SlideShare une entreprise Scribd logo
1  sur  25
Data Protection Fundamentals - GDPR
Elizabeth Dunne Barrister-at-law, PC. dp
Elizabeth Dunne Consultancy Services
October 23rd 2018
Elizabeth Dunne Consultancy Services 2018
• EU Regulation on General Data Protection – GDPR – was adopted
April 2016 and enforced 25th May 2018.
• New Data Protection Act 2018 (25th May 2018).
• Fines / sanctions for infringement and breach of the Act directly by
Office of Data Protection Commissioner.
• Investigations and new offences.
Data Protection and GDPR
Elizabeth Dunne Consultancy Services 2018
Elizabeth Dunne Consultancy Services 2018
• Current landscape and legislation – road to GDPR – Regulation and Data
Protection Act 2018
• Definitions to remember
• Steps to achieving compliance – the “lifecycle” of data:
– Collection
– Storage
– Usage
– Sharing
– Disposal
• Types of personal data
• Demonstrating compliance: Policies and Procedures – Website Privacy
Notice, Breach Protocol, Data Subject Access Protocol and Form, Data
Protection Policy and Data Retention Policy.
• Questions
Data Protection and GDPR
Data Protection and GDPR
• ‘Personal data’ is defined as any information relating to an
identified or identifiable natural person (‘data subject’); (doesn’t
apply to deceased persons, recital 27)
– an identifiable natural person is one who can be identified,
directly or indirectly, in particular by reference to an identifier
such as a name, an identification number, location data, an
online identifier or to one or more factors specific to the
physical, physiological, genetic, mental, economic, cultural or
social identity of that natural person;
• Legal basis – the legal basis on which processing occurs under ART
6 or 9 and must be identified by the controller
Elizabeth Dunne Consultancy Services 2018
Elizabeth Dunne Consultancy Services 2018
Data Protection and GDPR
‘Data Subject’: “an individual who is the subject of the personal data”.
‘Processing’ means: any operation or set of operations which is
performed on personal data or on sets of personal data, whether or not
by automated means, such as collection, recording, organisation,
structuring, storage, adaptation or alteration, retrieval, consultation, use,
disclosure by transmission, dissemination or otherwise making available,
alignment or combination, restriction, erasure or destruction;
‘Personal data breach’ means a breach of security leading to the
accidental or unlawful destruction, loss, alteration, unauthorised
disclosure of, or access to, personal data transmitted, stored or
otherwise processed;
‘Special categories of data’ will include personal data revealing
• racial or ethnic origin,
• political opinions,
• religious or philosophical beliefs, or
• trade union membership, and the processing of
• genetic data, biometric data for the purpose of uniquely identifying
a natural person,
• data concerning health or
• data concerning a natural person's sex life
• sexual orientation
• Criminal convictions of offences
Processing of these categories is prohibited, unless one of the
conditions under ART 9 are satisfied.
Data Protection and GDPR
Elizabeth Dunne Consultancy Services 2018
Processing of these categories is prohibited, unless one of the
conditions under ART 9 are satisfied:
• Explicit consent (where the data subject gives their consent);
• Processing is necessary for the purpose of carrying out obligations
or rights of the controller or data subject in the field of employment,
social security and social protection law (not based on consent);
• Processing is necessary to protect the vital interests of the data
subject or another (not based on consent).
There are other conditions in the area of public health or defence of
legal claims, but generally one of the above grounds must be satisfied
before the others will apply.
Data Protection and GDPR
Elizabeth Dunne Consultancy Services 2018
Elizabeth Dunne Consultancy Services 2018
Data Protection and GDPR
Processing of other categories of personal data (name, address, phone
number, email, financial details) must satisfy ART 6:
• The data subject has given consent (where consent is given);
• Processing is necessary for the performance of a contract to which
the data subject is party or in order to take steps at the request of
the data subject prior to entering a contract;
• Processing is necessary for compliance with a legal obligation to
which the controller is subject;
• Processing is necessary to protect vital interests of data subject;
• Processing is necessary for the performance of a task carried out in
the public interest or exercise of official authority;
• Legitimate interest of the controller.
Elizabeth Dunne Consultancy Services 2018
Data controller controls the contents and use of personal data
‘Controller’ means the natural or legal person, public authority, agency
or other body which, alone or jointly with others, determines the
purposes and means of the processing of personal data; where the
purposes and means of such processing are determined by Union or
Member State law, the controller or the specific criteria for its
nomination may be provided for by Union or Member State law;
‘Processor’ means a natural or legal person, public authority, agency or
other body which processes personal data on behalf of the controller;
Data Protection and GDPR
• Where is data stored?
• Hard drives (“C” drives (local), shared network drives)
• Databases (excel etc)
• Email
• Laptops / USBs
• Smart phones / other devices
• Cloud applications
• Paper files / relevant filing systems
• Stand alone systems
• Archive
• Social media whatsApp, Facebook / Instagram*
• *June 2018 – admins are data controllers for Facebook accounts
and data collected there.
Data Protection and GDPR - storage
Elizabeth Dunne Consultancy Services 2018
• GDPR requires “technical and organisational” measures to keep data
secure when stored– implement policies and purge duplicate data
• Record all categories of data (including sensitive) on a register and
draft a data retention schedule
• Assign access privilege to databases and network drives containing
personal or sensitive data – need to access only if handling
personal data on a need to know basis
• Check Cloud Service Provider’s contract to ensure it delivers the
same level of availability, security and confidentiality (data centres
should be listed and transfers prohibited outside EEA unless specific
measures in place to allow that transfer)
Data Protection and GDPR - Storage
Elizabeth Dunne Consultancy Services 2018
• Personal and Sensitive information should only be used for the
purpose it was collected for
• Any new or further use must be consented to by the data subject,
whether consent was obtained originally or not for the data
• Data subjects have rights: to access, object to processing,
rectification, erasure, porting and to withdraw consent – during use
of data. Staff generally have a right to their HR file and its contents
subject to reasonable considerations.
• Ensure you have DSAR procedure in place where changes to data
use occurs
• Review use of data sets regularly to make sure they’re not outdated
or inaccurate
Data Protection and GDPR - Usage
Elizabeth Dunne Consultancy Services 2018
• Know how your data subject’s personal information is shared:
– Within the organisation
– With 3rd parties
• Who has access within the organisation? Ensure you know what
they are doing with it (copying it / using emails for other purposes /
storing it?).
• Data subjects are entitled to know with whom their data is disclosed
to in particular, 3rd parties processing on your behalf.
• You must have a contract in place with 3rd parties who process
data on your behalf – employee, users and supplier data.
• For example: cloud services, payroll (staff data).
• They must follow your instructions and never share personal data
with others or use it for their own purposes.
• Statutory obligations and sharing of data e.g. department of social
protection, revenue, other gov agencies.
Data Protection and GDPR - Sharing
Elizabeth Dunne Consultancy Services 2018
• Data must only be kept for the purpose it was collected for and
disposed of when it is not needed.
• Have a retention and disposal period for different categories of data.
• Be careful of archiving personal data as it is amenable to the GDPR
and the Data Protection Act 2018
• Have retention periods for client and staff personal data
• Choose a disposal method: shredding for paper files (secure) and
purging of systems for electronic / networks; destruction of hard
drives.
• If you use third parties to process data make sure they have your
retention and disposal rules in place
Data Protection and GDPR - Disposal
Elizabeth Dunne Consultancy Services 2018
• Name
• National identifiers (e.g., passport I.D) sensitive
• Personal e-mail address / work email
• Personal identification numbers (PIN) or passwords
• Personal interests derived from tracking use of internet web sites
• Sexual life, marriage status, political opinions sensitive
• Personal telephone number
• Photograph or video identifiable to a natural person sensitive
• Product and service preferences
• Racial or ethnic origin Religious or philosophical beliefs Sexual
orientation Trade-union membership sensitive
• Utility bills
Data Protection and GDPR – Types of personal data
Elizabeth Dunne Consultancy Services 2018
• Age or special needs of vulnerable natural persons sensitive
• Allegations of criminal conduct sensitive
• Any information collected during health services sensitive
• Bank account or credit card number
• Biometric identifier and fingerprint data sensitive
• Credit card statements
• Criminal convictions or committed offences sensitive
• Criminal investigation reports sensitive
• Customer number
• Date of birth
• Diagnostic health information sensitive
• Disabilities sensitive
Data Protection and GDPR – Types of personal data
Elizabeth Dunne Consultancy Services 2018
• Doctor bills
• Employees’ salaries and human resources files (sensitive when
containing medical data or other sensitive categories)
• Financial profile
• Gender sensitive
• GPS position
• GPS trajectories
• Home address
• IP address Location derived from telecommunications systems
• Medical history sensitive
Data Protection and GDPR – Types of personal data
Elizabeth Dunne Consultancy Services 2018
• Privacy Website Notice Purpose:
• Your website is where people go to find details of your services
and GDPR requires data subjects know the following:
• A transparent description of:
• Who you are and contact details of person / email to deal with data
protection issues
• Types of data collected
• Legal basis for collection and processing
• Who it is disclosed to and how long you keep it
• How data subjects can exercise their rights
• Use of cookies and other tracking devices
• Transfer of data outside of the EEA
• Be in plain easy to understand language
Demonstrating Compliance - Policies and Procedures
Website Privacy Notice Public Facing
Elizabeth Dunne Consultancy Services 2018
Elizabeth Dunne Consultancy Services 2018
Data Breach Protocol
Data Breach Protocol and Form (log) purpose:
• Identify team members to co-ordinate breach response
• 72 hour window for notifiable breaches
• No automatic notification of data subject
• In general, a data breach will require notification to the DPC if the
data includes:
– the possibility of harm to the data subjects
– a large volume of personal data
– sensitive data (e.g. financial (loss of financial information can be detrimental) or
health information or other sensitive information
– If employee data is compromised, this must be included. It is not just service
user or supplier data
– DPC may advise if the data subject should be notified
• Identify weaknesses / risks in organisations leading to a breach
• Identify security risks and how they can be mitigated
Types of breaches include (most common):
• loss or theft of paperwork;
• data posted or sent to the wrong recipient;
• data sent by email to the wrong recipient;
• insecure webpage access (hacking);
• loss or theft of unencrypted device.
• If in doubt as to whether a situation involves a breach
consult with a member of the breach management Team.
Data Breach Log:
• Record of reportable and non reportable breaches
• Near misses
• https://dataprotection.ie/docs/Breach-Notification-Form/m/1726.htm
Elizabeth Dunne Consultancy Services 2018
Data Breach Protocol
Elizabeth Dunne Consultancy Services 2018
Data Subject Access Request and Form
Data Subject Access Protocol and Form purpose:
Service users, employees and suppliers have the right:
• to ask for details of their personal data held
• to ask for a copy of their personal data
• to have any inaccurate or misleading data rectified, corrected and
erased
• to restrict the processing of their personal data in certain
circumstances
• to object to the processing of their personal data
• to transfer their personal data to a third party
• a right not to be subject to automated decision making
• the right to receive notification of a data breach
• the right to lodge a complaint to the Data Protection Commissioner.
• Application made in writing
• Using a Data Subject Access Form – post or email it
• You cannot compel use of the Form but helps narrow down
information requested
• No charge (repeals 1988 and 2003 position)
• 2 working days to acknowledge receipt (not prescribed by
legislation)
• 30 days to respond (can be extended to 2 months)
• No third party information – only information relating to data
subject – disclosure of third party information is a breach
• Must verify identity of requester
• Begin processing the request but wait on verification
• Agents may apply on behalf of a data subject but verify their
identity
• Never allow anyone force you into revealing personal information
Elizabeth Dunne Consultancy Services 2018
Data Subject Access Request and Form
Data Protection Policy - Staff
Elizabeth Dunne Consultancy Services 2018
• Data Protection Policy (Staff) Purpose:
• Employees should be aware of both their rights and obligations
around data protection:
• A description of:
• contact details of person / email to deal with data protection issues
arising for staff
• Types of data collected relating to employment
• Reasons for collection and processing including sensitive data or
other data collected employees might not be aware of
• Who employee data is disclosed to and how long you keep it
• How employees can exercise their rights
• A statement of expectations for staff around data handling and
management of data.
Elizabeth Dunne Consultancy Services 2018
Data Retention Policy
• Data Retention Policy Purpose:
• Set out the document management and retention schedule.
• A description of:
• protocol for the management of all records
• Storage, management and destruction methods
• Responsibility around management of soft copy and hard copy data
• Schedule of documents and retention periods relevant to each area:
Personnel Files (HR), Corporate Records, Client and Service user
records.
• Miscellaneous other records.
• Most have statutory time periods but others are kept where a
business need arises or where retention relies on other bodies /
statutory agencies to which you are affiliated.
• Justification of time periods should be made where possible.
Questions and Answers
Elizabeth Dunne Consultancy Services 2018

Contenu connexe

Tendances

The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk- Mark - Fullbright
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson LLP
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR OverviewGydeline Ltd
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamBrowne Jacobson LLP
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Michael Adamberry
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterBrowne Jacobson LLP
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamBrowne Jacobson LLP
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonBrowne Jacobson LLP
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Russell_Kennedy
 

Tendances (20)

GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 

Similaire à Data Protection GDPR Basics

Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMichelleSaver
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
Webinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPRWebinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPRpanagenda
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
GDPR Data Life Cycle
GDPR Data Life CycleGDPR Data Life Cycle
GDPR Data Life CycleJatin Kochhar
 
WB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillWB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillTrustArc
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRNupur Samaddar
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyRay ABOU
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRRotary International
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Forums financiers de Wallonie
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 

Similaire à Data Protection GDPR Basics (20)

Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Webinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPRWebinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPR
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR Data Life Cycle
GDPR Data Life CycleGDPR Data Life Cycle
GDPR Data Life Cycle
 
GDPR Data Lifecycle
GDPR Data LifecycleGDPR Data Lifecycle
GDPR Data Lifecycle
 
WB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillWB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection Bill
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPR
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 

Dernier

Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Researchmichael115558
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxolyaivanovalion
 
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...shivangimorya083
 
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort ServiceBDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort ServiceDelhi Call girls
 
Zuja dropshipping via API with DroFx.pptx
Zuja dropshipping via API with DroFx.pptxZuja dropshipping via API with DroFx.pptx
Zuja dropshipping via API with DroFx.pptxolyaivanovalion
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...amitlee9823
 
Halmar dropshipping via API with DroFx
Halmar  dropshipping  via API with DroFxHalmar  dropshipping  via API with DroFx
Halmar dropshipping via API with DroFxolyaivanovalion
 
BabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxBabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxolyaivanovalion
 
Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionfulawalesam
 
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Callshivangimorya083
 
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfAccredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfadriantubila
 
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightCheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightDelhi Call girls
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfMarinCaroMartnezBerg
 
Data-Analysis for Chicago Crime Data 2023
Data-Analysis for Chicago Crime Data  2023Data-Analysis for Chicago Crime Data  2023
Data-Analysis for Chicago Crime Data 2023ymrp368
 
Carero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxCarero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxolyaivanovalion
 
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...amitlee9823
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxolyaivanovalion
 
Schema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfSchema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfLars Albertsson
 
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% SecureCall me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% SecurePooja Nehwal
 

Dernier (20)

Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Research
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFx
 
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
 
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort ServiceBDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
 
Zuja dropshipping via API with DroFx.pptx
Zuja dropshipping via API with DroFx.pptxZuja dropshipping via API with DroFx.pptx
Zuja dropshipping via API with DroFx.pptx
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Halmar dropshipping via API with DroFx
Halmar  dropshipping  via API with DroFxHalmar  dropshipping  via API with DroFx
Halmar dropshipping via API with DroFx
 
(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7
(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7
(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7
 
BabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxBabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptx
 
Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interaction
 
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfAccredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
 
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightCheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
 
Data-Analysis for Chicago Crime Data 2023
Data-Analysis for Chicago Crime Data  2023Data-Analysis for Chicago Crime Data  2023
Data-Analysis for Chicago Crime Data 2023
 
Carero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxCarero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptx
 
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptx
 
Schema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfSchema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdf
 
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% SecureCall me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
 

Data Protection GDPR Basics

  • 1. Data Protection Fundamentals - GDPR Elizabeth Dunne Barrister-at-law, PC. dp Elizabeth Dunne Consultancy Services October 23rd 2018 Elizabeth Dunne Consultancy Services 2018
  • 2. • EU Regulation on General Data Protection – GDPR – was adopted April 2016 and enforced 25th May 2018. • New Data Protection Act 2018 (25th May 2018). • Fines / sanctions for infringement and breach of the Act directly by Office of Data Protection Commissioner. • Investigations and new offences. Data Protection and GDPR Elizabeth Dunne Consultancy Services 2018
  • 3. Elizabeth Dunne Consultancy Services 2018 • Current landscape and legislation – road to GDPR – Regulation and Data Protection Act 2018 • Definitions to remember • Steps to achieving compliance – the “lifecycle” of data: – Collection – Storage – Usage – Sharing – Disposal • Types of personal data • Demonstrating compliance: Policies and Procedures – Website Privacy Notice, Breach Protocol, Data Subject Access Protocol and Form, Data Protection Policy and Data Retention Policy. • Questions Data Protection and GDPR
  • 4. Data Protection and GDPR • ‘Personal data’ is defined as any information relating to an identified or identifiable natural person (‘data subject’); (doesn’t apply to deceased persons, recital 27) – an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; • Legal basis – the legal basis on which processing occurs under ART 6 or 9 and must be identified by the controller Elizabeth Dunne Consultancy Services 2018
  • 5. Elizabeth Dunne Consultancy Services 2018 Data Protection and GDPR ‘Data Subject’: “an individual who is the subject of the personal data”. ‘Processing’ means: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; ‘Personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
  • 6. ‘Special categories of data’ will include personal data revealing • racial or ethnic origin, • political opinions, • religious or philosophical beliefs, or • trade union membership, and the processing of • genetic data, biometric data for the purpose of uniquely identifying a natural person, • data concerning health or • data concerning a natural person's sex life • sexual orientation • Criminal convictions of offences Processing of these categories is prohibited, unless one of the conditions under ART 9 are satisfied. Data Protection and GDPR Elizabeth Dunne Consultancy Services 2018
  • 7. Processing of these categories is prohibited, unless one of the conditions under ART 9 are satisfied: • Explicit consent (where the data subject gives their consent); • Processing is necessary for the purpose of carrying out obligations or rights of the controller or data subject in the field of employment, social security and social protection law (not based on consent); • Processing is necessary to protect the vital interests of the data subject or another (not based on consent). There are other conditions in the area of public health or defence of legal claims, but generally one of the above grounds must be satisfied before the others will apply. Data Protection and GDPR Elizabeth Dunne Consultancy Services 2018
  • 8. Elizabeth Dunne Consultancy Services 2018 Data Protection and GDPR Processing of other categories of personal data (name, address, phone number, email, financial details) must satisfy ART 6: • The data subject has given consent (where consent is given); • Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering a contract; • Processing is necessary for compliance with a legal obligation to which the controller is subject; • Processing is necessary to protect vital interests of data subject; • Processing is necessary for the performance of a task carried out in the public interest or exercise of official authority; • Legitimate interest of the controller.
  • 9. Elizabeth Dunne Consultancy Services 2018 Data controller controls the contents and use of personal data ‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law; ‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; Data Protection and GDPR
  • 10. • Where is data stored? • Hard drives (“C” drives (local), shared network drives) • Databases (excel etc) • Email • Laptops / USBs • Smart phones / other devices • Cloud applications • Paper files / relevant filing systems • Stand alone systems • Archive • Social media whatsApp, Facebook / Instagram* • *June 2018 – admins are data controllers for Facebook accounts and data collected there. Data Protection and GDPR - storage Elizabeth Dunne Consultancy Services 2018
  • 11. • GDPR requires “technical and organisational” measures to keep data secure when stored– implement policies and purge duplicate data • Record all categories of data (including sensitive) on a register and draft a data retention schedule • Assign access privilege to databases and network drives containing personal or sensitive data – need to access only if handling personal data on a need to know basis • Check Cloud Service Provider’s contract to ensure it delivers the same level of availability, security and confidentiality (data centres should be listed and transfers prohibited outside EEA unless specific measures in place to allow that transfer) Data Protection and GDPR - Storage Elizabeth Dunne Consultancy Services 2018
  • 12. • Personal and Sensitive information should only be used for the purpose it was collected for • Any new or further use must be consented to by the data subject, whether consent was obtained originally or not for the data • Data subjects have rights: to access, object to processing, rectification, erasure, porting and to withdraw consent – during use of data. Staff generally have a right to their HR file and its contents subject to reasonable considerations. • Ensure you have DSAR procedure in place where changes to data use occurs • Review use of data sets regularly to make sure they’re not outdated or inaccurate Data Protection and GDPR - Usage Elizabeth Dunne Consultancy Services 2018
  • 13. • Know how your data subject’s personal information is shared: – Within the organisation – With 3rd parties • Who has access within the organisation? Ensure you know what they are doing with it (copying it / using emails for other purposes / storing it?). • Data subjects are entitled to know with whom their data is disclosed to in particular, 3rd parties processing on your behalf. • You must have a contract in place with 3rd parties who process data on your behalf – employee, users and supplier data. • For example: cloud services, payroll (staff data). • They must follow your instructions and never share personal data with others or use it for their own purposes. • Statutory obligations and sharing of data e.g. department of social protection, revenue, other gov agencies. Data Protection and GDPR - Sharing Elizabeth Dunne Consultancy Services 2018
  • 14. • Data must only be kept for the purpose it was collected for and disposed of when it is not needed. • Have a retention and disposal period for different categories of data. • Be careful of archiving personal data as it is amenable to the GDPR and the Data Protection Act 2018 • Have retention periods for client and staff personal data • Choose a disposal method: shredding for paper files (secure) and purging of systems for electronic / networks; destruction of hard drives. • If you use third parties to process data make sure they have your retention and disposal rules in place Data Protection and GDPR - Disposal Elizabeth Dunne Consultancy Services 2018
  • 15. • Name • National identifiers (e.g., passport I.D) sensitive • Personal e-mail address / work email • Personal identification numbers (PIN) or passwords • Personal interests derived from tracking use of internet web sites • Sexual life, marriage status, political opinions sensitive • Personal telephone number • Photograph or video identifiable to a natural person sensitive • Product and service preferences • Racial or ethnic origin Religious or philosophical beliefs Sexual orientation Trade-union membership sensitive • Utility bills Data Protection and GDPR – Types of personal data Elizabeth Dunne Consultancy Services 2018
  • 16. • Age or special needs of vulnerable natural persons sensitive • Allegations of criminal conduct sensitive • Any information collected during health services sensitive • Bank account or credit card number • Biometric identifier and fingerprint data sensitive • Credit card statements • Criminal convictions or committed offences sensitive • Criminal investigation reports sensitive • Customer number • Date of birth • Diagnostic health information sensitive • Disabilities sensitive Data Protection and GDPR – Types of personal data Elizabeth Dunne Consultancy Services 2018
  • 17. • Doctor bills • Employees’ salaries and human resources files (sensitive when containing medical data or other sensitive categories) • Financial profile • Gender sensitive • GPS position • GPS trajectories • Home address • IP address Location derived from telecommunications systems • Medical history sensitive Data Protection and GDPR – Types of personal data Elizabeth Dunne Consultancy Services 2018
  • 18. • Privacy Website Notice Purpose: • Your website is where people go to find details of your services and GDPR requires data subjects know the following: • A transparent description of: • Who you are and contact details of person / email to deal with data protection issues • Types of data collected • Legal basis for collection and processing • Who it is disclosed to and how long you keep it • How data subjects can exercise their rights • Use of cookies and other tracking devices • Transfer of data outside of the EEA • Be in plain easy to understand language Demonstrating Compliance - Policies and Procedures Website Privacy Notice Public Facing Elizabeth Dunne Consultancy Services 2018
  • 19. Elizabeth Dunne Consultancy Services 2018 Data Breach Protocol Data Breach Protocol and Form (log) purpose: • Identify team members to co-ordinate breach response • 72 hour window for notifiable breaches • No automatic notification of data subject • In general, a data breach will require notification to the DPC if the data includes: – the possibility of harm to the data subjects – a large volume of personal data – sensitive data (e.g. financial (loss of financial information can be detrimental) or health information or other sensitive information – If employee data is compromised, this must be included. It is not just service user or supplier data – DPC may advise if the data subject should be notified • Identify weaknesses / risks in organisations leading to a breach • Identify security risks and how they can be mitigated
  • 20. Types of breaches include (most common): • loss or theft of paperwork; • data posted or sent to the wrong recipient; • data sent by email to the wrong recipient; • insecure webpage access (hacking); • loss or theft of unencrypted device. • If in doubt as to whether a situation involves a breach consult with a member of the breach management Team. Data Breach Log: • Record of reportable and non reportable breaches • Near misses • https://dataprotection.ie/docs/Breach-Notification-Form/m/1726.htm Elizabeth Dunne Consultancy Services 2018 Data Breach Protocol
  • 21. Elizabeth Dunne Consultancy Services 2018 Data Subject Access Request and Form Data Subject Access Protocol and Form purpose: Service users, employees and suppliers have the right: • to ask for details of their personal data held • to ask for a copy of their personal data • to have any inaccurate or misleading data rectified, corrected and erased • to restrict the processing of their personal data in certain circumstances • to object to the processing of their personal data • to transfer their personal data to a third party • a right not to be subject to automated decision making • the right to receive notification of a data breach • the right to lodge a complaint to the Data Protection Commissioner.
  • 22. • Application made in writing • Using a Data Subject Access Form – post or email it • You cannot compel use of the Form but helps narrow down information requested • No charge (repeals 1988 and 2003 position) • 2 working days to acknowledge receipt (not prescribed by legislation) • 30 days to respond (can be extended to 2 months) • No third party information – only information relating to data subject – disclosure of third party information is a breach • Must verify identity of requester • Begin processing the request but wait on verification • Agents may apply on behalf of a data subject but verify their identity • Never allow anyone force you into revealing personal information Elizabeth Dunne Consultancy Services 2018 Data Subject Access Request and Form
  • 23. Data Protection Policy - Staff Elizabeth Dunne Consultancy Services 2018 • Data Protection Policy (Staff) Purpose: • Employees should be aware of both their rights and obligations around data protection: • A description of: • contact details of person / email to deal with data protection issues arising for staff • Types of data collected relating to employment • Reasons for collection and processing including sensitive data or other data collected employees might not be aware of • Who employee data is disclosed to and how long you keep it • How employees can exercise their rights • A statement of expectations for staff around data handling and management of data.
  • 24. Elizabeth Dunne Consultancy Services 2018 Data Retention Policy • Data Retention Policy Purpose: • Set out the document management and retention schedule. • A description of: • protocol for the management of all records • Storage, management and destruction methods • Responsibility around management of soft copy and hard copy data • Schedule of documents and retention periods relevant to each area: Personnel Files (HR), Corporate Records, Client and Service user records. • Miscellaneous other records. • Most have statutory time periods but others are kept where a business need arises or where retention relies on other bodies / statutory agencies to which you are affiliated. • Justification of time periods should be made where possible.
  • 25. Questions and Answers Elizabeth Dunne Consultancy Services 2018