SlideShare a Scribd company logo
1 of 16
Download to read offline
IRIS Customer Conference
GDPR – Game Changing Legislation
Will Richmond-Coggan, Pitmans Law
27 March 2018
GDPR – Game Changing Legislation
We’re lawyers, so we always start with a disclaimer.
The guidance that follows is in the nature of general information about
the subject matter concerned – it is invariably the case that detailed
legal advice requires a lot of fact-sensitive information that we will not
have while discussing points today. As such, no reliance should be
placed on the guidance given in this talk without first taking such
detailed advice.
Nevertheless, feel free to ask questions, even those embarrassing
ones on behalf of your “friend” who couldn’t make it – it will help us to
make sure that the content is as relevant as possible!
General overview – this talk
I am going to cover as much of the following as
possible!
• An introduction to key concepts / main changes
• Outlining a roadmap to GDPR readiness
• The data subject’s rights
Core Concept – Personal data
• Now includes identification numbers, location, online identifiers
and factors specific to the individual's physical, physiological,
genetic, mental, economic, cultural or social identity.
• Still includes information about activities when linked to an
identifier
• Sensitive data now includes genetic and biometric data
• Criminal records now occupy a separate category and are
treated distinctly
Core Concept – Lawful processing
• Contract – necessary for the formation or performance of
a contract between the controller and subject
• Obligation – necessary for performance of a legal
obligation, or discharge of a statutory function
• Vital interests – to protect the vital interests of the data
subject or someone else
• Legitimate interests – of the data processor and
controller, but only where other rights aren’t affected
Lawful processing (cont.) – Consent
• Consent must be freely given, specific, informed and
unambiguous by “some form of clear affirmative action”
• It cannot be signified by inaction, silence or be a pre-
condition to other actions
• It must be as easy for a subject to withdraw consent as
to give it – form and substance
• Remember that processing under consent gives the data
subject wider rights than other lawfulness gateways
General overview – the legislation
Key game-changers brought in by GDPR:
• Direct accountability of data processors
• Data controller/processor distinction
• Limited scope to re-allocate risk contractually
• Territorial extent
• The “Global” Data Protection Regulation?
• Third countries – nomination of a data regulator
• And (of course) Brexit!
General overview – the legislation
Key game-changers brought in by GDPR:
• Breach notification and record keeping
• “Accountability principle” – document intensive
• Mandatory notification – data regulator
• Mandatory notification – data subjects
• Consequences are broader
• Wider fines – the greater of EUR 10m or 2% of global group
turnover for “minor” issues, it’s 4% / EUR 20m for major ones!
• ICO audits; data subject compensation; reputation
Get ready with… D… P… R…
Roadmap - Data discovery
Headline points:
• What is “personal data”
• Identification of an individual or information about activities
• Where should the data be located…
• Think about local drives, servers, cloud services, portable
• …where else is it actually…
• Think about personal devices, webmail, pen drives, offshore
• …and data flows
• Internal/external, compliant processing chains, cross-border
Roadmap – Policies for compliance
Headline points:
• Compliance with standards
• e.g. Cyber-Essentials, ISO 27001, BS 10012:2017
• GDPR-specific procedures
• Consent management, privacy protection systems, notifications
• Policy and process review
• System capabilities, gap analysis, develop and implement
• Training and awareness at all levels
• “Baked in” compliance – privacy by design and by default
Roadmap – Record keeping
Headline points:
• Accountability principle
• Have to be able to “show” as well as “do”
• Records are essential
• Of data held, decisions taken, policies and procedures
• ICO ability to audit
• Including onsite inspection and requiring delivery of information
• As part of a supply chain
• Accountability up and down the chain
Processes – Risk assessment
• Identify each of the processes of your business which
engage personal data
• Do you process as controller or processor – what is the
lawfulness gateway?
• Is the processing proportionate to the objectives?
• What measures of safeguarding are appropriate –
anonymisation/pseudonymisation; encryption;
permissions; policies
Processes – Breach notification
• Now mandatory for breaches: “leading to the destruction,
loss, alteration, unauthorised disclosure of, or access to,
personal data”
• Notification must be made within 72 hours of detection
• Data subjects must also be notified “without undue
delay” where the breach poses a high risk to their rights
• Think about the steps that will need to be taken in those
72 hours – processes need to be in place already
The Data Subject’s Journey
Inform
Access Rectify
Restrict Transfer
Object Erase
With Pitmans Law you can be assured of the quality of advice and service
you demand from a city law firm – but with a distinction. The courage to stand apart, to
think and act personably, with an uncompromising focus on achieving outstanding client
outcomes. We say what we mean, matching our behaviours to our words.
Established for over 150 years, Pitmans Law is headquartered in Reading with offices in
London and Southampton. The lower overheads of a regional office ensure we can
provide city quality legal advice at a competitive price to deliver exceptional value for our
corporate and private clients locally, nationally and internationally.
Pitmans provides legal advice to address our clients’ needs across a wide range
of industry sectors and specialisms including particularly strong specialist teams in
pensions advisory, real estate, dispute resolution as well as corporate and commercial
law. Our clients draw confidence from the top tier recognition Pitmans achieves in the
industry benchmarking directories, Legal 500 and Chambers UK.
Reading, London, Southampton
Pitmans Law is the founding UK member firm of the global legal network, Interact Law.
Contact us
T +44 (0)345 222 9222
E law@pitmans.com

More Related Content

What's hot

Optimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digitalOptimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digitalChristiana Kozakou
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)Bright
 
Csa privacy by design & gdpr austin chambers 11-4-17
Csa   privacy by design & gdpr austin chambers 11-4-17Csa   privacy by design & gdpr austin chambers 11-4-17
Csa privacy by design & gdpr austin chambers 11-4-17Trish McGinity, CCSK
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceCILIPScotland
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesDimitri Sirota
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketingSpotler
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...Ardoq
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality Susan Moran
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for developmentTomppa Järvinen
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashedChris Gilmour
 
Human resources: protecting confidentiality
Human resources: protecting confidentiality Human resources: protecting confidentiality
Human resources: protecting confidentiality KelbySchwender
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers networkBart Van Den Brande
 

What's hot (20)

Optimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digitalOptimize your info-driven business processes. How to move from paper to digital
Optimize your info-driven business processes. How to move from paper to digital
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)
 
Csa privacy by design & gdpr austin chambers 11-4-17
Csa   privacy by design & gdpr austin chambers 11-4-17Csa   privacy by design & gdpr austin chambers 11-4-17
Csa privacy by design & gdpr austin chambers 11-4-17
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library Service
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
 
Data Privacy & Security
Data Privacy & SecurityData Privacy & Security
Data Privacy & Security
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
S719a
S719aS719a
S719a
 
Human resources: protecting confidentiality
Human resources: protecting confidentiality Human resources: protecting confidentiality
Human resources: protecting confidentiality
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers network
 

Similar to Game changing legislation

#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance Dovetail Software
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Global Data Privacy Regulation
Global Data Privacy RegulationGlobal Data Privacy Regulation
Global Data Privacy RegulationJatin Kochhar
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?Jatin Kochhar
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 

Similar to Game changing legislation (20)

#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Global Data Privacy Regulation
Global Data Privacy RegulationGlobal Data Privacy Regulation
Global Data Privacy Regulation
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?
 
13687562.ppt
13687562.ppt13687562.ppt
13687562.ppt
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPRforum London
GDPRforum LondonGDPRforum London
GDPRforum London
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 

More from IRIS

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS
 
HMRC
HMRCHMRC
HMRCIRIS
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdprIRIS
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burdenIRIS
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedIRIS
 
Happy clients happy compliance
Happy clients happy complianceHappy clients happy compliance
Happy clients happy complianceIRIS
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anywayIRIS
 

More from IRIS (10)

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital Economy
 
HMRC
HMRCHMRC
HMRC
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdpr
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint hearted
 
Happy clients happy compliance
Happy clients happy complianceHappy clients happy compliance
Happy clients happy compliance
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
 

Recently uploaded

CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual serviceanilsa9823
 
The Economic History of the U.S. Lecture 23.pdf
The Economic History of the U.S. Lecture 23.pdfThe Economic History of the U.S. Lecture 23.pdf
The Economic History of the U.S. Lecture 23.pdfGale Pooley
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escortsranjana rawat
 
Stock Market Brief Deck (Under Pressure).pdf
Stock Market Brief Deck (Under Pressure).pdfStock Market Brief Deck (Under Pressure).pdf
Stock Market Brief Deck (Under Pressure).pdfMichael Silva
 
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure serviceWhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure servicePooja Nehwal
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...ssifa0344
 
The Economic History of the U.S. Lecture 25.pdf
The Economic History of the U.S. Lecture 25.pdfThe Economic History of the U.S. Lecture 25.pdf
The Economic History of the U.S. Lecture 25.pdfGale Pooley
 
The Economic History of the U.S. Lecture 20.pdf
The Economic History of the U.S. Lecture 20.pdfThe Economic History of the U.S. Lecture 20.pdf
The Economic History of the U.S. Lecture 20.pdfGale Pooley
 
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Delhi Call girls
 
Instant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School SpiritInstant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School Spiritegoetzinger
 
Booking open Available Pune Call Girls Wadgaon Sheri 6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Wadgaon Sheri  6297143586 Call Hot Ind...Booking open Available Pune Call Girls Wadgaon Sheri  6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Wadgaon Sheri 6297143586 Call Hot Ind...Call Girls in Nagpur High Profile
 
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service NashikHigh Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service NashikCall Girls in Nagpur High Profile
 
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130Suhani Kapoor
 
The Economic History of the U.S. Lecture 26.pdf
The Economic History of the U.S. Lecture 26.pdfThe Economic History of the U.S. Lecture 26.pdf
The Economic History of the U.S. Lecture 26.pdfGale Pooley
 
Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )
Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )
Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )Pooja Nehwal
 
The Economic History of the U.S. Lecture 30.pdf
The Economic History of the U.S. Lecture 30.pdfThe Economic History of the U.S. Lecture 30.pdf
The Economic History of the U.S. Lecture 30.pdfGale Pooley
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignHenry Tapper
 
The Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdfThe Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdfGale Pooley
 

Recently uploaded (20)

CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
 
The Economic History of the U.S. Lecture 23.pdf
The Economic History of the U.S. Lecture 23.pdfThe Economic History of the U.S. Lecture 23.pdf
The Economic History of the U.S. Lecture 23.pdf
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
 
Stock Market Brief Deck (Under Pressure).pdf
Stock Market Brief Deck (Under Pressure).pdfStock Market Brief Deck (Under Pressure).pdf
Stock Market Brief Deck (Under Pressure).pdf
 
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure serviceWhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
 
(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7
(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7
(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7
 
The Economic History of the U.S. Lecture 25.pdf
The Economic History of the U.S. Lecture 25.pdfThe Economic History of the U.S. Lecture 25.pdf
The Economic History of the U.S. Lecture 25.pdf
 
The Economic History of the U.S. Lecture 20.pdf
The Economic History of the U.S. Lecture 20.pdfThe Economic History of the U.S. Lecture 20.pdf
The Economic History of the U.S. Lecture 20.pdf
 
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
 
Instant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School SpiritInstant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School Spirit
 
Booking open Available Pune Call Girls Wadgaon Sheri 6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Wadgaon Sheri  6297143586 Call Hot Ind...Booking open Available Pune Call Girls Wadgaon Sheri  6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Wadgaon Sheri 6297143586 Call Hot Ind...
 
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service NashikHigh Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
 
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
 
The Economic History of the U.S. Lecture 26.pdf
The Economic History of the U.S. Lecture 26.pdfThe Economic History of the U.S. Lecture 26.pdf
The Economic History of the U.S. Lecture 26.pdf
 
Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )
Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )
Vip Call US 📞 7738631006 ✅Call Girls In Sakinaka ( Mumbai )
 
The Economic History of the U.S. Lecture 30.pdf
The Economic History of the U.S. Lecture 30.pdfThe Economic History of the U.S. Lecture 30.pdf
The Economic History of the U.S. Lecture 30.pdf
 
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaign
 
The Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdfThe Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdf
 

Game changing legislation

  • 1. IRIS Customer Conference GDPR – Game Changing Legislation Will Richmond-Coggan, Pitmans Law 27 March 2018
  • 2. GDPR – Game Changing Legislation We’re lawyers, so we always start with a disclaimer. The guidance that follows is in the nature of general information about the subject matter concerned – it is invariably the case that detailed legal advice requires a lot of fact-sensitive information that we will not have while discussing points today. As such, no reliance should be placed on the guidance given in this talk without first taking such detailed advice. Nevertheless, feel free to ask questions, even those embarrassing ones on behalf of your “friend” who couldn’t make it – it will help us to make sure that the content is as relevant as possible!
  • 3. General overview – this talk I am going to cover as much of the following as possible! • An introduction to key concepts / main changes • Outlining a roadmap to GDPR readiness • The data subject’s rights
  • 4. Core Concept – Personal data • Now includes identification numbers, location, online identifiers and factors specific to the individual's physical, physiological, genetic, mental, economic, cultural or social identity. • Still includes information about activities when linked to an identifier • Sensitive data now includes genetic and biometric data • Criminal records now occupy a separate category and are treated distinctly
  • 5. Core Concept – Lawful processing • Contract – necessary for the formation or performance of a contract between the controller and subject • Obligation – necessary for performance of a legal obligation, or discharge of a statutory function • Vital interests – to protect the vital interests of the data subject or someone else • Legitimate interests – of the data processor and controller, but only where other rights aren’t affected
  • 6. Lawful processing (cont.) – Consent • Consent must be freely given, specific, informed and unambiguous by “some form of clear affirmative action” • It cannot be signified by inaction, silence or be a pre- condition to other actions • It must be as easy for a subject to withdraw consent as to give it – form and substance • Remember that processing under consent gives the data subject wider rights than other lawfulness gateways
  • 7. General overview – the legislation Key game-changers brought in by GDPR: • Direct accountability of data processors • Data controller/processor distinction • Limited scope to re-allocate risk contractually • Territorial extent • The “Global” Data Protection Regulation? • Third countries – nomination of a data regulator • And (of course) Brexit!
  • 8. General overview – the legislation Key game-changers brought in by GDPR: • Breach notification and record keeping • “Accountability principle” – document intensive • Mandatory notification – data regulator • Mandatory notification – data subjects • Consequences are broader • Wider fines – the greater of EUR 10m or 2% of global group turnover for “minor” issues, it’s 4% / EUR 20m for major ones! • ICO audits; data subject compensation; reputation
  • 9. Get ready with… D… P… R…
  • 10. Roadmap - Data discovery Headline points: • What is “personal data” • Identification of an individual or information about activities • Where should the data be located… • Think about local drives, servers, cloud services, portable • …where else is it actually… • Think about personal devices, webmail, pen drives, offshore • …and data flows • Internal/external, compliant processing chains, cross-border
  • 11. Roadmap – Policies for compliance Headline points: • Compliance with standards • e.g. Cyber-Essentials, ISO 27001, BS 10012:2017 • GDPR-specific procedures • Consent management, privacy protection systems, notifications • Policy and process review • System capabilities, gap analysis, develop and implement • Training and awareness at all levels • “Baked in” compliance – privacy by design and by default
  • 12. Roadmap – Record keeping Headline points: • Accountability principle • Have to be able to “show” as well as “do” • Records are essential • Of data held, decisions taken, policies and procedures • ICO ability to audit • Including onsite inspection and requiring delivery of information • As part of a supply chain • Accountability up and down the chain
  • 13. Processes – Risk assessment • Identify each of the processes of your business which engage personal data • Do you process as controller or processor – what is the lawfulness gateway? • Is the processing proportionate to the objectives? • What measures of safeguarding are appropriate – anonymisation/pseudonymisation; encryption; permissions; policies
  • 14. Processes – Breach notification • Now mandatory for breaches: “leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data” • Notification must be made within 72 hours of detection • Data subjects must also be notified “without undue delay” where the breach poses a high risk to their rights • Think about the steps that will need to be taken in those 72 hours – processes need to be in place already
  • 15. The Data Subject’s Journey Inform Access Rectify Restrict Transfer Object Erase
  • 16. With Pitmans Law you can be assured of the quality of advice and service you demand from a city law firm – but with a distinction. The courage to stand apart, to think and act personably, with an uncompromising focus on achieving outstanding client outcomes. We say what we mean, matching our behaviours to our words. Established for over 150 years, Pitmans Law is headquartered in Reading with offices in London and Southampton. The lower overheads of a regional office ensure we can provide city quality legal advice at a competitive price to deliver exceptional value for our corporate and private clients locally, nationally and internationally. Pitmans provides legal advice to address our clients’ needs across a wide range of industry sectors and specialisms including particularly strong specialist teams in pensions advisory, real estate, dispute resolution as well as corporate and commercial law. Our clients draw confidence from the top tier recognition Pitmans achieves in the industry benchmarking directories, Legal 500 and Chambers UK. Reading, London, Southampton Pitmans Law is the founding UK member firm of the global legal network, Interact Law. Contact us T +44 (0)345 222 9222 E law@pitmans.com