SlideShare une entreprise Scribd logo
1  sur  75
Legal Update: Data
    Protection
Connect with the DMA…
• The #tag for this event is: #dmalegal

• LinkedIn: DMA: Direct Marketing Association (UK)
  Limited

• Twitter: @DMA_UK/ @DMANorth

• DMA Website: http://www.dma.org.uk

• Email: dma@dma.org.uk or events@dma.org.uk

• Phone: 020 7291 3300 or 0161 918 6780
Today’s agenda
•   09.00 – 09.30 Registration and Coffee
•   09.30 – 09.35 Welcome and Introduction
•   09.35 – 10.05 Data Protection Regulation
             – Richard Parkinson, Legal Director Pinsent Masons and
               Samantha Livesey, Partner, Pinsent Masons
•   10.05 – 10.35 Data Protection Regulation
             – Caroline Roberts, Director of Public Affairs, DMA and James
               Milligan, Solicitor, DMA
•   10.35 – 10.55 Refreshment Break
•   10.55 – 11.15 Cookies – New Privacy Regulations
             – James Milligan, Solicitor, DMA
•   11.15– 11.30 Hot Industry Issues
             – Caroline Roberts, Director of Public Affairs, DMA and James
               Milligan, Solicitor, DMA
•   11.30 – 12.00 Panel Debate and Close
The Proposed New EU Data
   Protection Regulation

Samantha Livesey and Richard Parkinson
Agenda
1.   Introduction
2.   Timescale
3.   Headline proposed changes
4.   Summary of main changes from current regime
5.   Some specifics + considerations for compliance
Retailers: gaining competitive
advantage from customer insights
From proposal to law: legislative process
to implementation
                                        Committee stage:
           Draft report published:      Jan to April 2013
           Nov 2012

                                                        Lead committee
                              Parliamentary
                                                        vote: April 2013
Hearings:                     amendments to text:
May to Nov 2012               Dec 2012
                                                                         Q1. 2014?




May 2012                      December 2012                 April 2013     2014
Regulation directly applies across EU
Headline proposed changes
•   Data processors directly covered
•   Expanded definitions: “personal data” and “data subject”
•   Explicit consent required
•   Right to be forgotten
•   Greater emphasis on accountability
•   Notification of data security breaches
•   More onerous sanctions for breach
Consent
Consent: Current Position            Consent: Proposed Position

- Freely given, specific, informed   -Freely given, specific, informed and explicit
indication of the data subject’s     indication of data subject’s wishes
wishes
                                     - Given either by a statement or a clear
- Explicit consent required for      affirmative action
sensitive personal data only
                                     - Data controller / data subject relationship to
                                     be taken into account

                                     - Burden of proof on controller to
                                     demonstrate consent
Greater accountability
• Public bodies / companies <250 staff
• Appointment of DP officer
   2 year appointment
   independent reporting to board
   inform
   train
• Maintenance of documentation
• Data protection impact reports
Data security breach notification
•   Mandatory notification
•   Within 24 hours of becoming aware of breach
•   Report to cover:
     nature of breach
     number of data subjects
     categories of data
     proposed mitigation
Data security breach roadmap

          INCIDENT:          NOTIFY:            ALERT:         INVESTIGATE
                                                               INVESTIGATE
         A data security   Notify Insurer      Involve your     : Find out what
                                                                  Find out what
         incident occurs   immediately       security breach      happened
                                                                  happened
                                             response team
NOTIFY
ICO
WITHIN
24
HOURS
         EVALUATE:          RESPOND:
                            RESPOND:          ASSESS:
                                              ASSESS:           CONTAIN:
                                                                CONTAIN:
         How successful    Complete your
                            Complete your     What are the
                                              What are the     Prevent/limit any
                                                               Prevent/limit any
             was the       security breach
                              Incident          potential
                                                potential      further data loss
                                                               further data loss
           response?       Response plan
                           response Plan     consequences?
                                             consequences?
Proposed enhanced sanctions
• Depend on:-
   Size of organisation involved
   Nature and gravity of breach
   Whether intentional or negligent
   Technical and organisational measures
   Previous breaches
   Co-operation with ICO
Proposed enhanced sanctions
•   Up to €250k or 0.5% annual worldwide turnover
    intentional or negligent failure to operate a proper subject
    access request
•   Up to €500k or 1% annual worldwide turnover intentional
    or negligent failure to respond to subject access requests
    in accordance with Regulation
•   Up to €1m or 2% of annual worldwide turnover for other
    compliance failures
Winners                                   Losers

Data Protection Officers                  Data processors

Data subjects?
Genuinely better protection for them?     Data subjects?


Multinational businesses seeking to       Consumers: Increased burden and
operate in a genuinely single             cost of compliance passed on
European market

The (few?) national supervisory           Other national supervisory authorities:
authorities likely to receive increased   increased duties; same resources
funding
Initiatives for information sharing on    The many industries that operate
cyber/data security incidents: both       using “indirectly identifiable data”
industry groups and government            (or in the “grey zone”)
Use your time wisely
Any Questions?
Contact details
    Samantha Livesey                     Richard Parkinson
        Partner                            Legal Director

         Pinsent Masons LLP                     Pinsent Masons LLP
           3 Hardman Street                      3 Hardman Street
         Manchester M3 3AU                     Manchester M3 3AU
          Tel: 0161 234 8327                    Tel: 0161 234 8434
 samantha.livesey@pinsentmasons.com   richard.parkinson@pinsentmasons.com
Combining the experience, resources and international reach
                                                of McGrigors and Pinsent Masons
  Pinsent Masons LLP is a limited liability partnership registered in England & Wales (registered number: OC333653) authorised and regulated by
the Solicitors Regulation Authority, and by the appropriate regulatory body in the other jurisdictions in which it operates. The word ‘partner’, used in
  relation to the LLP, refers to a member of the LLP or an employee or consultant of the LLP or any affiliated firm who is a lawyer with equivalent
standing and qualifications. A list of the members of the LLP, and of those non-members who are designated as partners, is displayed at the LLP’s
  registered office: 30 Crown Place, London EC2A 4ES, United Kingdom. We use ‘Pinsent Masons’ to refer to Pinsent Masons LLP and affiliated
   entities that practise under the name ‘Pinsent Masons’ or a name that incorporates those words. Reference to ‘Pinsent Masons’ is to Pinsent
                   Masons LLP and/or one or more of those affiliated entities as the context requires. © Pinsent Masons LLP 2012

                                      For a full list of our locations around the globe please visit our websites:




                                               www.pinsentmasons.com                 www.Out-Law.com
Draft EU Data Protection
             Regulation
      DMA View and Lobbying
              Activity



Caroline Roberts             James Milligan
Director of Public Affairs   DMA Solicitor
Draft Regulation
- DMA View

•   DMA welcomes the Commission’s aim to reduce red tape
    and simplify bureaucracy – but proposals do not achieve
    that: overly strict, bureaucratic and unworkable


•   Needs to be a fair balance between privacy and legitimate
    business interests

•   Current proposals will stifle innovation, add considerably to
    business costs and place unnecessary obstacle to e-
    commerce jobs growth

•   Will be particularly harmful to SMEs

•   Hard to say how Commission’s estimate of 2.3 billion euros
    saving to businesses was calculated
“The proposed EU Data Protection Regulation
could cost the UK £47 billion in lost sales
According to the businesses polled for the study,
the proposed EU legislation could cost UK each
an average of £76,000.
Crucially, if these results were representative of
the UK economy as a whole, this would translate
into a potential cost of £47 billion to UK
businesses, concentrated amongst mainly
SMEs.”
Key points in the draft Regulation
     Opt-in and opt–out - obtaining consent



•   General rule for direct marketing – “explicit consent by
    clear statement or affirmative action” .
•   Possible legitimate interests exemption ?
•   Legacy databases – what about data collected under
    current law?
•   At odds with existing rules on voice calls, email and
    SMS marketing
Key points in the draft Regulation
IP addresses and cookies



•   Definition of personal data extended so could cover some IP
    addresses and cookies
•   But IP addresses identify a device not an individual + some
    IPs are general
•   Huge implications for digital marketers
•   Web analytics & profiling made much more difficult, if not
    impossible
•   Interaction with new cookie rules
Key points in the draft Regulation
    The right to be forgotten




•   Right for individuals to request organisations to delete any
    information held on them
•   Drafted with social media in mind – but goes beyond this
•   Problem of information which has already been passed on to
    third parties
•   Possibility of misleading consumers by raising unrealistic
    expectations
•   Suppression files.
Key points in the draft Regulation
Subject Access Requests

•   Data subjects to be able to request full information on data
    held on them free of any charge
•   Currently can levy a £10 fee – doesn’t cover cost but deters
    time-wasters, frivolous or vexatious requests.
•   Costs organisations £50 million p.a. now to meet SARs
•   Proposal that can provide data in electronic form if data
    subject agrees to this
Key points in the draft Regulation
- Marketing to Children



•   General rule – parental consent required for under 18’s
•   Exception for online marketing to children above age of 13
•   No flexibility – a risk-based approach would be better.
Key Points in the draft Regulation –Delegated
Acts


•   A major concern is that much of the detail of the Regulation
    will be implemented through additional delegated legislation –
    some 45 Delegated Acts are mentioned.
•   Details of this secondary legislation will not be clear until
    Regulation passed
•   These areas of secondary legislation will include:
           • powers to specify further procedures
           • technical standards for Privacy by Design/Default
           • specification of lawful processing condition
           • additional responsibilities for national data protection
             authorities; etc.
•   European Commission will be taking significant powers to
    itself away from the national authorities - raises serious issues
    of subsidiarity and accountability
Current position - UK
• Government reshuffle
      • at MoJ Helen Grant replaces Lord McNally.
• MoJ Data Protection Advisory Panel
      • DMA invited to join
• Justice Select Committee enquiry
      • DMA submitted evidence
      • 3 oral hearings ICO, Minister, FSB, Privacy
        International, Microsoft, Which?
      • Focus on bureaucratic burdens, benefits of
        harmonisation, Right to be Forgotten
      • Report in October to EU Scrutiny Committee
• Allies
      • CBI; Federation of Small Business; Which? etc.
• DMA Research
      • Data Privacy: What the Consumer Really Thinks and
        on the economic value of the dm industry, Putting a
        Price on Direct Marketing
Current position – UK Data Group
•   DMA chairing industry group under Advertising Association
    umbrella - to co-ordinate lobbying efforts

•   + ISBA, IPA, MRS, IPM, Sky, ITV, Channel 4, Microsoft,
    Google, Facebook

•   Ministerial Round Table on 23rd October

•   Set of draft amendments to propose

•   Priorities agreed: definition of personal data; profiling; consent;
    impact on small businesses; compliance costs

•   Mapping exercise of key individuals to target – pooling of
    intelligence on lobbying outcomes
Current position – Brussels –
Council of Ministers
• Council of Ministers Working Group meeting
  monthly

• Initial reports indicate UK Government (and
  others) taking a helpful and business-friendly
  stance – many object to delegated acts; find it
  too prescriptive and blunt in outlook on risk
  and harm & would prefer a more principles-
  based approach.

• UK pushing for Directive, rather than
  Regulation – as is Germany
Current position – Brussels –
European Parliament
• Lead Committee = LIBE
     • Civil Liberties, Justice & Home Affairs
     • Rapporteur is German Green MEP
     • Aiming for Draft Report for discussion in
       December with vote in early 2013
• 4 other Committees will produce reports
     •   ITRE – industry & trade
     •   IMCO – Internal Market & Consumer Protection
     •   Juri – Legal
     •   Employment & Social Affairs
Current position – Brussels -
FEDMA
•   FEDMA co-ordinating central European effort, a link point for
    exchange of intelligence on lobbying outcomes in different
    Member States

•   Organising meetings in Brussels with key individuals in
    Council, Commission and Parliament, e.g. Cypriot Presidency;
    advisers to key MEPs; party group secretariats.

•   Produced a FEDMA position paper on priorities for industry +
    draft amendments to text

•   Lobbying directly where there is no national DMA

•   DMA participating in Europe-wide group, Data Industry
    Platform – for collective lobbying + current research project by
    KPMG on likely effect of Regulation on European industry
Next steps
•   Industry Round Table with MoJ and DCMS Ministers –
    23rd October

•   Contact key UK MEPs

•   Promote suggested amendments to Regulation – to UK
    MEPs and via FEDMA to others
•
•   Lobby UK political leaders to influence their MEPs in EU
    Parliament

•   Continue to engage with key Commission, Council and
    Parliament civil servants and advisers
Timing
• Council Working Party meets on 25/26
  September + 4 more meetings in 2012

• 6th December – Council Ministers meet

• LIBE lead EP Committee – meeting with
  national parliaments on 9/10 October; will
  produce working document in mid-October &
  draft report in late November
• Other 4 Committees in parallel

• ???????? 2014.
Coffee break…

The next session starts at 10.55am
Cookies – 6 months on


          James Milligan

          DMA Solicitor
Covering:


• 26th May?

• Current developments

• What does the law require?

• Practical Guidance
26th May



• Online world did not end
• ICO issued revised guidance
• Implied consent = shared
  understanding.
• www.silktide.com
Current Developments
ICO reporting tool
What does the law require?


• The EU's revised privacy and
  communications directive came into
  force on 26 May 2011
• EU laws have been in place since 2003
   clear information requirement.
• The changes in May dramatically
  tightened the rules: clear information
  and consent from users to store a
  cookie on their device.
The law doesn’t just cover cookies


• The law isn’t actually about cookies, but because it affects
  them so much people have started calling it the ‘Cookie
  Law’

• The law covers all technologies which store information in
  the “terminal equipment" of a user, and that includes so-
  called Flash cookies (Locally Stored Objects), HTML5
  Local Storage, web beacons or bugs…and more

• This applies to email and mobile marketing too!
In practice



Those setting cookies must:

•   tell people that the cookies are there,
•   explain what the cookies are doing, and
•   obtain their consent to store a cookie on
    their device.
Two exemptions from consent
requirement


•   1. “use of cookie is for the sole purpose of
    carrying out the transmission of a
    communication over an electronic
    communications network“

•   2. “cookies that are strictly necessary for the
        provision of a service”
    – e.g. internet banking, online shopping
       carts, website log-ins
What steps should you have been
taking?


Follow the ICO’s guidelines:

1.   Check what type of cookies and similar technologies
     you use and how you use them.

2.   Assess how intrusive your use of cookies is.

3.   Decide what solution to obtain consent will be best
     in your circumstances.
Check what type of cookies you use


•   This might have to be a comprehensive audit of your
    website or it could be as simple as checking what data
    files are placed on user terminals and why.
•   You should analyse which cookies are strictly necessary
    and might not need consent.
•   You might also use this as an opportunity to ‘clean up’
    your webpages and stop using any cookies that are
    unnecessary or which have been superseded as your
    site has evolved

•   And also check that you have identified ALL your
    websites.
Assess how intrusive your use of
cookies is



• ….It might be useful to think of this in terms of a
  sliding scale, with privacy neutral cookies at one
  end of the scale and more intrusive uses of the
  technology at the other.

• You can then focus your efforts on achieving
  compliance appropriately providing more
  information and offering more detailed choices at
  the intrusive end of the scale.
Decide how to obtain consent

•   Once you know what you do, how you do it and for what
    purpose, you need to think about the best method for
    gaining consent.

•   The more privacy intrusive your activity, the more you
    will need to do to get meaningful consent….

     –   Pop-up box
     –   Splash page
     –   Landing page
     –   Webpage header, banner or scrolling text
     –   Through T&Cs for registered website users

•   Cannot currently rely on users’ browser settings!
Thank you and Questions


DMA Cookie Watch
http://www.dma.org.uk/toolkit/cookie-watch

Tel: 020 7291 3347
Email:     james.milligan@dma.org.uk

DMA Legal Advice
Tel: 020 7291 3360
Email: legaladvice@dma.org.uk
Hot Industry Topics


Caroline Roberts             James Milligan
Director of Public Affairs   DMA Solicitor
Hot Industry Topics

•   Consumer Rights legislation
•   Marketing to children
•   Telemarketing
•   Financial services
•   Alcohol marketing
•   Postal Affairs
•   Environment
Consumer Law – all change
• UK consumer law is not fit for purpose.
• Outdated language and concepts not
  appropriate in age of digital downloads
  and international online retail.
• To help consolidate and simplify
  consumer law for the benefit of
  consumers and traders, the
  Government has launched three
  consultations.
1. Consumer Rights Bill
•    BIS consultation proposes a range of options to clarify the rights
     and remedies for goods and services, including digital content,
     including:

          • Replace the current system of implied terms with a clear set
            of statutory guarantees when purchasing goods
          • Set a clear time limit for a short term right to reject
          • Clarify the number of times a retailer can repair sub-
            standard goods before being obliged to replace them
          • Replace “reasonable care and skill” with statutory
            guarantees for service levels
          • Introduce statutory remedies for sub-standard services
          • Clarify the rights and remedies available when buying digital
            content.

•    If implemented, these changes will see a complete change to how
     consumer law protects people when buying goods and services, and
     will introduce concepts that will allow for developments in
     technology.

•    This consultation closes on 5 October
2. Unfair terms in consumer contracts: a
    new approach


•   Current law on unfair terms in consumer contracts
    contained in two pieces of legislation which have their
    own inconsistencies and overlapping provisions.
•   As part of consultation on package of measures to
    simplify and consolidate consumer law, the Law
    Commissions asked to review and update 2005 report
    in relation to its general consumer recommendations.
•   Also asked to look at one specific issue: Which terms in
    a contract should be excluded from any rules? (has
    arisen from 2009 litigation over bank charges)
•   Their advice to be published spring 2013.
•   Consultation looks at recommendations in 2005 report
    and updates some proposals in light of changes since.
•   The consultation closes on 25 October.
3. Implementation of the Consumer Rights
    Directive

•   Agreed by the European Commission in 2011 – into UK law
    by April 2014.
•   Focused on harmonising and simplifying rules in a few key
    areas of consumer law:
        • Information that must be given to a consumer before s/he
          buys goods or services on a trader’s premises
        • Information that must be given to a consumer before s/he
          buys goods or services away from a trader’s premises, for
          example a fair, or at a distance (eg online)
        • Cancellation rights and responsibilities when a consumer
          buys goods or services away from a trader’s business
          premises or at a distance
        • Delivery times for goods and where responsibility lies if
          there is a problem
        • Post-contract helplines – these now cannot be a premium
          rate but can only be a basic rate call
        • Additional payments – these are payments that are charged
          on top of the price of the goods or services. They now need
          to have active or express consent so pre-ticked boxes will
          no longer be allowed
        • Payment fees (eg credit card surcharges).
Consumer Rights Directive – UK implementation

•   Payment fees are also subject to a separate consultation,
    issued by the Department for Business Innovation and Skills
    on 3 September
•   Many of the provisions of the Consumer Rights Directive have
    to be implemented as agreed in Europe but the consultation
    looks at some areas where there is leeway in how the UK
    Government implements the provisions. These include
    applying the provisions to sectors exempted by the Directive,
    for example healthcare and social services, setting a minimum
    value for a transaction to be subject to the provisions and
    dealing with emergency repairs in the home.
•   Aims to put an end to certain bad business practices and help
    consumers make well informed decisions when buying
    products or services.
•   Also to boost business confidence, setting out clearer rules
    and responsibilities and cutting red tape by reducing
    compliance costs.
•   Consultation closes on 1 November.
Marketing to children
•   General political concern about over-commercialisation
•   Bailey Review on Commercialisation and Sexualisation of
    Childhood – “Letting Children Be Children” - report
    published 2011
•   Says role and practice of advertising in broadly good
    shape – praises industry initiatives, e.g. CHECK
•   5 key recommendations:
         • Sexual imagery on billboards, magazine covers.
         • No under-16 brand ambassadors & peer to peer
           techniques
         • Harmonisation of the age of a child at 16
         • Website for parents to complain
         • Improving industry and regulatory understanding of
           parental concerns
Marketing to children – industry response

•   Children’s Panel set up to monitor advertising to children and
    take forward issues of concern
•   Parent Port – gateway portal for parents for information,
    advice, complaints, etc.
•   Research - Credos, Advertising Association think tank
•   UK Brand Ambassador and Peer-to-Peer Marketing Pledge:
•   Agreed principle that
        “ Young people under the age of 16 should not be
        employed directly or indirectly paid or paid-in-kind to
        actively promote brands, products, goods, services,
        causes or ideas to their peers, associates or friends”
•   30+ national company signatories + 13 trade associations,
    including DMA
•   Industry awareness campaigns
Marketing to children- latest developments


  • Consultation on extending age rating system to
    music DVDs and Blu-rays
  • Govt encouraging industry to introduce clear
    warnings on explicit videos online
  • Govt finalising legislation to implement the new
    classification system for video games
  • Govt asking ASA to consider whether more
    should be done to spell out commercial intent of
    advergames to young people and parents
Telemarketing

    OFCOM issued consultation 4th April on Simplifying Non-
    geographic Numbers - detailed proposals on the unbundled
    tariff and Freephone

•   Non-geographic numbers include 03, 080, 0845,0870, 083/4,
    0871/2/3, 09 and 118 numbers.

•   Used to call businesses and Government agencies, to get
    information, make payments for services and vote on TV
    shows. Nearly every consumer and every company in the
    country uses these numbers in some way.

•   Confusion about the price – even freephone not clear cut

•   Concerns about revenue sharing.
Telemarketing

•   Main proposals:

     – Freephone: (080 and 116 numbers) to be free from all
       telephones, landline and mobile;

     – 03: to become the only non-geographic number range
       linked to the price of a call to a geographic number (i.e.
       the 01/02 number ranges);

     – Revenue sharing ranges: (084, 087, 09 and 118
       numbers -where a portion of the retail charge is passed
       back to the receiver of the call) are to have a common
       simplified structure.

•   Consultation closed 27th June 2012 – now awaiting
    Government’s response
Financial Services


•   EU Gender Directive
     – In force 21st December 2012
     – ECJ ruled 1st March 2011 that gender sensitive pricing
       is contrary to the principle of equal treatment in EU
       law
     – Therefore gender neutral pricing will become the norm
     - Unisex premiums would see the lower-risk gender
       paying more to subsidise the high-risk gender
Financial Services


• Re- architecture of financial services regulatory
  environment
• Replacement of FSA by Financial Conduct
  Authority and Prudential Regulatory Authority
• Banking Reform Bill – ring fencing of retail and
  investment arms within banks included in
  Queen’s Speech 2012.
Financial Services – consumer credit

•   Consumer Credit in limbo- move to FCA?

    – Investigations into payday loans and payment
      protection insurance have raised the issue of
      standards in the consumer credit market

    – BIS Committee of MPs has called for tighter controls
      on debt management companies and payday
      lenders
        • Charge higher licensing fees for higher risk
          credit businesses
        • Put in place a fast track procedure to suspend
          credit licences
        • Give the regulator the power to ban harmful
          products
Financial Services – consumer credit

• BIS Consultation on the Early
  Implementation of a Ban on Above Cost
  Payment Surcharges
• Credit/Debit Card charges
• Consultation closes 15 October 2012.
Alcohol
•   Government issued its Alcohol strategy on 23rd March

•   Focus on pricing issues

•   Minimum pricing in Scotland to be introduced –
    implications for rest of UK?

•   Positive comments on the work of self-regulation

•   Commons Health Select Committee holding an inquiry
    into the Governments’ proposals, looking at:

     – effects of marketing on alcohol consumption, in particular
       in relation to children and young people.
     – international evidence of the most effective interventions
       for reducing consumption of alcohol and evidence of any
       successful programmes to reduce harmful drinking, such
       as: education; reduction in strength; raising legal drinking
       age; and plain packaging and marketing bans.
Postal issues


• Reversions issue with Royal Mail
• DMA in discussions with RM to secure a more
  beneficial outcome – hosted summit in August
• Making progress

• VAT – single supply of services
Environment


•   The DMA and Defra signed a Responsibility Deal in 2011.

•   Part of this was the introduction of a new website where
    householders can opt-out of receiving all types of advertising
    mail.

•   Aim to reduce the amount of unwanted advertising mail put
    through the letterbox

•   Doorstop Preference Service is ready to launch – awaiting
    final Defra input and agreement with newspaper and
    directories industries.
Queen’s Speech 2012

•   DEFAMATION BILL – end to libel tourism and protection for
    website operators for user generated content on their site
    provided they comply with new dispute resolution procedures
    to allow complainant to deal directly with the author

•   ELECTORAL REGISTRATION AND ADMINISTRATION BILL
    – introduction of individual electoral registration and system
    opened up for digital application. - edited version of register
    will be kept but issue on opt-outs.

•   ENTERPRISE AND REGULATORY REFORM BILL – aims to
    cut red tape

•   PENSIONS BILL – creating a single tier pension and bringing
    forward increases to the state pension age

•   DRAFT COMMUNICATIONS DATA BILL – dubbed “The
    Snoopers’ Charter”
Any Questions?

james.milligan@dma.org.uk        caroline.roberts@dma.org.uk
020 7291 3347                    020 7291 3346



DMA members can contact DMA Legal Department for free advice:
  by email: legaladvice@dma.org.uk
  or call: 020 7291 3360
Thank you…

 Presentations will be emailed to you Monday
 A final thank you to all of today’s speakers:
         Richard Parkinson, Pinsent Masons
         Samantha Livesey, Pinsent Masons
              Caroline Roberts, DMA
               James Milligan, DMA
Please return your completed
evaluation forms and badges to the
registration desk we look forward to
          seeing you again!

Contenu connexe

Tendances

Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec
 
CyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRShadi A. Razak
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110guestd7fc9c
 
Contracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy BortzContracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy Bortzitnewsafrica
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Karina Matos
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRIryna Chekanava
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To ConsiderSymantec
 
Under Lock And Key
Under Lock And KeyUnder Lock And Key
Under Lock And KeyYarko Petriw
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...Symantec
 
Trust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory FrameworkTrust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory FrameworkFrancoise Gilbert
 
Convince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XConvince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XDave James
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
How to implement gdpr in your document repository
How to implement gdpr in your document repository How to implement gdpr in your document repository
How to implement gdpr in your document repository XeniT Solutions nv
 
Convince your board - Ten steps to GDPR compliance
Convince your board  - Ten steps to GDPR complianceConvince your board  - Ten steps to GDPR compliance
Convince your board - Ten steps to GDPR complianceDave James
 

Tendances (20)

Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
CyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPR
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
 
Contracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy BortzContracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy Bortz
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
Data protection
Data protectionData protection
Data protection
 
Under Lock And Key
Under Lock And KeyUnder Lock And Key
Under Lock And Key
 
BSI Data Protection Online
BSI Data Protection OnlineBSI Data Protection Online
BSI Data Protection Online
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
 
Trust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory FrameworkTrust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory Framework
 
CSA Concepts of Sovereignty & Cloud User Rights
CSA Concepts of Sovereignty & Cloud User RightsCSA Concepts of Sovereignty & Cloud User Rights
CSA Concepts of Sovereignty & Cloud User Rights
 
Convince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XConvince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List X
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
How to implement gdpr in your document repository
How to implement gdpr in your document repository How to implement gdpr in your document repository
How to implement gdpr in your document repository
 
Convince your board - Ten steps to GDPR compliance
Convince your board  - Ten steps to GDPR complianceConvince your board  - Ten steps to GDPR compliance
Convince your board - Ten steps to GDPR compliance
 
57th ICCA Congress | 12.11.2018 | Data Protection - 150 days after GDPR
57th ICCA Congress | 12.11.2018 | Data Protection - 150 days after GDPR57th ICCA Congress | 12.11.2018 | Data Protection - 150 days after GDPR
57th ICCA Congress | 12.11.2018 | Data Protection - 150 days after GDPR
 

En vedette

Design startup-asia-sharable
Design startup-asia-sharableDesign startup-asia-sharable
Design startup-asia-sharablemomobeijing
 
10 lbs apps from china worth attention
10 lbs apps   from china worth attention  10 lbs apps   from china worth attention
10 lbs apps from china worth attention momobeijing
 
Presentación impress 2.
Presentación impress 2.Presentación impress 2.
Presentación impress 2.imnhhhc Hujbvv
 
Data Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, MicrosoftData Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, MicrosoftRachel Aldighieri
 
Wodache mobile monday
Wodache mobile mondayWodache mobile monday
Wodache mobile mondaymomobeijing
 
16fun at MoMo Beijing #38
16fun at MoMo Beijing #3816fun at MoMo Beijing #38
16fun at MoMo Beijing #38momobeijing
 
Touch china en_mm
Touch china en_mmTouch china en_mm
Touch china en_mmmomobeijing
 
Lu Gang -Rethink sxsw-short
Lu Gang -Rethink sxsw-shortLu Gang -Rethink sxsw-short
Lu Gang -Rethink sxsw-shortmomobeijing
 
Planning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaignPlanning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaignRachel Aldighieri
 
An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014Rachel Aldighieri
 
Inserts nuts and bolts presentation 11 july
Inserts nuts and bolts presentation   11 julyInserts nuts and bolts presentation   11 july
Inserts nuts and bolts presentation 11 julyRachel Aldighieri
 
汇聚创新的力量 丘总
汇聚创新的力量 丘总汇聚创新的力量 丘总
汇聚创新的力量 丘总momobeijing
 
DMA North: Making mobile marketing work
DMA North: Making mobile marketing workDMA North: Making mobile marketing work
DMA North: Making mobile marketing workRachel Aldighieri
 
MoMo Beijing introduction to thai mobile environment - 14th may 2012
MoMo Beijing   introduction to thai mobile environment - 14th may 2012MoMo Beijing   introduction to thai mobile environment - 14th may 2012
MoMo Beijing introduction to thai mobile environment - 14th may 2012momobeijing
 

En vedette (20)

Design startup-asia-sharable
Design startup-asia-sharableDesign startup-asia-sharable
Design startup-asia-sharable
 
Twin IPM Approach
Twin IPM ApproachTwin IPM Approach
Twin IPM Approach
 
Almost Extinct
Almost ExtinctAlmost Extinct
Almost Extinct
 
10 lbs apps from china worth attention
10 lbs apps   from china worth attention  10 lbs apps   from china worth attention
10 lbs apps from china worth attention
 
Presentación impress 2.
Presentación impress 2.Presentación impress 2.
Presentación impress 2.
 
Data Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, MicrosoftData Protection 2013, Future Forward, Microsoft
Data Protection 2013, Future Forward, Microsoft
 
Wodache mobile monday
Wodache mobile mondayWodache mobile monday
Wodache mobile monday
 
16fun at MoMo Beijing #38
16fun at MoMo Beijing #3816fun at MoMo Beijing #38
16fun at MoMo Beijing #38
 
Touch china en_mm
Touch china en_mmTouch china en_mm
Touch china en_mm
 
Lu Gang -Rethink sxsw-short
Lu Gang -Rethink sxsw-shortLu Gang -Rethink sxsw-short
Lu Gang -Rethink sxsw-short
 
Planning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaignPlanning advertising mail into an integrated campaign
Planning advertising mail into an integrated campaign
 
Edu 290
Edu 290Edu 290
Edu 290
 
Momo jakob
Momo jakobMomo jakob
Momo jakob
 
Master ppt social
Master ppt socialMaster ppt social
Master ppt social
 
An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014
 
Inserts nuts and bolts presentation 11 july
Inserts nuts and bolts presentation   11 julyInserts nuts and bolts presentation   11 july
Inserts nuts and bolts presentation 11 july
 
汇聚创新的力量 丘总
汇聚创新的力量 丘总汇聚创新的力量 丘总
汇聚创新的力量 丘总
 
DMA North: Making mobile marketing work
DMA North: Making mobile marketing workDMA North: Making mobile marketing work
DMA North: Making mobile marketing work
 
Chris Martin
Chris MartinChris Martin
Chris Martin
 
MoMo Beijing introduction to thai mobile environment - 14th may 2012
MoMo Beijing   introduction to thai mobile environment - 14th may 2012MoMo Beijing   introduction to thai mobile environment - 14th may 2012
MoMo Beijing introduction to thai mobile environment - 14th may 2012
 

Similaire à Legal update 21 september 2012

The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...IT Governance Ltd
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 septRachel Aldighieri
 
Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...
Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...
Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...Iryna Chekanava
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due DiligenceResilient Systems
 
Cyber Recovery - Legal Toolkit
Cyber Recovery - Legal ToolkitCyber Recovery - Legal Toolkit
Cyber Recovery - Legal ToolkitKevin Duffey
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Brian Miller, Solicitor
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
In house lawyers' forum, September 2017
In house lawyers' forum, September 2017In house lawyers' forum, September 2017
In house lawyers' forum, September 2017Browne Jacobson LLP
 
Data protection within development
Data protection within developmentData protection within development
Data protection within developmentowaspsuffolk
 
David doughty presentation 181119
David doughty presentation 181119David doughty presentation 181119
David doughty presentation 181119David Doughty
 
In house lawyers, September 2018, Nottingham
In house lawyers, September 2018, NottinghamIn house lawyers, September 2018, Nottingham
In house lawyers, September 2018, NottinghamBrowne Jacobson LLP
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection RegulationImplementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection RegulationJim Kaplan CIA CFE
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPRTripwire
 

Similaire à Legal update 21 september 2012 (20)

The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 
Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...
Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...
Private Equity at the Eye of a Perfect Storm: Why Cyber Risk and Regulation M...
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
 
Cyber Recovery - Legal Toolkit
Cyber Recovery - Legal ToolkitCyber Recovery - Legal Toolkit
Cyber Recovery - Legal Toolkit
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
In house lawyers' forum, September 2017
In house lawyers' forum, September 2017In house lawyers' forum, September 2017
In house lawyers' forum, September 2017
 
2018-11-15 IT Assessment
2018-11-15 IT Assessment2018-11-15 IT Assessment
2018-11-15 IT Assessment
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
Data protection within development
Data protection within developmentData protection within development
Data protection within development
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
David doughty presentation 181119
David doughty presentation 181119David doughty presentation 181119
David doughty presentation 181119
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
In house lawyers, September 2018, Nottingham
In house lawyers, September 2018, NottinghamIn house lawyers, September 2018, Nottingham
In house lawyers, September 2018, Nottingham
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection RegulationImplementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPR
 

Plus de Rachel Aldighieri

Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Rachel Aldighieri
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowRachel Aldighieri
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skillsRachel Aldighieri
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Rachel Aldighieri
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015Rachel Aldighieri
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormRachel Aldighieri
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMARachel Aldighieri
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustRachel Aldighieri
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015Rachel Aldighieri
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterRachel Aldighieri
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Rachel Aldighieri
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Rachel Aldighieri
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15Rachel Aldighieri
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015Rachel Aldighieri
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Rachel Aldighieri
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterRachel Aldighieri
 

Plus de Rachel Aldighieri (20)

Navigating B2B marketing
Navigating B2B marketingNavigating B2B marketing
Navigating B2B marketing
 
Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to know
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skills
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order Form
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 August
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - Manchester
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015
 
Legal update - 1 July
Legal update - 1 JulyLegal update - 1 July
Legal update - 1 July
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - Manchester
 
Legal update
Legal updateLegal update
Legal update
 

Dernier

SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 

Dernier (20)

SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 

Legal update 21 september 2012

  • 1. Legal Update: Data Protection
  • 2. Connect with the DMA… • The #tag for this event is: #dmalegal • LinkedIn: DMA: Direct Marketing Association (UK) Limited • Twitter: @DMA_UK/ @DMANorth • DMA Website: http://www.dma.org.uk • Email: dma@dma.org.uk or events@dma.org.uk • Phone: 020 7291 3300 or 0161 918 6780
  • 3. Today’s agenda • 09.00 – 09.30 Registration and Coffee • 09.30 – 09.35 Welcome and Introduction • 09.35 – 10.05 Data Protection Regulation – Richard Parkinson, Legal Director Pinsent Masons and Samantha Livesey, Partner, Pinsent Masons • 10.05 – 10.35 Data Protection Regulation – Caroline Roberts, Director of Public Affairs, DMA and James Milligan, Solicitor, DMA • 10.35 – 10.55 Refreshment Break • 10.55 – 11.15 Cookies – New Privacy Regulations – James Milligan, Solicitor, DMA • 11.15– 11.30 Hot Industry Issues – Caroline Roberts, Director of Public Affairs, DMA and James Milligan, Solicitor, DMA • 11.30 – 12.00 Panel Debate and Close
  • 4. The Proposed New EU Data Protection Regulation Samantha Livesey and Richard Parkinson
  • 5. Agenda 1. Introduction 2. Timescale 3. Headline proposed changes 4. Summary of main changes from current regime 5. Some specifics + considerations for compliance
  • 6.
  • 8. From proposal to law: legislative process to implementation Committee stage: Draft report published: Jan to April 2013 Nov 2012 Lead committee Parliamentary vote: April 2013 Hearings: amendments to text: May to Nov 2012 Dec 2012 Q1. 2014? May 2012 December 2012 April 2013 2014
  • 10. Headline proposed changes • Data processors directly covered • Expanded definitions: “personal data” and “data subject” • Explicit consent required • Right to be forgotten • Greater emphasis on accountability • Notification of data security breaches • More onerous sanctions for breach
  • 11. Consent Consent: Current Position Consent: Proposed Position - Freely given, specific, informed -Freely given, specific, informed and explicit indication of the data subject’s indication of data subject’s wishes wishes - Given either by a statement or a clear - Explicit consent required for affirmative action sensitive personal data only - Data controller / data subject relationship to be taken into account - Burden of proof on controller to demonstrate consent
  • 12. Greater accountability • Public bodies / companies <250 staff • Appointment of DP officer  2 year appointment  independent reporting to board  inform  train • Maintenance of documentation • Data protection impact reports
  • 13. Data security breach notification • Mandatory notification • Within 24 hours of becoming aware of breach • Report to cover:  nature of breach  number of data subjects  categories of data  proposed mitigation
  • 14. Data security breach roadmap INCIDENT: NOTIFY: ALERT: INVESTIGATE INVESTIGATE A data security Notify Insurer Involve your : Find out what Find out what incident occurs immediately security breach happened happened response team NOTIFY ICO WITHIN 24 HOURS EVALUATE: RESPOND: RESPOND: ASSESS: ASSESS: CONTAIN: CONTAIN: How successful Complete your Complete your What are the What are the Prevent/limit any Prevent/limit any was the security breach Incident potential potential further data loss further data loss response? Response plan response Plan consequences? consequences?
  • 15. Proposed enhanced sanctions • Depend on:-  Size of organisation involved  Nature and gravity of breach  Whether intentional or negligent  Technical and organisational measures  Previous breaches  Co-operation with ICO
  • 16. Proposed enhanced sanctions • Up to €250k or 0.5% annual worldwide turnover intentional or negligent failure to operate a proper subject access request • Up to €500k or 1% annual worldwide turnover intentional or negligent failure to respond to subject access requests in accordance with Regulation • Up to €1m or 2% of annual worldwide turnover for other compliance failures
  • 17. Winners Losers Data Protection Officers Data processors Data subjects? Genuinely better protection for them? Data subjects? Multinational businesses seeking to Consumers: Increased burden and operate in a genuinely single cost of compliance passed on European market The (few?) national supervisory Other national supervisory authorities: authorities likely to receive increased increased duties; same resources funding Initiatives for information sharing on The many industries that operate cyber/data security incidents: both using “indirectly identifiable data” industry groups and government (or in the “grey zone”)
  • 18. Use your time wisely
  • 20. Contact details Samantha Livesey Richard Parkinson Partner Legal Director Pinsent Masons LLP Pinsent Masons LLP 3 Hardman Street 3 Hardman Street Manchester M3 3AU Manchester M3 3AU Tel: 0161 234 8327 Tel: 0161 234 8434 samantha.livesey@pinsentmasons.com richard.parkinson@pinsentmasons.com
  • 21. Combining the experience, resources and international reach of McGrigors and Pinsent Masons Pinsent Masons LLP is a limited liability partnership registered in England & Wales (registered number: OC333653) authorised and regulated by the Solicitors Regulation Authority, and by the appropriate regulatory body in the other jurisdictions in which it operates. The word ‘partner’, used in relation to the LLP, refers to a member of the LLP or an employee or consultant of the LLP or any affiliated firm who is a lawyer with equivalent standing and qualifications. A list of the members of the LLP, and of those non-members who are designated as partners, is displayed at the LLP’s registered office: 30 Crown Place, London EC2A 4ES, United Kingdom. We use ‘Pinsent Masons’ to refer to Pinsent Masons LLP and affiliated entities that practise under the name ‘Pinsent Masons’ or a name that incorporates those words. Reference to ‘Pinsent Masons’ is to Pinsent Masons LLP and/or one or more of those affiliated entities as the context requires. © Pinsent Masons LLP 2012 For a full list of our locations around the globe please visit our websites: www.pinsentmasons.com www.Out-Law.com
  • 22. Draft EU Data Protection Regulation DMA View and Lobbying Activity Caroline Roberts James Milligan Director of Public Affairs DMA Solicitor
  • 23. Draft Regulation - DMA View • DMA welcomes the Commission’s aim to reduce red tape and simplify bureaucracy – but proposals do not achieve that: overly strict, bureaucratic and unworkable • Needs to be a fair balance between privacy and legitimate business interests • Current proposals will stifle innovation, add considerably to business costs and place unnecessary obstacle to e- commerce jobs growth • Will be particularly harmful to SMEs • Hard to say how Commission’s estimate of 2.3 billion euros saving to businesses was calculated
  • 24. “The proposed EU Data Protection Regulation could cost the UK £47 billion in lost sales According to the businesses polled for the study, the proposed EU legislation could cost UK each an average of £76,000. Crucially, if these results were representative of the UK economy as a whole, this would translate into a potential cost of £47 billion to UK businesses, concentrated amongst mainly SMEs.”
  • 25. Key points in the draft Regulation Opt-in and opt–out - obtaining consent • General rule for direct marketing – “explicit consent by clear statement or affirmative action” . • Possible legitimate interests exemption ? • Legacy databases – what about data collected under current law? • At odds with existing rules on voice calls, email and SMS marketing
  • 26. Key points in the draft Regulation IP addresses and cookies • Definition of personal data extended so could cover some IP addresses and cookies • But IP addresses identify a device not an individual + some IPs are general • Huge implications for digital marketers • Web analytics & profiling made much more difficult, if not impossible • Interaction with new cookie rules
  • 27. Key points in the draft Regulation The right to be forgotten • Right for individuals to request organisations to delete any information held on them • Drafted with social media in mind – but goes beyond this • Problem of information which has already been passed on to third parties • Possibility of misleading consumers by raising unrealistic expectations • Suppression files.
  • 28. Key points in the draft Regulation Subject Access Requests • Data subjects to be able to request full information on data held on them free of any charge • Currently can levy a £10 fee – doesn’t cover cost but deters time-wasters, frivolous or vexatious requests. • Costs organisations £50 million p.a. now to meet SARs • Proposal that can provide data in electronic form if data subject agrees to this
  • 29. Key points in the draft Regulation - Marketing to Children • General rule – parental consent required for under 18’s • Exception for online marketing to children above age of 13 • No flexibility – a risk-based approach would be better.
  • 30. Key Points in the draft Regulation –Delegated Acts • A major concern is that much of the detail of the Regulation will be implemented through additional delegated legislation – some 45 Delegated Acts are mentioned. • Details of this secondary legislation will not be clear until Regulation passed • These areas of secondary legislation will include: • powers to specify further procedures • technical standards for Privacy by Design/Default • specification of lawful processing condition • additional responsibilities for national data protection authorities; etc. • European Commission will be taking significant powers to itself away from the national authorities - raises serious issues of subsidiarity and accountability
  • 31. Current position - UK • Government reshuffle • at MoJ Helen Grant replaces Lord McNally. • MoJ Data Protection Advisory Panel • DMA invited to join • Justice Select Committee enquiry • DMA submitted evidence • 3 oral hearings ICO, Minister, FSB, Privacy International, Microsoft, Which? • Focus on bureaucratic burdens, benefits of harmonisation, Right to be Forgotten • Report in October to EU Scrutiny Committee • Allies • CBI; Federation of Small Business; Which? etc. • DMA Research • Data Privacy: What the Consumer Really Thinks and on the economic value of the dm industry, Putting a Price on Direct Marketing
  • 32. Current position – UK Data Group • DMA chairing industry group under Advertising Association umbrella - to co-ordinate lobbying efforts • + ISBA, IPA, MRS, IPM, Sky, ITV, Channel 4, Microsoft, Google, Facebook • Ministerial Round Table on 23rd October • Set of draft amendments to propose • Priorities agreed: definition of personal data; profiling; consent; impact on small businesses; compliance costs • Mapping exercise of key individuals to target – pooling of intelligence on lobbying outcomes
  • 33. Current position – Brussels – Council of Ministers • Council of Ministers Working Group meeting monthly • Initial reports indicate UK Government (and others) taking a helpful and business-friendly stance – many object to delegated acts; find it too prescriptive and blunt in outlook on risk and harm & would prefer a more principles- based approach. • UK pushing for Directive, rather than Regulation – as is Germany
  • 34. Current position – Brussels – European Parliament • Lead Committee = LIBE • Civil Liberties, Justice & Home Affairs • Rapporteur is German Green MEP • Aiming for Draft Report for discussion in December with vote in early 2013 • 4 other Committees will produce reports • ITRE – industry & trade • IMCO – Internal Market & Consumer Protection • Juri – Legal • Employment & Social Affairs
  • 35. Current position – Brussels - FEDMA • FEDMA co-ordinating central European effort, a link point for exchange of intelligence on lobbying outcomes in different Member States • Organising meetings in Brussels with key individuals in Council, Commission and Parliament, e.g. Cypriot Presidency; advisers to key MEPs; party group secretariats. • Produced a FEDMA position paper on priorities for industry + draft amendments to text • Lobbying directly where there is no national DMA • DMA participating in Europe-wide group, Data Industry Platform – for collective lobbying + current research project by KPMG on likely effect of Regulation on European industry
  • 36. Next steps • Industry Round Table with MoJ and DCMS Ministers – 23rd October • Contact key UK MEPs • Promote suggested amendments to Regulation – to UK MEPs and via FEDMA to others • • Lobby UK political leaders to influence their MEPs in EU Parliament • Continue to engage with key Commission, Council and Parliament civil servants and advisers
  • 37. Timing • Council Working Party meets on 25/26 September + 4 more meetings in 2012 • 6th December – Council Ministers meet • LIBE lead EP Committee – meeting with national parliaments on 9/10 October; will produce working document in mid-October & draft report in late November • Other 4 Committees in parallel • ???????? 2014.
  • 38. Coffee break… The next session starts at 10.55am
  • 39. Cookies – 6 months on James Milligan DMA Solicitor
  • 40. Covering: • 26th May? • Current developments • What does the law require? • Practical Guidance
  • 41. 26th May • Online world did not end • ICO issued revised guidance • Implied consent = shared understanding. • www.silktide.com
  • 44. What does the law require? • The EU's revised privacy and communications directive came into force on 26 May 2011 • EU laws have been in place since 2003 clear information requirement. • The changes in May dramatically tightened the rules: clear information and consent from users to store a cookie on their device.
  • 45. The law doesn’t just cover cookies • The law isn’t actually about cookies, but because it affects them so much people have started calling it the ‘Cookie Law’ • The law covers all technologies which store information in the “terminal equipment" of a user, and that includes so- called Flash cookies (Locally Stored Objects), HTML5 Local Storage, web beacons or bugs…and more • This applies to email and mobile marketing too!
  • 46. In practice Those setting cookies must: • tell people that the cookies are there, • explain what the cookies are doing, and • obtain their consent to store a cookie on their device.
  • 47. Two exemptions from consent requirement • 1. “use of cookie is for the sole purpose of carrying out the transmission of a communication over an electronic communications network“ • 2. “cookies that are strictly necessary for the provision of a service” – e.g. internet banking, online shopping carts, website log-ins
  • 48. What steps should you have been taking? Follow the ICO’s guidelines: 1. Check what type of cookies and similar technologies you use and how you use them. 2. Assess how intrusive your use of cookies is. 3. Decide what solution to obtain consent will be best in your circumstances.
  • 49. Check what type of cookies you use • This might have to be a comprehensive audit of your website or it could be as simple as checking what data files are placed on user terminals and why. • You should analyse which cookies are strictly necessary and might not need consent. • You might also use this as an opportunity to ‘clean up’ your webpages and stop using any cookies that are unnecessary or which have been superseded as your site has evolved • And also check that you have identified ALL your websites.
  • 50. Assess how intrusive your use of cookies is • ….It might be useful to think of this in terms of a sliding scale, with privacy neutral cookies at one end of the scale and more intrusive uses of the technology at the other. • You can then focus your efforts on achieving compliance appropriately providing more information and offering more detailed choices at the intrusive end of the scale.
  • 51. Decide how to obtain consent • Once you know what you do, how you do it and for what purpose, you need to think about the best method for gaining consent. • The more privacy intrusive your activity, the more you will need to do to get meaningful consent…. – Pop-up box – Splash page – Landing page – Webpage header, banner or scrolling text – Through T&Cs for registered website users • Cannot currently rely on users’ browser settings!
  • 52. Thank you and Questions DMA Cookie Watch http://www.dma.org.uk/toolkit/cookie-watch Tel: 020 7291 3347 Email: james.milligan@dma.org.uk DMA Legal Advice Tel: 020 7291 3360 Email: legaladvice@dma.org.uk
  • 53. Hot Industry Topics Caroline Roberts James Milligan Director of Public Affairs DMA Solicitor
  • 54. Hot Industry Topics • Consumer Rights legislation • Marketing to children • Telemarketing • Financial services • Alcohol marketing • Postal Affairs • Environment
  • 55. Consumer Law – all change • UK consumer law is not fit for purpose. • Outdated language and concepts not appropriate in age of digital downloads and international online retail. • To help consolidate and simplify consumer law for the benefit of consumers and traders, the Government has launched three consultations.
  • 56. 1. Consumer Rights Bill • BIS consultation proposes a range of options to clarify the rights and remedies for goods and services, including digital content, including: • Replace the current system of implied terms with a clear set of statutory guarantees when purchasing goods • Set a clear time limit for a short term right to reject • Clarify the number of times a retailer can repair sub- standard goods before being obliged to replace them • Replace “reasonable care and skill” with statutory guarantees for service levels • Introduce statutory remedies for sub-standard services • Clarify the rights and remedies available when buying digital content. • If implemented, these changes will see a complete change to how consumer law protects people when buying goods and services, and will introduce concepts that will allow for developments in technology. • This consultation closes on 5 October
  • 57. 2. Unfair terms in consumer contracts: a new approach • Current law on unfair terms in consumer contracts contained in two pieces of legislation which have their own inconsistencies and overlapping provisions. • As part of consultation on package of measures to simplify and consolidate consumer law, the Law Commissions asked to review and update 2005 report in relation to its general consumer recommendations. • Also asked to look at one specific issue: Which terms in a contract should be excluded from any rules? (has arisen from 2009 litigation over bank charges) • Their advice to be published spring 2013. • Consultation looks at recommendations in 2005 report and updates some proposals in light of changes since. • The consultation closes on 25 October.
  • 58. 3. Implementation of the Consumer Rights Directive • Agreed by the European Commission in 2011 – into UK law by April 2014. • Focused on harmonising and simplifying rules in a few key areas of consumer law: • Information that must be given to a consumer before s/he buys goods or services on a trader’s premises • Information that must be given to a consumer before s/he buys goods or services away from a trader’s premises, for example a fair, or at a distance (eg online) • Cancellation rights and responsibilities when a consumer buys goods or services away from a trader’s business premises or at a distance • Delivery times for goods and where responsibility lies if there is a problem • Post-contract helplines – these now cannot be a premium rate but can only be a basic rate call • Additional payments – these are payments that are charged on top of the price of the goods or services. They now need to have active or express consent so pre-ticked boxes will no longer be allowed • Payment fees (eg credit card surcharges).
  • 59. Consumer Rights Directive – UK implementation • Payment fees are also subject to a separate consultation, issued by the Department for Business Innovation and Skills on 3 September • Many of the provisions of the Consumer Rights Directive have to be implemented as agreed in Europe but the consultation looks at some areas where there is leeway in how the UK Government implements the provisions. These include applying the provisions to sectors exempted by the Directive, for example healthcare and social services, setting a minimum value for a transaction to be subject to the provisions and dealing with emergency repairs in the home. • Aims to put an end to certain bad business practices and help consumers make well informed decisions when buying products or services. • Also to boost business confidence, setting out clearer rules and responsibilities and cutting red tape by reducing compliance costs. • Consultation closes on 1 November.
  • 60. Marketing to children • General political concern about over-commercialisation • Bailey Review on Commercialisation and Sexualisation of Childhood – “Letting Children Be Children” - report published 2011 • Says role and practice of advertising in broadly good shape – praises industry initiatives, e.g. CHECK • 5 key recommendations: • Sexual imagery on billboards, magazine covers. • No under-16 brand ambassadors & peer to peer techniques • Harmonisation of the age of a child at 16 • Website for parents to complain • Improving industry and regulatory understanding of parental concerns
  • 61. Marketing to children – industry response • Children’s Panel set up to monitor advertising to children and take forward issues of concern • Parent Port – gateway portal for parents for information, advice, complaints, etc. • Research - Credos, Advertising Association think tank • UK Brand Ambassador and Peer-to-Peer Marketing Pledge: • Agreed principle that “ Young people under the age of 16 should not be employed directly or indirectly paid or paid-in-kind to actively promote brands, products, goods, services, causes or ideas to their peers, associates or friends” • 30+ national company signatories + 13 trade associations, including DMA • Industry awareness campaigns
  • 62. Marketing to children- latest developments • Consultation on extending age rating system to music DVDs and Blu-rays • Govt encouraging industry to introduce clear warnings on explicit videos online • Govt finalising legislation to implement the new classification system for video games • Govt asking ASA to consider whether more should be done to spell out commercial intent of advergames to young people and parents
  • 63. Telemarketing OFCOM issued consultation 4th April on Simplifying Non- geographic Numbers - detailed proposals on the unbundled tariff and Freephone • Non-geographic numbers include 03, 080, 0845,0870, 083/4, 0871/2/3, 09 and 118 numbers. • Used to call businesses and Government agencies, to get information, make payments for services and vote on TV shows. Nearly every consumer and every company in the country uses these numbers in some way. • Confusion about the price – even freephone not clear cut • Concerns about revenue sharing.
  • 64. Telemarketing • Main proposals: – Freephone: (080 and 116 numbers) to be free from all telephones, landline and mobile; – 03: to become the only non-geographic number range linked to the price of a call to a geographic number (i.e. the 01/02 number ranges); – Revenue sharing ranges: (084, 087, 09 and 118 numbers -where a portion of the retail charge is passed back to the receiver of the call) are to have a common simplified structure. • Consultation closed 27th June 2012 – now awaiting Government’s response
  • 65. Financial Services • EU Gender Directive – In force 21st December 2012 – ECJ ruled 1st March 2011 that gender sensitive pricing is contrary to the principle of equal treatment in EU law – Therefore gender neutral pricing will become the norm - Unisex premiums would see the lower-risk gender paying more to subsidise the high-risk gender
  • 66. Financial Services • Re- architecture of financial services regulatory environment • Replacement of FSA by Financial Conduct Authority and Prudential Regulatory Authority • Banking Reform Bill – ring fencing of retail and investment arms within banks included in Queen’s Speech 2012.
  • 67. Financial Services – consumer credit • Consumer Credit in limbo- move to FCA? – Investigations into payday loans and payment protection insurance have raised the issue of standards in the consumer credit market – BIS Committee of MPs has called for tighter controls on debt management companies and payday lenders • Charge higher licensing fees for higher risk credit businesses • Put in place a fast track procedure to suspend credit licences • Give the regulator the power to ban harmful products
  • 68. Financial Services – consumer credit • BIS Consultation on the Early Implementation of a Ban on Above Cost Payment Surcharges • Credit/Debit Card charges • Consultation closes 15 October 2012.
  • 69. Alcohol • Government issued its Alcohol strategy on 23rd March • Focus on pricing issues • Minimum pricing in Scotland to be introduced – implications for rest of UK? • Positive comments on the work of self-regulation • Commons Health Select Committee holding an inquiry into the Governments’ proposals, looking at: – effects of marketing on alcohol consumption, in particular in relation to children and young people. – international evidence of the most effective interventions for reducing consumption of alcohol and evidence of any successful programmes to reduce harmful drinking, such as: education; reduction in strength; raising legal drinking age; and plain packaging and marketing bans.
  • 70. Postal issues • Reversions issue with Royal Mail • DMA in discussions with RM to secure a more beneficial outcome – hosted summit in August • Making progress • VAT – single supply of services
  • 71. Environment • The DMA and Defra signed a Responsibility Deal in 2011. • Part of this was the introduction of a new website where householders can opt-out of receiving all types of advertising mail. • Aim to reduce the amount of unwanted advertising mail put through the letterbox • Doorstop Preference Service is ready to launch – awaiting final Defra input and agreement with newspaper and directories industries.
  • 72. Queen’s Speech 2012 • DEFAMATION BILL – end to libel tourism and protection for website operators for user generated content on their site provided they comply with new dispute resolution procedures to allow complainant to deal directly with the author • ELECTORAL REGISTRATION AND ADMINISTRATION BILL – introduction of individual electoral registration and system opened up for digital application. - edited version of register will be kept but issue on opt-outs. • ENTERPRISE AND REGULATORY REFORM BILL – aims to cut red tape • PENSIONS BILL – creating a single tier pension and bringing forward increases to the state pension age • DRAFT COMMUNICATIONS DATA BILL – dubbed “The Snoopers’ Charter”
  • 73. Any Questions? james.milligan@dma.org.uk caroline.roberts@dma.org.uk 020 7291 3347 020 7291 3346 DMA members can contact DMA Legal Department for free advice: by email: legaladvice@dma.org.uk or call: 020 7291 3360
  • 74. Thank you… Presentations will be emailed to you Monday A final thank you to all of today’s speakers: Richard Parkinson, Pinsent Masons Samantha Livesey, Pinsent Masons Caroline Roberts, DMA James Milligan, DMA
  • 75. Please return your completed evaluation forms and badges to the registration desk we look forward to seeing you again!