
• If you have only lost permission for certain channels, contact via
another channel to update permissions
Data protection toolkit
www.dma.org.uk/product/data-protection-toolkit
Contacts
Janine Paterson, Solicitor & Legal Manager, DMA
T - 020 7291 3347
janine.paterson@dma.org.uk
Legal Advice Email Box
legaladvice@dma.org.uk

Contenu connexe

Tendances

Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Actmrmwood
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentationIan Clive Oultram
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protectionmeritnorthwest
 
Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Harrison Leavey
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection ActSaimaRafiq
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk- Mark - Fullbright
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentationOvationsGroup
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 

Tendances (20)

Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protection
 
Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)
 
POPI Seminar FINAL
POPI Seminar FINALPOPI Seminar FINAL
POPI Seminar FINAL
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentation
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
POPI Update 2013
POPI Update 2013POPI Update 2013
POPI Update 2013
 
PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 

En vedette

Presentation for ITS 2012
Presentation for ITS 2012Presentation for ITS 2012
Presentation for ITS 2012Genki Furumi
 
Masada family tree
Masada family treeMasada family tree
Masada family treefujii57
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
History of Development AL in Australia
History of Development AL in  AustraliaHistory of Development AL in  Australia
History of Development AL in AustraliaMatahati Mahbol
 
How Agile Solves Project Management Problems
How Agile Solves Project Management ProblemsHow Agile Solves Project Management Problems
How Agile Solves Project Management ProblemsDesigned Culture
 
DMA Integration Summit 2013 - Microsoft
DMA Integration Summit 2013 - MicrosoftDMA Integration Summit 2013 - Microsoft
DMA Integration Summit 2013 - MicrosoftRachel Aldighieri
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMARachel Aldighieri
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Rachel Aldighieri
 
張豐年醫師否決「國光石化之開發」
張豐年醫師否決「國光石化之開發」張豐年醫師否決「國光石化之開發」
張豐年醫師否決「國光石化之開發」佳真 王
 
What does data sharing mean to consumers? - 27 February 2013
What does data sharing mean to consumers? - 27 February 2013What does data sharing mean to consumers? - 27 February 2013
What does data sharing mean to consumers? - 27 February 2013Rachel Aldighieri
 
FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)
FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)
FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)DyanaCD
 
DMA Mobile connects presentation
DMA Mobile connects presentationDMA Mobile connects presentation
DMA Mobile connects presentationRachel Aldighieri
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Rachel Aldighieri
 
Mobilising print media: new paths to purchase
Mobilising print media: new paths to purchase Mobilising print media: new paths to purchase
Mobilising print media: new paths to purchase Rachel Aldighieri
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustRachel Aldighieri
 

En vedette (20)

Magazine
MagazineMagazine
Magazine
 
Renaissance
RenaissanceRenaissance
Renaissance
 
Legal update
Legal updateLegal update
Legal update
 
Presentation for ITS 2012
Presentation for ITS 2012Presentation for ITS 2012
Presentation for ITS 2012
 
Masada family tree
Masada family treeMasada family tree
Masada family tree
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
History of Development AL in Australia
History of Development AL in  AustraliaHistory of Development AL in  Australia
History of Development AL in Australia
 
How Agile Solves Project Management Problems
How Agile Solves Project Management ProblemsHow Agile Solves Project Management Problems
How Agile Solves Project Management Problems
 
DMA Integration Summit 2013 - Microsoft
DMA Integration Summit 2013 - MicrosoftDMA Integration Summit 2013 - Microsoft
DMA Integration Summit 2013 - Microsoft
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...
 
張豐年醫師否決「國光石化之開發」
張豐年醫師否決「國光石化之開發」張豐年醫師否決「國光石化之開發」
張豐年醫師否決「國光石化之開發」
 
What does data sharing mean to consumers? - 27 February 2013
What does data sharing mean to consumers? - 27 February 2013What does data sharing mean to consumers? - 27 February 2013
What does data sharing mean to consumers? - 27 February 2013
 
Retweets
RetweetsRetweets
Retweets
 
FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)
FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)
FA DOKUMEN DD ISLAMIC MINT NUSANTARA_13012011 (7 hal)
 
DMA Mobile connects presentation
DMA Mobile connects presentationDMA Mobile connects presentation
DMA Mobile connects presentation
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015
 
Ugly duck
Ugly duckUgly duck
Ugly duck
 
Mobilising print media: new paths to purchase
Mobilising print media: new paths to purchase Mobilising print media: new paths to purchase
Mobilising print media: new paths to purchase
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 August
 

Similaire à An Introduction to Data Protection (London) - June 2015

Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing associationiof_events
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...m-hance
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillSymptai Consulting Limited
 
5) How charities can protect themselves against data reform - ‘Emerging Digit...
5) How charities can protect themselves against data reform - ‘Emerging Digit...5) How charities can protect themselves against data reform - ‘Emerging Digit...
5) How charities can protect themselves against data reform - ‘Emerging Digit...Code Computerlove
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Forums financiers de Wallonie
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014Rachel Aldighieri
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013Rachel Aldighieri
 

Similaire à An Introduction to Data Protection (London) - June 2015 (20)

Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 
5) How charities can protect themselves against data reform - ‘Emerging Digit...
5) How charities can protect themselves against data reform - ‘Emerging Digit...5) How charities can protect themselves against data reform - ‘Emerging Digit...
5) How charities can protect themselves against data reform - ‘Emerging Digit...
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013
 
Living with gdpr
Living with gdprLiving with gdpr
Living with gdpr
 

Plus de Rachel Aldighieri

Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Rachel Aldighieri
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowRachel Aldighieri
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skillsRachel Aldighieri
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormRachel Aldighieri
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015Rachel Aldighieri
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterRachel Aldighieri
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Rachel Aldighieri
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterRachel Aldighieri
 
Simon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiSimon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiRachel Aldighieri
 
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Rachel Aldighieri
 
Tim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADTim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADRachel Aldighieri
 
David Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltDavid Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltRachel Aldighieri
 
Thinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberThinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberRachel Aldighieri
 
Thinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 NovemberThinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 NovemberRachel Aldighieri
 
Inserts nuts and bolts 2014 - Manchester
Inserts nuts and bolts 2014 - ManchesterInserts nuts and bolts 2014 - Manchester
Inserts nuts and bolts 2014 - ManchesterRachel Aldighieri
 

Plus de Rachel Aldighieri (20)

Navigating B2B marketing
Navigating B2B marketingNavigating B2B marketing
Navigating B2B marketing
 
Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to know
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skills
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order Form
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - Manchester
 
Legal update - 1 July
Legal update - 1 JulyLegal update - 1 July
Legal update - 1 July
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - Manchester
 
ZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROIZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROI
 
Simon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiSimon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBi
 
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...
 
Tim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADTim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&AD
 
David Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltDavid Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, Redsalt
 
Thinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberThinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 November
 
Thinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 NovemberThinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 November
 
Festival of Marketing
Festival of MarketingFestival of Marketing
Festival of Marketing
 
Inserts nuts and bolts 2014 - Manchester
Inserts nuts and bolts 2014 - ManchesterInserts nuts and bolts 2014 - Manchester
Inserts nuts and bolts 2014 - Manchester
 
Email tracking report 2014
Email tracking report 2014 Email tracking report 2014
Email tracking report 2014
 

Dernier

2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local Leads2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local LeadsSearch Engine Journal
 
Digital Marketing complete introduction.
Digital Marketing complete introduction.Digital Marketing complete introduction.
Digital Marketing complete introduction.Kashish Bindra
 
5 Digital Marketing Tips | Devherds Software Solutions
5 Digital Marketing Tips | Devherds Software Solutions5 Digital Marketing Tips | Devherds Software Solutions
5 Digital Marketing Tips | Devherds Software SolutionsDevherds Software Solutions
 
Creating a Successful Digital Marketing Campaign.pdf
Creating a Successful Digital Marketing Campaign.pdfCreating a Successful Digital Marketing Campaign.pdf
Creating a Successful Digital Marketing Campaign.pdfgopzzzin
 
Exploring the Impact of Social Media Trends on Society.pdf
Exploring the Impact of Social Media Trends on Society.pdfExploring the Impact of Social Media Trends on Society.pdf
Exploring the Impact of Social Media Trends on Society.pdfolivalibereo
 
top marketing posters - Fresh Spar Technologies - Manojkumar C
top marketing posters - Fresh Spar Technologies - Manojkumar Ctop marketing posters - Fresh Spar Technologies - Manojkumar C
top marketing posters - Fresh Spar Technologies - Manojkumar CManojkumar C
 
20 Top Social Media Tips for Peer Specialists
20 Top Social Media Tips for Peer Specialists20 Top Social Media Tips for Peer Specialists
20 Top Social Media Tips for Peer Specialistsmlicam615
 
Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...
Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...
Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...Associazione Digital Days
 
Codes and Conventions of Film Magazine Covers.pptx
Codes and Conventions of Film Magazine Covers.pptxCodes and Conventions of Film Magazine Covers.pptx
Codes and Conventions of Film Magazine Covers.pptxGeorgeCulica
 
15 Tactics to Scale Your Trade Show Marketing Strategy
15 Tactics to Scale Your Trade Show Marketing Strategy15 Tactics to Scale Your Trade Show Marketing Strategy
15 Tactics to Scale Your Trade Show Marketing StrategyBlue Atlas Marketing
 
TAM Sports IPL 17 Advertising Report- M01 - M23
TAM Sports IPL 17 Advertising Report- M01 - M23TAM Sports IPL 17 Advertising Report- M01 - M23
TAM Sports IPL 17 Advertising Report- M01 - M23Social Samosa
 
History of JWT by The Knowledge Center.pdf
History of JWT by The Knowledge Center.pdfHistory of JWT by The Knowledge Center.pdf
History of JWT by The Knowledge Center.pdfwilliam charnock
 
Gen Z and Millennial Debit Card Use Survey.pdf
Gen Z and Millennial Debit Card Use Survey.pdfGen Z and Millennial Debit Card Use Survey.pdf
Gen Z and Millennial Debit Card Use Survey.pdfMedia Logic
 
Agencia Marketing Branding Measurement Certification Google Ads Abril 2024
Agencia Marketing Branding Measurement Certification Google Ads Abril 2024Agencia Marketing Branding Measurement Certification Google Ads Abril 2024
Agencia Marketing Branding Measurement Certification Google Ads Abril 2024Marketing BRANDING
 
social media optimization complete indroduction
social media optimization complete indroductionsocial media optimization complete indroduction
social media optimization complete indroductioninfoshraddha747
 
Content Marketing: How To Find The True Value Of Your Marketing Funnel
Content Marketing: How To Find The True Value Of Your Marketing FunnelContent Marketing: How To Find The True Value Of Your Marketing Funnel
Content Marketing: How To Find The True Value Of Your Marketing FunnelSearch Engine Journal
 
Best digital marketing e-book form bignners
Best digital marketing e-book form bignnersBest digital marketing e-book form bignners
Best digital marketing e-book form bignnersmuntasibkhan58
 
Bamboo Charcoal Toothpaste By Phyto Atomy For More Details Message On WhatsA...
Bamboo Charcoal Toothpaste By Phyto Atomy  For More Details Message On WhatsA...Bamboo Charcoal Toothpaste By Phyto Atomy  For More Details Message On WhatsA...
Bamboo Charcoal Toothpaste By Phyto Atomy For More Details Message On WhatsA...shrutimishraqt
 
Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...
Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...
Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...Marketing BRANDING
 
Miss Immigrant USA Activity Pageant Program.pdf
Miss Immigrant USA Activity Pageant Program.pdfMiss Immigrant USA Activity Pageant Program.pdf
Miss Immigrant USA Activity Pageant Program.pdfMagdalena Kulisz
 

Dernier (20)

2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local Leads2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local Leads
 
Digital Marketing complete introduction.
Digital Marketing complete introduction.Digital Marketing complete introduction.
Digital Marketing complete introduction.
 
5 Digital Marketing Tips | Devherds Software Solutions
5 Digital Marketing Tips | Devherds Software Solutions5 Digital Marketing Tips | Devherds Software Solutions
5 Digital Marketing Tips | Devherds Software Solutions
 
Creating a Successful Digital Marketing Campaign.pdf
Creating a Successful Digital Marketing Campaign.pdfCreating a Successful Digital Marketing Campaign.pdf
Creating a Successful Digital Marketing Campaign.pdf
 
Exploring the Impact of Social Media Trends on Society.pdf
Exploring the Impact of Social Media Trends on Society.pdfExploring the Impact of Social Media Trends on Society.pdf
Exploring the Impact of Social Media Trends on Society.pdf
 
top marketing posters - Fresh Spar Technologies - Manojkumar C
top marketing posters - Fresh Spar Technologies - Manojkumar Ctop marketing posters - Fresh Spar Technologies - Manojkumar C
top marketing posters - Fresh Spar Technologies - Manojkumar C
 
20 Top Social Media Tips for Peer Specialists
20 Top Social Media Tips for Peer Specialists20 Top Social Media Tips for Peer Specialists
20 Top Social Media Tips for Peer Specialists
 
Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...
Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...
Francesco d’Angela, Service Designer di @HintoGroup- “Oltre la Frontiera Crea...
 
Codes and Conventions of Film Magazine Covers.pptx
Codes and Conventions of Film Magazine Covers.pptxCodes and Conventions of Film Magazine Covers.pptx
Codes and Conventions of Film Magazine Covers.pptx
 
15 Tactics to Scale Your Trade Show Marketing Strategy
15 Tactics to Scale Your Trade Show Marketing Strategy15 Tactics to Scale Your Trade Show Marketing Strategy
15 Tactics to Scale Your Trade Show Marketing Strategy
 
TAM Sports IPL 17 Advertising Report- M01 - M23
TAM Sports IPL 17 Advertising Report- M01 - M23TAM Sports IPL 17 Advertising Report- M01 - M23
TAM Sports IPL 17 Advertising Report- M01 - M23
 
History of JWT by The Knowledge Center.pdf
History of JWT by The Knowledge Center.pdfHistory of JWT by The Knowledge Center.pdf
History of JWT by The Knowledge Center.pdf
 
Gen Z and Millennial Debit Card Use Survey.pdf
Gen Z and Millennial Debit Card Use Survey.pdfGen Z and Millennial Debit Card Use Survey.pdf
Gen Z and Millennial Debit Card Use Survey.pdf
 
Agencia Marketing Branding Measurement Certification Google Ads Abril 2024
Agencia Marketing Branding Measurement Certification Google Ads Abril 2024Agencia Marketing Branding Measurement Certification Google Ads Abril 2024
Agencia Marketing Branding Measurement Certification Google Ads Abril 2024
 
social media optimization complete indroduction
social media optimization complete indroductionsocial media optimization complete indroduction
social media optimization complete indroduction
 
Content Marketing: How To Find The True Value Of Your Marketing Funnel
Content Marketing: How To Find The True Value Of Your Marketing FunnelContent Marketing: How To Find The True Value Of Your Marketing Funnel
Content Marketing: How To Find The True Value Of Your Marketing Funnel
 
Best digital marketing e-book form bignners
Best digital marketing e-book form bignnersBest digital marketing e-book form bignners
Best digital marketing e-book form bignners
 
Bamboo Charcoal Toothpaste By Phyto Atomy For More Details Message On WhatsA...
Bamboo Charcoal Toothpaste By Phyto Atomy  For More Details Message On WhatsA...Bamboo Charcoal Toothpaste By Phyto Atomy  For More Details Message On WhatsA...
Bamboo Charcoal Toothpaste By Phyto Atomy For More Details Message On WhatsA...
 
Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...
Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...
Agencia Marketing Branding Examen Fundamentals Digital Marketing Google Abril...
 
Miss Immigrant USA Activity Pageant Program.pdf
Miss Immigrant USA Activity Pageant Program.pdfMiss Immigrant USA Activity Pageant Program.pdf
Miss Immigrant USA Activity Pageant Program.pdf
 

An Introduction to Data Protection (London) - June 2015

  • 1. Wednesday 10th June 2015 – DMA House, London Janine Paterson, Solicitor & Legal Manager, DMA An introduction to data protection
  • 2. Agenda 8.30am Registration and welcome 9.00am Why is data protection important? 9.05am Understanding the law The Data Protection Act 1998 Key terms 8 Principles 10.00am Break 10.10am Understanding the law The Privacy and Electronic Communications Regulation 2003 Key rules Key points 10.30am Practical tips for marketers 10.50am Questions 11.00am Close
  • 3. Why is it important? • It helps us to protect information about ourselves and others • It helps us avoid damage to the reputation of our organisation • It makes good business sense – it can increase efficiency and effectiveness • It helps us avoid enforcement action by the Information Commissioner – both employers and employees can be prosecuted – companies can face a monetary penalty of up to £500,000 for major breaches
  • 4. Agenda 8.30am Registration and welcome 9.00am Why is data protection important? 9.05am Understanding the law The Data Protection Act 1998 Key terms 8 Principles 10.00am Break 10.10am Understanding the law The Privacy and Electronic Communications Regulation 2003 Key rules Key points 10.30am Practical tips for marketers 10.50am Summary and questions 11.00am Close
  • 5. Agenda 8.30am Registration and welcome 9.00am Why is data protection important? 9.05am Understanding the law The Data Protection Act 1998 Key terms 8 Principles 10.00am Break 10.10am Understanding the law The Privacy and Electronic Communications Regulation 2003 Key rules Key points 10.30am Practical tips for marketers 10.50am Summary and questions 11.00am Close
  • 6. Understanding the law 1 • Data Protection Act 1998 (DPA) – Came into force 1 March 2000 – Replaced 1984 Act – Covers doing anything with data – Applies electronic records and some manual records
  • 7. Key terms • Personal data – any data that can be used to identify a living individual – Examples of personal data can include: • Name and address • Email address (even business email addresses if they are non generic) • Name and telephone number • Photographs – Only personal data is protected by the DPA • Sensitive personal data – any data relating to: • Health • Race or ethnic origin • Political opinions • Religious beliefs • Trade union membership • Sex life • Criminal proceedings or convictions
  • 8. Key terms • Processing – obtaining, recording or holding information or carrying out any operation on the information including • Organising • Adapting • Retrieving • Disclosing • Blocking • Destroying • Data subject – a living identifiable individual to whom the personal data relates
  • 9. Key terms • Data controller - Determines how data will be used - Usually owns or rents the data (may be done by 3rd party on their behalf) - Required to notify (register) as a controller with the ICO - May be fined by ICO if any data breaches arise • Data processor - Processes data on behalf of controller or other processor - Processing can be anything from data storage to advanced data manipulation and modelling - Includes companies that manage / broker / collect data on behalf of others
  • 10. The 8 principles • Fairly and lawfully collected • Processed for specified and limited purposes • Adequate, relevant and not excessive • Accurate and kept up to date • Not kept for longer than necessary • Processed in accordance with Individuals’ rights • Security – appropriate technical and organisational measures • Not transferred outside the European Economic Area (EEA) unless adequate protections are in place • (EEA: The 28 member states of the EU, plus Iceland, Liechtenstein and Norway)
  • 11. Principle 1: Fairly and lawfully collected • Fair processing information provided • Organisation’s identity given • Purpose of collection made clear • Further information necessary • Correct permissions obtained - Implied consent: opt-out mechanism provided - Express consent: opt-in mechanism provided • Sensitive personal data only captured if strictly necessary
  • 12. Principle 2: Processed for limited purposes • Only process data for the purpose(s) you told the individual • Make the purpose(s) clear at the point of data collection • Change of circumstances – what happens to the data then? • Subsequent use of data for direct marketing purposes • Data cleansing – regular and ad hoc
  • 13. Principle 3: Adequate, relevant and not excessive • Minimum amount of information required • Additional information for specific individuals • Collect data that you will use now • Collection of data that ‘may be useful’ in the future is not permitted
  • 14. Principle 4: Accurate and kept up to date • Take reasonable steps to ensure accuracy (but what is ‘reasonable’?) • Ensure data is not incorrect or misleading • Undertake regular data cleansing • Clean data against the relevant preference service files and other appropriate cleansing files
  • 15. Principle 5: Not kept for longer than necessary • Keep for as long as purpose collected for • Suppression lists
  • 16. Principle 6: Processed in accordance with the right of data subjects • Subject access requests • ‘Where did you get my data from?’ • Right to prevent direct marketing • Customer service / legally required communications – no opt-out provision required • Right to have inaccurate data corrected
  • 17. Principle 7: Technological and organisational security • Data security must be appropriate – take account of: – Current state of technological development – Cost of implementing security measures – Potential harm that could result from a data breach – Nature of data to be protected – non/sensitive? • Need for risk assessment and risk management techniques • Record your findings and assessments
  • 18. Principle 7: Technological and organisational security (continued) • Ensure adequate organisational data security measures • Prevent unauthorised as well as unlawful processing or disclosure of data • Security measures by data controller and data processor • Data processing and transfer agreements in place • Staff training • Data access on a ‘need to know’ basis – individual log-ins only • Secure disposal of data – internally/externally - keep records
  • 19. Principle 8: Processed within the EEA unless adequate protection in place • Data can be freely transferred within the EEA (providing data transfer agreements are in place) • Do not transfer data unless the country (destination and countries data is routed via) have an adequate level of data protection • Need to inform individuals before transferring their data outside the EEA but do not need their consent
  • 20. Understanding the law 2 • Privacy and Electronic Communications Regulations 2003 (PECR) – Came into force 11 December 2003 – Covers electronic communications – email, telephone, SMS
  • 21. Key rules • Sender must not conceal their identity • Communication must have valid address where opt-outs can be sent • Opt-in required for individuals (B2C) • Soft opt-in/existing customer exemption – available: – When you are collecting the address/mobile number in the sale or negotiations for the sale of a product or service; – You only send communications about similar products and services; – You provided an opportunity at time of collection to opt-out.
  • 22. Key points • Existing customer exemption: Not an excuse for unsolicited contact where correct permissions were never obtained • B2B – Opt-out and marketing message needs to directly relate to the work they do. • Subject headers in emails must be clear and accurate • Free and simple-to-use opt-out method must always be provided • Action unsubscribe requests promptly – add to internal suppression file • Maintain different flags for different types of communication – helps to avoid general opt-outs for all channels
  • 23. Practical tips for marketers • Data capture forms • Marketing permissions • Sourcing data • Regaining lost permission
  • 24. Data capture forms • Key information to include; – Why the data is being requested – What the data will be used for – Provision of an opt-in/out for marketing – Marketing channels to be used – Link to privacy policy • Key information to include in privacy policy – How the data subject can opt-out of marketing – If the data will be processed outside the EEA – How long the data will be kept for – How to make a subject access request – How to make a complaint regarding use of data
  • 25. Marketing permissions Own marketing 3rd party marketing Own marketing 3rd party marketing Mail opt-out opt-out (MPS screening) opt-out opt-out Telephone opt-out opt-out (TPS screening) opt-out opt-out (TPS/ CTPS screening) Email opt-in/ soft opt- in opt-in opt-in (unless corporate subscriber exemption) opt-in (unless corporate subscriber exemption) SMS opt-in/ soft opt- in opt-in opt-in opt-in Fax opt-in opt-in opt-out opt-out (FPS screening) B2C B2B
  • 26. Sourcing data/ due diligence • Who compiled the list? When? Has it been amended or updated since? • When was consent obtained? • Who obtained consent and what was the context? • Was it opt-in or opt-out? • Was information provided clearly and intelligibly? How was it provided? • Did it list organisations by name, by description, or any third party?
  • 27. Regaining lost permissions • Why was permission lost: – Poor customer service? – Poor communications timing? – Inappropriate offers? – In-house technical issues – permissions not recorded on CRM system • Revalidation exercise – obtaining up-to-date data • Can very occasionally include request regarding marketing update in a service message providing it is a minor part of the message • If you have only lost permission for certain channels, contact via another channel to update permissions
  • 29. Contacts Janine Paterson, Solicitor & Legal Manager, DMA T - 020 7291 3347 janine.paterson@dma.org.uk Legal Advice Email Box legaladvice@dma.org.uk