SlideShare une entreprise Scribd logo
1  sur  15
A Quick Look at GDPR
And how to Make Websites Comply
What is GDPR?
GDPR is a privacy law that regulates the data collected of the EU citizens by
organizations around the world.
The law gives the users much control over their personal data.
The law makes it mandatory that the users be aware of what data are collected
and get the explicit consent for collecting them.
The users have many rights over the data that has been collected, and the
organizations are required to honor them within a set period or time.
What is GDPR (contd.)
Even if an organization is not located in the EU, they have an obligation to
comply with the law, if they have users in the EU
Not complying with the law may lead to hefty fines. The fines could potentially
be up to €20 million or 4% of the annual turnover of the previous year.
Some Important Terms in GDPR
1. Data subject - The term data subject refers to a natural person whose data
is collected, held, or processed.
2. Personal Data - This refers to the information that can directly or indirectly
identify a data subject.
3. Data controller - Data controller is an entity that determines the purposes
and means of processing the personal data.
4. Data processor - It is the entity that processes the data on behalf of the
data controller.
Some Important Term in GDPR (contd.)
1. Processing - It refers to any operation or set of operation performed on the
personal data.
2. Profiling - Any means of automated processing of personal data.
3. Third-party - is an entity other than the data subject, data controller, or the
data processor that is authorized to process personal data.
4. Consent - A consent is a freely given, informed, and unambiguous
agreement expressed by the data subject, given by a statement or an
affirmative action, to the processing of his/her personal data.
Principles of GDPR
There are 6 Principles of the GDPR that the organizations should abide by.
● Lawfulness, Fairness, and Transparency - The data collected should be
processed lawfully, fairly, and with complete transparency.
● Purpose Limitation - Data should only be used for specific purposes.
● Data Minimization - Only the data that is requires for a process should be
collected
● Accuracy - The data collected should be always accurate
Principles of GDPR (contd.)
● Storage limitation - The data collected should not be stored a period
longer than that is required.
● Integrity and Confidentiality (security) - This principle states that the data
controller should be held responsible for, and be able to show compliance
with all the above 6 principles of GDPR.
Right of the Data Subjects
GDPR gives multiple rights to the users that the organizations are expected to
respond to in the specified period of time.
● Right to be Informed - The data subjects should be informed all the details
about their personal data that are collected.
● Right of access - The individuals have the right of access to the personal
data.
● Right to rectification - The data subjects have the right ot have their data
rectified.
Rights of the Data Subjects (contd.)
● Right to erasure - The data subjects have the right to have their data
erased in certain circumstances.
● Right to restrict processing - This gives the individuals the right to restrict
or suppress the processing of their data.
● Right to data portability - This allows the data subjects to obtain and reuse
their personal data for their own purposes.
● Right to object - The data subjects have the right to object to the
processing their data in certain circumstances.
● Rights related to automated decision making including profiling
How to Get Started
The first step is an internal audit of all the data that are collected, how and why
they are collected and processed, for how long. Determine the point of each
and every data collection.
Next step is to inform the users at every point of where the data are collected.
Inform the users all about the data that is collected, in a clear and easily
understandable manner.
Craft a privacy policy for the website informing the users about every activities
done by the organization.
How to Get Started (contd.)
Get the consent of the users, existing and new, at every point the data is
collected and keep a record of the consent to be provided as proof if and when
required.
Proper infrastructure in place to identify and honor every user request
regarding their rights.
It is important to inform the users of a data breach when it occurs. Always keep
proper security measures in place regarding the personal data and inform the
users as soon as possible in case of a data breach.
How the Law Applies to Cookies
Cookies are one of the ways that the website collect user information.
The law does not apply to the cookies that are necessary for the website to
function.
For the rest of the cookies that collect user information that can be used to
directly or indirectly collect data, should only be stored on the users’ website
when they have given their explicit consent.
How the Law Applies to Cookies (contd.)
When giving consent, the users should be informed as and their consent should
be explicit and given by affirmative action like clicking on a button.
Most website inform the users of their cookie usage on the website with the
help of a small banner. A link to a cookie policy page is given to the users with
details about what cookies, used and the purpose of using and other related
information.
To be compliant with the law, it is important to get the users’ consent before
the website places a cookie on the users browser.
Consequences of not Complying
Not complying with the law can potentially result in hefty fines. And this is
applied to every organizations that serves the citizen of the EU.
There are two different maximum amounts of the fine imposed. These are €10
million or 2% of the annual turnover or whichever is higher and €20 million or
4% of the annual turnover.
The penalty of non-compliance may also vary depending on multiple criteria as
per the guidelines to the supervisory authority.
Thank you...
Slides prepared by Cookie Law Info

Contenu connexe

Tendances

Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
Yizi
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
SaimaRafiq
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
N N
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
joshquarrie
 

Tendances (19)

Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To Know
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for Ops
 
Data Protection Guidelines
Data Protection GuidelinesData Protection Guidelines
Data Protection Guidelines
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)
 
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and RequirementsPrivacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
 

Similaire à A quick look at gdpr

New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
Ulf Mattsson
 

Similaire à A quick look at gdpr (20)

Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
GDPR
GDPRGDPR
GDPR
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
Are You Prepared for the GDPR?
Are You Prepared for the GDPR?Are You Prepared for the GDPR?
Are You Prepared for the GDPR?
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant?
 
Top 10 GDPR Requirements
Top 10 GDPR RequirementsTop 10 GDPR Requirements
Top 10 GDPR Requirements
 
Data Privacy Laws: A Global Overview and Compliance Strategies
Data Privacy Laws: A Global Overview and Compliance StrategiesData Privacy Laws: A Global Overview and Compliance Strategies
Data Privacy Laws: A Global Overview and Compliance Strategies
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 

Dernier

+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
Health
 
PLE-statistics document for primary schs
PLE-statistics document for primary schsPLE-statistics document for primary schs
PLE-statistics document for primary schs
cnajjemba
 
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
q6pzkpark
 
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
ZurliaSoop
 
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
vexqp
 
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
nirzagarg
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
nirzagarg
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
gajnagarg
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
nirzagarg
 
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Bertram Ludäscher
 
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
nirzagarg
 
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get CytotecAbortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Riyadh +966572737505 get cytotec
 
Cytotec in Jeddah+966572737505) get unwanted pregnancy kit Riyadh
Cytotec in Jeddah+966572737505) get unwanted pregnancy kit RiyadhCytotec in Jeddah+966572737505) get unwanted pregnancy kit Riyadh
Cytotec in Jeddah+966572737505) get unwanted pregnancy kit Riyadh
Abortion pills in Riyadh +966572737505 get cytotec
 

Dernier (20)

Data Analyst Tasks to do the internship.pdf
Data Analyst Tasks to do the internship.pdfData Analyst Tasks to do the internship.pdf
Data Analyst Tasks to do the internship.pdf
 
Digital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham WareDigital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham Ware
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Research
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
 
PLE-statistics document for primary schs
PLE-statistics document for primary schsPLE-statistics document for primary schs
PLE-statistics document for primary schs
 
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
 
Harnessing the Power of GenAI for BI and Reporting.pptx
Harnessing the Power of GenAI for BI and Reporting.pptxHarnessing the Power of GenAI for BI and Reporting.pptx
Harnessing the Power of GenAI for BI and Reporting.pptx
 
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
 
The-boAt-Story-Navigating-the-Waves-of-Innovation.pptx
The-boAt-Story-Navigating-the-Waves-of-Innovation.pptxThe-boAt-Story-Navigating-the-Waves-of-Innovation.pptx
The-boAt-Story-Navigating-the-Waves-of-Innovation.pptx
 
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
 
Dubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls DubaiDubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls Dubai
 
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
 
Capstone in Interprofessional Informatic // IMPACT OF COVID 19 ON EDUCATION
Capstone in Interprofessional Informatic  // IMPACT OF COVID 19 ON EDUCATIONCapstone in Interprofessional Informatic  // IMPACT OF COVID 19 ON EDUCATION
Capstone in Interprofessional Informatic // IMPACT OF COVID 19 ON EDUCATION
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
 
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
 
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
 
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get CytotecAbortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
 
Cytotec in Jeddah+966572737505) get unwanted pregnancy kit Riyadh
Cytotec in Jeddah+966572737505) get unwanted pregnancy kit RiyadhCytotec in Jeddah+966572737505) get unwanted pregnancy kit Riyadh
Cytotec in Jeddah+966572737505) get unwanted pregnancy kit Riyadh
 

A quick look at gdpr

  • 1. A Quick Look at GDPR And how to Make Websites Comply
  • 2. What is GDPR? GDPR is a privacy law that regulates the data collected of the EU citizens by organizations around the world. The law gives the users much control over their personal data. The law makes it mandatory that the users be aware of what data are collected and get the explicit consent for collecting them. The users have many rights over the data that has been collected, and the organizations are required to honor them within a set period or time.
  • 3. What is GDPR (contd.) Even if an organization is not located in the EU, they have an obligation to comply with the law, if they have users in the EU Not complying with the law may lead to hefty fines. The fines could potentially be up to €20 million or 4% of the annual turnover of the previous year.
  • 4. Some Important Terms in GDPR 1. Data subject - The term data subject refers to a natural person whose data is collected, held, or processed. 2. Personal Data - This refers to the information that can directly or indirectly identify a data subject. 3. Data controller - Data controller is an entity that determines the purposes and means of processing the personal data. 4. Data processor - It is the entity that processes the data on behalf of the data controller.
  • 5. Some Important Term in GDPR (contd.) 1. Processing - It refers to any operation or set of operation performed on the personal data. 2. Profiling - Any means of automated processing of personal data. 3. Third-party - is an entity other than the data subject, data controller, or the data processor that is authorized to process personal data. 4. Consent - A consent is a freely given, informed, and unambiguous agreement expressed by the data subject, given by a statement or an affirmative action, to the processing of his/her personal data.
  • 6. Principles of GDPR There are 6 Principles of the GDPR that the organizations should abide by. ● Lawfulness, Fairness, and Transparency - The data collected should be processed lawfully, fairly, and with complete transparency. ● Purpose Limitation - Data should only be used for specific purposes. ● Data Minimization - Only the data that is requires for a process should be collected ● Accuracy - The data collected should be always accurate
  • 7. Principles of GDPR (contd.) ● Storage limitation - The data collected should not be stored a period longer than that is required. ● Integrity and Confidentiality (security) - This principle states that the data controller should be held responsible for, and be able to show compliance with all the above 6 principles of GDPR.
  • 8. Right of the Data Subjects GDPR gives multiple rights to the users that the organizations are expected to respond to in the specified period of time. ● Right to be Informed - The data subjects should be informed all the details about their personal data that are collected. ● Right of access - The individuals have the right of access to the personal data. ● Right to rectification - The data subjects have the right ot have their data rectified.
  • 9. Rights of the Data Subjects (contd.) ● Right to erasure - The data subjects have the right to have their data erased in certain circumstances. ● Right to restrict processing - This gives the individuals the right to restrict or suppress the processing of their data. ● Right to data portability - This allows the data subjects to obtain and reuse their personal data for their own purposes. ● Right to object - The data subjects have the right to object to the processing their data in certain circumstances. ● Rights related to automated decision making including profiling
  • 10. How to Get Started The first step is an internal audit of all the data that are collected, how and why they are collected and processed, for how long. Determine the point of each and every data collection. Next step is to inform the users at every point of where the data are collected. Inform the users all about the data that is collected, in a clear and easily understandable manner. Craft a privacy policy for the website informing the users about every activities done by the organization.
  • 11. How to Get Started (contd.) Get the consent of the users, existing and new, at every point the data is collected and keep a record of the consent to be provided as proof if and when required. Proper infrastructure in place to identify and honor every user request regarding their rights. It is important to inform the users of a data breach when it occurs. Always keep proper security measures in place regarding the personal data and inform the users as soon as possible in case of a data breach.
  • 12. How the Law Applies to Cookies Cookies are one of the ways that the website collect user information. The law does not apply to the cookies that are necessary for the website to function. For the rest of the cookies that collect user information that can be used to directly or indirectly collect data, should only be stored on the users’ website when they have given their explicit consent.
  • 13. How the Law Applies to Cookies (contd.) When giving consent, the users should be informed as and their consent should be explicit and given by affirmative action like clicking on a button. Most website inform the users of their cookie usage on the website with the help of a small banner. A link to a cookie policy page is given to the users with details about what cookies, used and the purpose of using and other related information. To be compliant with the law, it is important to get the users’ consent before the website places a cookie on the users browser.
  • 14. Consequences of not Complying Not complying with the law can potentially result in hefty fines. And this is applied to every organizations that serves the citizen of the EU. There are two different maximum amounts of the fine imposed. These are €10 million or 2% of the annual turnover or whichever is higher and €20 million or 4% of the annual turnover. The penalty of non-compliance may also vary depending on multiple criteria as per the guidelines to the supervisory authority.
  • 15. Thank you... Slides prepared by Cookie Law Info