SlideShare a Scribd company logo
1 of 40
-GDPR - 5 Months On!
-
CPD Accredited
Fill out survey at the end of the webinar
Q&A Session
Questions Tab or #BPWebinars
Q&A
CPD
On Demand
This session is being recorded
REC
The Presenters…
Jennifer Hussey
Employment Law Advisor & Payroll Specialist
Thesaurus Software / Bright Contracts
Rachel Hynes
Marketing Executive
Thesaurus Software / BrightPay
Webinar Agenda
•Breakdown of the General Data Protection Regulation
•Processing Employee Data under GDPR
•GDPR and Payroll Processing
•How BrightPay and BrightPay Connect Can Help
•How Thesaurus Software Has Prepared
Questions & Answers
-Breakdown of GDPR
GDPR, what is it?
General Data Protection Regulation
• Aims to provide better protection for personal data
• Current data legislation dates back to 1998
Definition of Personal Data
“Any information related on a natural person or ‘Data Subject’, that can
be used to directly or indirectly identify a person.”
✓ A name
✓ A photo
✓ An email address
✓ Bank details
✓ Posts on social networking websites
✓ Medical information
✓ CCTV images
✓ Records of websites visited
✓ A computer IP address
Data Protection Principles
Lawfulness Purpose
Limitation
Data
Minimisation
Accuracy Storage
Limitation
Integrity &
Confidentiality
What’s new in GDPR
• Accountability – demonstrating compliance
• Transparency – providing information pre-processing
• Mandatory data breach reporting (72 hours)
• DPO – Data Protection Officer
• Fines – Administrative Fines, Civil Liability
• Strengthened ‘Consent’ obligations
• New and enhanced Data Subject rights
Integrity &
Confidentiality
Demonstrating Accountability
Article 24.1- “….the controller shall implement appropriate technical
and organizational measures to ensure and to be able to
demonstrate that processing is performed in accordance with
this Regulation”
• Putting together an inventory of the data you currently hold and
process
• Complete Data Protection Impact Assesment (DPIA)
• Appoint a DPO if necessary
Integrity &
Confidentiality
• Details of Data Controller or DPO
• Purpose and legal basis for processing
• Sharing of data – internally / any third
parties
• Storage or transfer of data outside EEA
• Retention periods
• Rights of data subjects
• Consent
• Breach reporting / complaints to supervising
authority
• Any automated decision making processes
• Any Special Categories processed
Transparency
Article 12 - “The controller shall take appropriate measures to provide any
information……..relating to processing to the data subject in a concise, transparent, intelligible
and easily accessible form, using clear and plain language, in particular for any information
addressed specifically to a child”
At the time when personal data is obtained, the data subject must be
provided with information on:
Breach Reporting / Fines
Integrity &
Confidentiality
5. Changes to Consent Rules
1. Consent must be:
- Specific, informed,
unambiguous and freely given
- Must be for a specified purpose
2. Where consent is
obtained as part of a larger
document covering other
things, consent must be
clearly distinguished from
everything else
3. Evidence needs to be
retained as to how the consent
was obtained
Forms, brochures signage,
website screenshots etc.
4. Language must be
accessible and easily
understood
9. Enhanced Rights for Data Subjects
The right to
erasure
The right to
restrict
processing
The right to data
portability
The right to
object
Rights in relation to
automated
decision making
Right to be
informed
The right to
access
The right to
rectification
-Processing Employee Data under GDPR
Who?
• Job Applicants
• Existing Employees
• Leaver
What?
• Name and address
• Payroll information
• Next of kin
• Performance review
• Health or sickness information
HR and Payroll under GDPR
Data Management
Payroll and personal data must be processed lawfully, fairly and
in a transparent manner.
- A lawful reason for processing data must exist
- All data must be kept up-to-date and only be used for purposes that
have been communicated
- Only hold information required for as long as it is needed.
- Data needs to be protected and stored in a secure manner.
The data subject has given consent
Necessary for the performance of contract
Necessary for the compliance with legal obligation
In order to protect vital interests of a person
Necessary for public interest or official authority
For the legitimate interests of data controller or yourself the
employer in this case.
Lawful Processing
• Under GDPR consent must be "freely given, specific, informed and
unambiguous".
• Consent can no longer be relied upon as a lawful reason for
processing employee personal data
Lawful Processing & Consent
Enhanced Rights for Employees
The right to be informed
The right of access
The right to rectification
© NEST Corporation 2015
Recommended Self-Service Option
The GDPR includes a best practice recommendation that,
where possible, organisations should be able to provide remote
access to a secure self-service system which would provide the
individual with direct access to his or her information.
24/7 Online
Access
Payroll
Information
Employee
Documents
Annual Leave
Entitlements
-GDPR & Payroll Processing
Email Payslips
• Yes you can email payslips
• Security measures should be
taken, like password protecting
the payslips
Postal Payslips
• Yes you can post payslips
• Security measures should be
taken, like security sealed
envelopes
Distributing Payslips
• It is recommended (but not mandatory) to offer a secure
self-service portal to securely send and store payslips
Recommended Self-Service Option
• Password protected for each employee
• Provides flexibility and full transparency for employees to retrieve
and update their information at any time
• Employers can login and view payslips, payroll reports and
amounts due to Revenue
• Distribution of payslips and reports are automated and
automatically available to employees
Securely Storing Employee Payroll Data
• Password protect computers that hold
personal data
• Password protect software applications
that hold personal data
• Password protect or encrypt payslips
and other documents that may be
emailed to employees
-Data Processor Agreement
Who Processes Payroll?
In-house Payroll Outsourced Payroll
Data Processor Employer Payroll Bureau
Data
Controller
Employer Employer
Data Subject Employees Employees
A written contract must
be in place!
Employees must be
informed, consent is
not required.
Data Processor Agreement
• Whenever a data controller uses a data processor there needs to be
a written contract in place
• Controllers are liable for their compliance with the GDPR and must
only appoint processors who can provide ‘sufficient guarantees’ that
the requirements of the GDPR will be met
• Data processors will have some direct responsibilities and may be
subject to fines or other sanctions if they don’t comply
What does this contract look like?
• Compliance:
• Draft new Terms of Service / EULAs / Engagement Letters
• Issue an Addendum to any existing contract
• Contract Content
• Mandatory content has expanded
• Template Data Processor Agreement (DPA)
-How BrightPay can help
-
Standard Licence: £99 + VAT
• One employer
• Unlimited employees
• Free phone & email support
• Full functionality
Payroll Software
Bureau Licence: £229 + VAT
• Unlimited employers
• Unlimited employees
• Free phone & email support
• Full functionality
-
How can Bright Contracts help
with GDPR compliance?
-
Standard Licence: £99 + VAT
• One employer
• Unlimited employees
• Free phone & email support
• Online HR templates
Employment Contracts,
Handbooks & Privacy Policies
Bureau Licence: £199 + VAT
• Unlimited employers
• Unlimited employees
• Free phone & email support
• Online HR templates
-
How can BrightPay Connect help
with GDPR compliance?
© NEST Corporation 2015
BrightPay
Connect
•Automated
Cloud Backup
Self-Service
Remote
Access
Password
Protected
Payslip Portal
Secure
Document
Exchange
Accurate
Employee
Records
Right to
Rectification
User
Restrictions
Central
Location for
Documents
-
Single Employer:
£49
+ VAT per tax year
BrightPay Connect
Standard Pro Bundle:
• BrightPay Payroll
• BrightPay Connect
• Bright Contracts
Worth: £247
Bundle Price: £199
-How have we prepared for GDPR?
© NEST Corporation 2015
Key
Changes
•In-Program
Customer
Support
Privacy
Policy
Internal
IT Audits
Secure
Servers
Additional
Consent
Staff Training
& Awareness
Bright
Contracts
Thesaurus &
BrightPay
Connect
-Questions & Answers

More Related Content

What's hot

Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Ulf Mattsson
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)Madhumita Mantri
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceSarah Fox
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 

What's hot (20)

Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 

Similar to GDPR - 5 Months On!

GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantEsendex
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPRMarketo
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Followetouches
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
Managed Service Provider Contracts
Managed Service Provider ContractsManaged Service Provider Contracts
Managed Service Provider ContractsWhitmeyerTuffin
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersSpain-Holiday.com
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 

Similar to GDPR - 5 Months On! (20)

Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Follow
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Managed Service Provider Contracts
Managed Service Provider ContractsManaged Service Provider Contracts
Managed Service Provider Contracts
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 

More from BrightPay Payroll and Auto Enrolment Software

More from BrightPay Payroll and Auto Enrolment Software (20)

Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back
 
BrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it worksBrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it works
 
Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022
 
Webinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQWebinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQ
 
Revenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for OctoberRevenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for October
 
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker RevenueEmployment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
 
EWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to knowEWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to know
 
The End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term ImpactsThe End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term Impacts
 
BrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for AccountantsBrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for Accountants
 
BrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting SoftwareBrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting Software
 
Furlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from JulyFurlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from July
 
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine PolicyLeaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
 
Take the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflowsTake the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflows
 
Payroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule ChangesPayroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule Changes
 
Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...
 
Optimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve ProfitabilityOptimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve Profitability
 
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC QuirksCJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
 
IR35 - Are you Ready?
IR35 - Are you Ready?IR35 - Are you Ready?
IR35 - Are you Ready?
 
The Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-HouseThe Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-House
 
Switch to BrightPay
Switch to BrightPaySwitch to BrightPay
Switch to BrightPay
 

Recently uploaded

Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVshikhaohhpro
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfkalichargn70th171
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdfWave PLM
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...gurkirankumar98700
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comFatema Valibhai
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfkalichargn70th171
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Modelsaagamshah0812
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️Delhi Call girls
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...OnePlan Solutions
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsJhone kinadey
 
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...MyIntelliSource, Inc.
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...MyIntelliSource, Inc.
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...ICS
 
Active Directory Penetration Testing, cionsystems.com.pdf
Active Directory Penetration Testing, cionsystems.com.pdfActive Directory Penetration Testing, cionsystems.com.pdf
Active Directory Penetration Testing, cionsystems.com.pdfCionsystems
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsAndolasoft Inc
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AIABDERRAOUF MEHENNI
 

Recently uploaded (20)

Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.com
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Models
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
Microsoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdfMicrosoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdf
 
Active Directory Penetration Testing, cionsystems.com.pdf
Active Directory Penetration Testing, cionsystems.com.pdfActive Directory Penetration Testing, cionsystems.com.pdf
Active Directory Penetration Testing, cionsystems.com.pdf
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
 

GDPR - 5 Months On!

  • 1. -GDPR - 5 Months On!
  • 2. - CPD Accredited Fill out survey at the end of the webinar Q&A Session Questions Tab or #BPWebinars Q&A CPD On Demand This session is being recorded REC
  • 3. The Presenters… Jennifer Hussey Employment Law Advisor & Payroll Specialist Thesaurus Software / Bright Contracts Rachel Hynes Marketing Executive Thesaurus Software / BrightPay
  • 4. Webinar Agenda •Breakdown of the General Data Protection Regulation •Processing Employee Data under GDPR •GDPR and Payroll Processing •How BrightPay and BrightPay Connect Can Help •How Thesaurus Software Has Prepared Questions & Answers
  • 6. GDPR, what is it? General Data Protection Regulation • Aims to provide better protection for personal data • Current data legislation dates back to 1998
  • 7. Definition of Personal Data “Any information related on a natural person or ‘Data Subject’, that can be used to directly or indirectly identify a person.” ✓ A name ✓ A photo ✓ An email address ✓ Bank details ✓ Posts on social networking websites ✓ Medical information ✓ CCTV images ✓ Records of websites visited ✓ A computer IP address
  • 8. Data Protection Principles Lawfulness Purpose Limitation Data Minimisation Accuracy Storage Limitation Integrity & Confidentiality
  • 9. What’s new in GDPR • Accountability – demonstrating compliance • Transparency – providing information pre-processing • Mandatory data breach reporting (72 hours) • DPO – Data Protection Officer • Fines – Administrative Fines, Civil Liability • Strengthened ‘Consent’ obligations • New and enhanced Data Subject rights Integrity & Confidentiality
  • 10. Demonstrating Accountability Article 24.1- “….the controller shall implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation” • Putting together an inventory of the data you currently hold and process • Complete Data Protection Impact Assesment (DPIA) • Appoint a DPO if necessary Integrity & Confidentiality
  • 11. • Details of Data Controller or DPO • Purpose and legal basis for processing • Sharing of data – internally / any third parties • Storage or transfer of data outside EEA • Retention periods • Rights of data subjects • Consent • Breach reporting / complaints to supervising authority • Any automated decision making processes • Any Special Categories processed Transparency Article 12 - “The controller shall take appropriate measures to provide any information……..relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child” At the time when personal data is obtained, the data subject must be provided with information on:
  • 12. Breach Reporting / Fines Integrity & Confidentiality
  • 13. 5. Changes to Consent Rules 1. Consent must be: - Specific, informed, unambiguous and freely given - Must be for a specified purpose 2. Where consent is obtained as part of a larger document covering other things, consent must be clearly distinguished from everything else 3. Evidence needs to be retained as to how the consent was obtained Forms, brochures signage, website screenshots etc. 4. Language must be accessible and easily understood
  • 14. 9. Enhanced Rights for Data Subjects The right to erasure The right to restrict processing The right to data portability The right to object Rights in relation to automated decision making Right to be informed The right to access The right to rectification
  • 16. Who? • Job Applicants • Existing Employees • Leaver What? • Name and address • Payroll information • Next of kin • Performance review • Health or sickness information HR and Payroll under GDPR
  • 17. Data Management Payroll and personal data must be processed lawfully, fairly and in a transparent manner. - A lawful reason for processing data must exist - All data must be kept up-to-date and only be used for purposes that have been communicated - Only hold information required for as long as it is needed. - Data needs to be protected and stored in a secure manner.
  • 18. The data subject has given consent Necessary for the performance of contract Necessary for the compliance with legal obligation In order to protect vital interests of a person Necessary for public interest or official authority For the legitimate interests of data controller or yourself the employer in this case. Lawful Processing
  • 19. • Under GDPR consent must be "freely given, specific, informed and unambiguous". • Consent can no longer be relied upon as a lawful reason for processing employee personal data Lawful Processing & Consent
  • 20. Enhanced Rights for Employees The right to be informed The right of access The right to rectification
  • 21. © NEST Corporation 2015 Recommended Self-Service Option The GDPR includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information. 24/7 Online Access Payroll Information Employee Documents Annual Leave Entitlements
  • 22. -GDPR & Payroll Processing
  • 23. Email Payslips • Yes you can email payslips • Security measures should be taken, like password protecting the payslips Postal Payslips • Yes you can post payslips • Security measures should be taken, like security sealed envelopes Distributing Payslips • It is recommended (but not mandatory) to offer a secure self-service portal to securely send and store payslips
  • 24. Recommended Self-Service Option • Password protected for each employee • Provides flexibility and full transparency for employees to retrieve and update their information at any time • Employers can login and view payslips, payroll reports and amounts due to Revenue • Distribution of payslips and reports are automated and automatically available to employees
  • 25. Securely Storing Employee Payroll Data • Password protect computers that hold personal data • Password protect software applications that hold personal data • Password protect or encrypt payslips and other documents that may be emailed to employees
  • 27. Who Processes Payroll? In-house Payroll Outsourced Payroll Data Processor Employer Payroll Bureau Data Controller Employer Employer Data Subject Employees Employees A written contract must be in place! Employees must be informed, consent is not required.
  • 28. Data Processor Agreement • Whenever a data controller uses a data processor there needs to be a written contract in place • Controllers are liable for their compliance with the GDPR and must only appoint processors who can provide ‘sufficient guarantees’ that the requirements of the GDPR will be met • Data processors will have some direct responsibilities and may be subject to fines or other sanctions if they don’t comply
  • 29. What does this contract look like? • Compliance: • Draft new Terms of Service / EULAs / Engagement Letters • Issue an Addendum to any existing contract • Contract Content • Mandatory content has expanded • Template Data Processor Agreement (DPA)
  • 31.
  • 32. - Standard Licence: £99 + VAT • One employer • Unlimited employees • Free phone & email support • Full functionality Payroll Software Bureau Licence: £229 + VAT • Unlimited employers • Unlimited employees • Free phone & email support • Full functionality
  • 33. - How can Bright Contracts help with GDPR compliance?
  • 34. - Standard Licence: £99 + VAT • One employer • Unlimited employees • Free phone & email support • Online HR templates Employment Contracts, Handbooks & Privacy Policies Bureau Licence: £199 + VAT • Unlimited employers • Unlimited employees • Free phone & email support • Online HR templates
  • 35. - How can BrightPay Connect help with GDPR compliance?
  • 36. © NEST Corporation 2015 BrightPay Connect •Automated Cloud Backup Self-Service Remote Access Password Protected Payslip Portal Secure Document Exchange Accurate Employee Records Right to Rectification User Restrictions Central Location for Documents
  • 37. - Single Employer: £49 + VAT per tax year BrightPay Connect Standard Pro Bundle: • BrightPay Payroll • BrightPay Connect • Bright Contracts Worth: £247 Bundle Price: £199
  • 38. -How have we prepared for GDPR?
  • 39. © NEST Corporation 2015 Key Changes •In-Program Customer Support Privacy Policy Internal IT Audits Secure Servers Additional Consent Staff Training & Awareness Bright Contracts Thesaurus & BrightPay Connect