SlideShare une entreprise Scribd logo
1  sur  25
Data Protection - All Change
or More of the Same?
Paul Ticher
This presentation is intended to help you
understand aspects of the Data Protection Act
1998 and related legislation.
It is not intended to provide detailed advice on
specific points, and is not necessarily a full
statement of the law.

Data Protection - All Change or More of the Same?
What Data Protection is about: 1



Protecting data

Protecting people
Prevent harm to the individuals whose data we
hold, or other people
• Keep information in the right hands
• Hold good quality data

Data Protection - All Change or More of the Same?


What Data Protection is about: 2
Give us
more
money!

Support our
campaign!

We sold your
details to
someone else

Reassure people that we use their information
responsibly, so that they trust us
• Be transparent – open and honest, don‟t hide
things or go behind people‟s back
• Offer people a reasonable choice over how you
use their data, and what for
Data Protection - All Change or More of the Same?
What Data Protection is about: 3

Comply with specific legal requirements, such as:

Right to opt out of direct marketing



Right of Subject Access
Notification
(And others)

Data Protection - All Change or More of the Same?
The main topics for today
Top priorities
• Security
And while we‟re about it
• Transparency
• Latest developments on
• Choice
• Enforcement
• Accuracy & data quality
• Guidance
• New EU Regulation
But first:
• The Data Protection Principles
• The definition of Personal data
• Confidentiality

Data Protection - All Change or More of the Same?
The Data Protection Principles

1. Data „processing‟ must be „fair‟ and legal
2. You must limit your use of data to the purpose(s)
you obtained it for
3. Data must be adequate, relevant & not excessive
4. Data must be accurate & up to date
5. Data must not be held longer than necessary
6. Data Subjects‟ rights must be respected
7. You must have appropriate security
8. Special rules apply to transfers abroad

Data Protection - All Change or More of the Same?
Personal data

The Act applies to information that is „personal‟ and
„data‟
The personal part means that it is about:
identifiable, living individuals
The data part means that it is recorded:
• on a computer or automated system
• in a „relevant filing system‟
• with the intention of going into one of these
systems
• (others apply to public bodies)

Data Protection - All Change or More of the Same?
How DP and Confidentiality overlap

Data Protection

Confidentiality

Clear boundaries

Data Protection - All Change or More of the Same?
Taking confidentiality seriously

Gossip

Scams
Circumventing
security

Data Protection - All Change or More of the Same?
Security (Principle 7)

The Data Protection Act says you must prevent:
• unauthorised access to personal data
• accidental loss or damage of personal data
The security measures must be appropriate.
They must also be technical and organisational.

The Information Commissioner can
impose a penalty of up to £???????
for gross breaches of security (or
other Data Protection requirements)

Data Protection - All Change or More of the Same?
Key security measures

Protect „data in transit‟
• passwords, encryption on USB devices, tablets
and laptops
• extreme care when faxing, e-mailing & posting
• think about encryption on e-mails if appropriate
Network security – anti-virus, firewall, log-ons, etc.
Website security – „OWASP top ten‟ or similar
Bring Your Own Device policy
External contractors („Data Processors‟)
Secure destruction – shredding, etc.
Access controls, clear desks, locked filing cabinets
Staff DBS checks, supervision and monitoring

Data Protection - All Change or More of the Same?
‘Fair’ processing (Pr. 1): Transparency

One part of being fair to people is to make sure they
have no unpleasant surprises when you use data
about them.
This means you must always think whether you
need to tell them anything about:
• who is collecting their information
• what purposes you hold their data for
• who you might pass the data on to
• how to contact you if they want to stop you from
using their data or check what you are doing

Data Protection - All Change or More of the Same?
‘Fair’ processing (Pr. 1): Choice

The other important part of being fair is to give
people a reasonable choice over how their
information is used.
People must be given a choice over Direct
marketing
Choices can be:
• Opt out (we‟ll do it unless you say „no‟)
• Opt in (we‟ll only do it if you say „yes‟)
Be clear about what choices are offered, record
them carefully, and ensure that they are acted on.
Pre-ticked boxes are not good practice

Data Protection - All Change or More of the Same?
Conditions for fair processing

You must meet at least one of these:
• With consent of the Data Subject
(“specific, informed and freely given”)
• For a contract involving the Data Subject
• To meet a legal obligation
• To protect the Subject‟s „vital interests‟
• Government & judicial functions
• In your „legitimate interests‟ (or those you
disclose to) provided you don‟t infringe the Data
Subject‟s rights, freedoms or legitimate interests

Data Protection - All Change or More of the Same?
Data quality (Principles 3 & 4)

The Data Protection Act says that data must be:
• Adequate
• Relevant
• Not excessive
• Accurate
• Up to date (where necessary)

Data Protection - All Change or More of the Same?
Data Controller
The „person‟ legally responsible for complying with
the Data Protection Act


Staff & volunteers are part of the Data Controller
A trading company is a separate Data Controller
Organisations can be joint Data Controllers

Data Protection - All Change or More of the Same?


Data Processor
An organisation that has access to Personal Data
on your behalf for your purposes
The Data Controller remains responsible for what
happens to the data
There must be a written contract with the Data
Processor, setting out the relationship and, in
particular, their security responsibilities
Data Processors could include:
• Payroll service
• Cloud computing provider
• Tele-marketing company
• Client database maintenance & development
• Mailing house
• Contractor, delivering services
Data Protection - All Change or More of the Same?
Developments in enforcement

Recent penalties include:
• Fines for spam messaging
• Fine for breach caused by employee working
from home
• Fines for charities
Other options: enforcement notices, legally binding
undertakings
There have been a few successful challenges on
technicalities
Information Commissioner is consulting on a more
targeted approach to handling complaints

Data Protection - All Change or More of the Same?
Developments in ICO guidance

Recent publications include:
• a Code of Practice on handling Subject Access
• guidance on Bring Your Own Device policies
• a complete update of their guidance on Direct
Marketing
• guidance on Social Networking
• consultation on a review of the Privacy Notices
Code of Practice

Data Protection - All Change or More of the Same?
New EU Regulation: Rationale

1995: Directive 95/46/EC
1998: UK Data Protection Act (in force from 2000)
2003 (and earlier): Privacy & Electronic
Communications Regulations
Subsequently:
• World Wide Web
• Cloud computing
• Social media
• Profiling
• Cookies, GPS tracking ...
• Privacy awareness

Data Protection - All Change or More of the Same?
New EU Regulation: Timetable

January 2012: first draft published by Commission
2012: various EU bodies contribute views
2013: attempts to reconcile differing views, with
several conflicting drafts produced
October 2013: compromise draft agreed by
parliament
2015? Negotiations with Council
Mid-2015? Ratification of final Regulation

Data Protection - All Change or More of the Same?
New EU Regulation: Some key issues

Consent tightened up – no more pre-ticked boxes
Marketing is a „legitimate interest‟
Limited right of erasure
Right to object to profiling
More detailed privacy notices
Mandatory breach notification
Data Protection by default and by design
Mandatory Data Protection Officer
Privacy impact assessments replace Notification
Much-increased penalties (especially for multinational companies)

Data Protection - All Change or More of the Same?
Data Protection: the absolute basics

We are trying to:
• Prevent harm by
• Keeping data only in the right hands (and
being clear what „the right hands‟ are)
• Holding good quality data (accurate, up to
date and adequate)
• Reassure people so that they trust us
• Making sure people know enough about
what we are doing
• Giving people a choice where possible

Data Protection - All Change or More of the Same?
Thank you for listening

To go into more detail, join one of my webinars:
www.paulticher.com/webinars

Or contact me at:
0116 273 8191
paul@paulticher.com

Your Logo

www.paulticher.com

2 Old College Court, 29 Priory Street, Ware, Hertfordshire, SG12 0DE

Contenu connexe

Tendances

Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Harrison Leavey
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashedChris Gilmour
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudGurbir Singh
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for developmentTomppa Järvinen
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 

Tendances (20)

Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)Remember Data Protection Act (DPA)
Remember Data Protection Act (DPA)
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 

En vedette

Keep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection RegulationKeep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection RegulationDavid Reed
 
What's new in Vectorworks 2016
What's new in Vectorworks 2016What's new in Vectorworks 2016
What's new in Vectorworks 2016elinapaul
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Per Norhammar
 
Data Protector 9.07 what is new
Data Protector 9.07 what is new Data Protector 9.07 what is new
Data Protector 9.07 what is new Andrey Karpov
 
Data Protection overview presentation
Data Protection overview presentationData Protection overview presentation
Data Protection overview presentationAndrey Karpov
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
Annual employment law update, January 2017, Exeter
Annual employment law update, January 2017, ExeterAnnual employment law update, January 2017, Exeter
Annual employment law update, January 2017, ExeterBrowne Jacobson LLP
 
What is new in vectorworks 2017
What is new in vectorworks 2017What is new in vectorworks 2017
What is new in vectorworks 2017elinapaul
 
Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017Matheson Law Firm
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...Exove
 
DMI 2017 Mobile Trends
DMI 2017 Mobile TrendsDMI 2017 Mobile Trends
DMI 2017 Mobile TrendsDMI
 

En vedette (12)

Keep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection RegulationKeep Calm and Carry On - Marketing and the New Data Protection Regulation
Keep Calm and Carry On - Marketing and the New Data Protection Regulation
 
What's new in Vectorworks 2016
What's new in Vectorworks 2016What's new in Vectorworks 2016
What's new in Vectorworks 2016
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?
 
Data Protector 9.07 what is new
Data Protector 9.07 what is new Data Protector 9.07 what is new
Data Protector 9.07 what is new
 
Data Protection overview presentation
Data Protection overview presentationData Protection overview presentation
Data Protection overview presentation
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Annual employment law update, January 2017, Exeter
Annual employment law update, January 2017, ExeterAnnual employment law update, January 2017, Exeter
Annual employment law update, January 2017, Exeter
 
What is new in vectorworks 2017
What is new in vectorworks 2017What is new in vectorworks 2017
What is new in vectorworks 2017
 
Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017Getting the Deal Through: Data Protection & Privacy 2017
Getting the Deal Through: Data Protection & Privacy 2017
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
DMI 2017 Mobile Trends
DMI 2017 Mobile TrendsDMI 2017 Mobile Trends
DMI 2017 Mobile Trends
 
Design Your Career 2018
Design Your Career 2018Design Your Career 2018
Design Your Career 2018
 

Similaire à DP Act Changes and EU Regulation

Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11mrmwood
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 septRachel Aldighieri
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPRNate Stockard
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? Desynit
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteClive Rich
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Rachel Aldighieri
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015Rachel Aldighieri
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUser Vision
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesStephen Denning
 

Similaire à DP Act Changes and EU Regulation (20)

Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me?
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 

Dernier

Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 

Dernier (20)

Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 

DP Act Changes and EU Regulation

  • 1. Data Protection - All Change or More of the Same? Paul Ticher
  • 2. This presentation is intended to help you understand aspects of the Data Protection Act 1998 and related legislation. It is not intended to provide detailed advice on specific points, and is not necessarily a full statement of the law. Data Protection - All Change or More of the Same?
  • 3. What Data Protection is about: 1  Protecting data Protecting people Prevent harm to the individuals whose data we hold, or other people • Keep information in the right hands • Hold good quality data Data Protection - All Change or More of the Same? 
  • 4. What Data Protection is about: 2 Give us more money! Support our campaign! We sold your details to someone else Reassure people that we use their information responsibly, so that they trust us • Be transparent – open and honest, don‟t hide things or go behind people‟s back • Offer people a reasonable choice over how you use their data, and what for Data Protection - All Change or More of the Same?
  • 5. What Data Protection is about: 3 Comply with specific legal requirements, such as: Right to opt out of direct marketing  Right of Subject Access Notification (And others) Data Protection - All Change or More of the Same?
  • 6. The main topics for today Top priorities • Security And while we‟re about it • Transparency • Latest developments on • Choice • Enforcement • Accuracy & data quality • Guidance • New EU Regulation But first: • The Data Protection Principles • The definition of Personal data • Confidentiality Data Protection - All Change or More of the Same?
  • 7. The Data Protection Principles 1. Data „processing‟ must be „fair‟ and legal 2. You must limit your use of data to the purpose(s) you obtained it for 3. Data must be adequate, relevant & not excessive 4. Data must be accurate & up to date 5. Data must not be held longer than necessary 6. Data Subjects‟ rights must be respected 7. You must have appropriate security 8. Special rules apply to transfers abroad Data Protection - All Change or More of the Same?
  • 8. Personal data The Act applies to information that is „personal‟ and „data‟ The personal part means that it is about: identifiable, living individuals The data part means that it is recorded: • on a computer or automated system • in a „relevant filing system‟ • with the intention of going into one of these systems • (others apply to public bodies) Data Protection - All Change or More of the Same?
  • 9. How DP and Confidentiality overlap Data Protection Confidentiality Clear boundaries Data Protection - All Change or More of the Same?
  • 11. Security (Principle 7) The Data Protection Act says you must prevent: • unauthorised access to personal data • accidental loss or damage of personal data The security measures must be appropriate. They must also be technical and organisational. The Information Commissioner can impose a penalty of up to £??????? for gross breaches of security (or other Data Protection requirements) Data Protection - All Change or More of the Same?
  • 12. Key security measures Protect „data in transit‟ • passwords, encryption on USB devices, tablets and laptops • extreme care when faxing, e-mailing & posting • think about encryption on e-mails if appropriate Network security – anti-virus, firewall, log-ons, etc. Website security – „OWASP top ten‟ or similar Bring Your Own Device policy External contractors („Data Processors‟) Secure destruction – shredding, etc. Access controls, clear desks, locked filing cabinets Staff DBS checks, supervision and monitoring Data Protection - All Change or More of the Same?
  • 13. ‘Fair’ processing (Pr. 1): Transparency One part of being fair to people is to make sure they have no unpleasant surprises when you use data about them. This means you must always think whether you need to tell them anything about: • who is collecting their information • what purposes you hold their data for • who you might pass the data on to • how to contact you if they want to stop you from using their data or check what you are doing Data Protection - All Change or More of the Same?
  • 14. ‘Fair’ processing (Pr. 1): Choice The other important part of being fair is to give people a reasonable choice over how their information is used. People must be given a choice over Direct marketing Choices can be: • Opt out (we‟ll do it unless you say „no‟) • Opt in (we‟ll only do it if you say „yes‟) Be clear about what choices are offered, record them carefully, and ensure that they are acted on. Pre-ticked boxes are not good practice Data Protection - All Change or More of the Same?
  • 15. Conditions for fair processing You must meet at least one of these: • With consent of the Data Subject (“specific, informed and freely given”) • For a contract involving the Data Subject • To meet a legal obligation • To protect the Subject‟s „vital interests‟ • Government & judicial functions • In your „legitimate interests‟ (or those you disclose to) provided you don‟t infringe the Data Subject‟s rights, freedoms or legitimate interests Data Protection - All Change or More of the Same?
  • 16. Data quality (Principles 3 & 4) The Data Protection Act says that data must be: • Adequate • Relevant • Not excessive • Accurate • Up to date (where necessary) Data Protection - All Change or More of the Same?
  • 17. Data Controller The „person‟ legally responsible for complying with the Data Protection Act  Staff & volunteers are part of the Data Controller A trading company is a separate Data Controller Organisations can be joint Data Controllers Data Protection - All Change or More of the Same? 
  • 18. Data Processor An organisation that has access to Personal Data on your behalf for your purposes The Data Controller remains responsible for what happens to the data There must be a written contract with the Data Processor, setting out the relationship and, in particular, their security responsibilities Data Processors could include: • Payroll service • Cloud computing provider • Tele-marketing company • Client database maintenance & development • Mailing house • Contractor, delivering services Data Protection - All Change or More of the Same?
  • 19. Developments in enforcement Recent penalties include: • Fines for spam messaging • Fine for breach caused by employee working from home • Fines for charities Other options: enforcement notices, legally binding undertakings There have been a few successful challenges on technicalities Information Commissioner is consulting on a more targeted approach to handling complaints Data Protection - All Change or More of the Same?
  • 20. Developments in ICO guidance Recent publications include: • a Code of Practice on handling Subject Access • guidance on Bring Your Own Device policies • a complete update of their guidance on Direct Marketing • guidance on Social Networking • consultation on a review of the Privacy Notices Code of Practice Data Protection - All Change or More of the Same?
  • 21. New EU Regulation: Rationale 1995: Directive 95/46/EC 1998: UK Data Protection Act (in force from 2000) 2003 (and earlier): Privacy & Electronic Communications Regulations Subsequently: • World Wide Web • Cloud computing • Social media • Profiling • Cookies, GPS tracking ... • Privacy awareness Data Protection - All Change or More of the Same?
  • 22. New EU Regulation: Timetable January 2012: first draft published by Commission 2012: various EU bodies contribute views 2013: attempts to reconcile differing views, with several conflicting drafts produced October 2013: compromise draft agreed by parliament 2015? Negotiations with Council Mid-2015? Ratification of final Regulation Data Protection - All Change or More of the Same?
  • 23. New EU Regulation: Some key issues Consent tightened up – no more pre-ticked boxes Marketing is a „legitimate interest‟ Limited right of erasure Right to object to profiling More detailed privacy notices Mandatory breach notification Data Protection by default and by design Mandatory Data Protection Officer Privacy impact assessments replace Notification Much-increased penalties (especially for multinational companies) Data Protection - All Change or More of the Same?
  • 24. Data Protection: the absolute basics We are trying to: • Prevent harm by • Keeping data only in the right hands (and being clear what „the right hands‟ are) • Holding good quality data (accurate, up to date and adequate) • Reassure people so that they trust us • Making sure people know enough about what we are doing • Giving people a choice where possible Data Protection - All Change or More of the Same?
  • 25. Thank you for listening To go into more detail, join one of my webinars: www.paulticher.com/webinars Or contact me at: 0116 273 8191 paul@paulticher.com Your Logo www.paulticher.com 2 Old College Court, 29 Priory Street, Ware, Hertfordshire, SG12 0DE