SlideShare une entreprise Scribd logo
1  sur  7
Télécharger pour lire hors ligne
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   1
RE: European Union General Data Protection Regulation (GDPR) Checklist
Greetings,
Our firm has prepared an overview of the General Data Protection Regulation that was
approved by the European Commission in April 2016. As of today’s date, this regulation has yet to
go into effect, but companies will have to be in full compliance by 2018.
As our firm gets further information about the approval and implementation of this
regulatory regime, an update to the EU Data Privacy Directive of 1995, our firm is ready to work
with your company to execute the proper procedures for compliance.
The GDPR imposes enhanced requirements on all businesses operating in the EU, which
includes those processing personal data in the EU and transferring data from the EU. It aims to
create a more consistent data protection regime, while providing EU citizens better control over
the use of their information by creating new rights.
The following is a checklist of items that serves as a guideline for what companies have to
do before 2018 to ensure GDPR compliance. Gagnier Margossian LLP is advising its current and
potential clients to begin this compliance implementation alongside compliance with other legal
changes in the European Union in the wake of the Schrems decision in October 2015 and the
prospective EU-U.S. Privacy Shield program (yet to be approved and details for compliance yet to
be released).
Item Compliance
Status
1. Assess the risk and identify areas that could cause compliance problems under
the GDPR.
-­‐ Fines for non-compliance can be up to 20 million Euros or 4% of the
company’s annual global turnover.
-­‐ Additionally, collective actions can be filed by consumer associations.
2. Make sure to document:
-­‐ The personal data the company holds/collects;
-­‐ Where the information came from;
-­‐ Where the information is stored;
-­‐ How the information is processed;
-­‐ How the information it protected; and
-­‐ With whom it is shared (annual audits are now a necessity for
recordkeeping).
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   2
3. Maintain detailed records of the processing performed on personal data. This
must include:
-­‐ Determining the types of data processing being carried out;
-­‐ Identifying the basis for carrying it out; and
-­‐ Documenting the basis.
-­‐ The company will have to explain their legal basis for processing data in their
privacy notice and when they respond to a subject access request.
4. Evaluate the company’s policies and procedures to ensure they take into
account all the rights individuals have under the GDPR, including the:
-­‐ Right to access information;
-­‐ Right to correct inaccuracies;
-­‐ Right to have information erased (the right to be forgotten) without undue
delay; and
-­‐ Right to withdraw consent at any time, which must be an easy to access
process.
5. Companies must also:
-­‐ Prevent direct marketing;
-­‐ Prevent automated decision-making and profiling; and
-­‐ Provide data electronically and in a commonly used format (data portability).
6. Draft or revise security policies, which should include implementing appropriate
technical and organizational measures, taking into account the nature, scope,
context and purposes for processing as well as the risk of varying likelihood and
severity for the rights and freedoms of individuals. Security actions may include:
-­‐ The pseudonymisation and encryption of personal data;
-­‐ The ability to ensure the ongoing confidentiality, integrity, availability and
resilience of systems and services processing personal data;
-­‐ The ability to restore the availability and access to data in a timely manner in
the event of a physical or technical incident; and
-­‐ A process for regularly testing, assessing and evaluating the effectiveness of
technical and organizational measure for ensuring the security of the
processing.
-­‐ NOTE: Controllers or processors that adhere to either an approved code of
conduct or an approved certification mechanism can use these tools to
demonstrate compliance with the GDPR’s security standards.
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   3
7. Ensure procedures are in place to continually monitor compliance with these
policies, including the security policies, prior to, during and after processing of
personal data.
-­‐ Additionally, perform a gap assessment and consider participation in
certification programs.
8. Before collecting personal data, the company must disclose:
-­‐ The identity of the controller;
-­‐ The purposes for processing;
-­‐ Any recipients of personal data; and
How long the data will be stored.
-­‐ Disclosures must be intelligible and easily accessible, using clear and plain
language.
9. Additionally, the company must inform data subjects of their:
-­‐ Right to withdraw consent at any time;
-­‐ Right to request access, rectification or restriction of processing; and
-­‐ Right to lodge a complaint to a supervisory authority.
10. Review how the company is seeking, obtaining and recording consent. The
company must comply with the following requirements.
-­‐ Consent must be “freely given, specific, informed and unambiguous (opt in),”
or it is explicit (the higher standard). This should include assessing whether
the company’s audit trail for such consent is effective and whether they need
to make any changes. Consent must be referenced in the company Privacy
Policy.
o Consent is not freely given if there is a clear imbalance between the
data subject and the controller, in particular, where the controller is a
public authority.
o Additionally, the controller cannot make a service conditional upon
consent, unless the processing is necessary for the service.
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   4
-­‐ To show consent, the data subject must signal agreement by “a statement or
clear affirmative action.”
-­‐ Consent must be specific to each data processing operations.
-­‐ Data subjects must be informed about their right to withdraw consent at
anytime, before they give their consent.
-­‐ The controller must provide “accurate and full information on all relevant
issues,” including the nature of the data that will be process, the purposes of
processing, the identity of the controller and the identity of any other
recipients of the data.
-­‐ Your company’s customers should explicitly reference use of your company’s
platform and technologies in their policies. This is a reliable means to put the
public on Notice and ensure Consent at this juncture.
11. Review current privacy notices and make necessary changes to include the
additional communication requirements to individuals on:
-­‐ The legal basis for processing data;
-­‐ The data retention periods; and
-­‐ The individual’s right to complain if the individual believes the data is being
mishandled.
12. Update the company’s procedures and/or amend retention policies if necessary
to comply with GDPR requirements, including:
-­‐ Privacy policies are easily accessible, written in clear and plain language, and
include full disclosure of your data collection and processing;
-­‐ Disclosure of data retention policies;
-­‐ Respect to access requests within a month; and
-­‐ Allow individuals to correct inaccurate information about them.
13. The company should conduct a thorough data privacy impact assessment where
data processing operations may lead to high risks to data subjects’ personal data.
-­‐ The company should refer and implement the provisions of the Information
Commissioners Office’s guidance on Privacy Impact Assessments.
14. Ensure the company has proper procedures in place to detect, report and
investigate a data breach in which individuals are likely to suffer some form of
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   5
damage. To comply with this requirement, the company should do the following:
-­‐ Assess the types of data the company holds;
-­‐ Document which type of data would trigger notice if there was a breach;
and
-­‐ Develop appropriate policies and procedures.
15. The company must comply with the following notification requirements when a
breach occurs:
-­‐ If a data processor experiences a personal data breach, it must notify the
controller but otherwise has no other notification or reported obligation
under the GDPR.
-­‐ If a breach occurs the company (controller) is required to notify privacy
regulators of the data breach within seventy-two (72) hours after the breach
is discovered.
o If notification is not made within seventy-two (72) hours, the
controller must provide a “reasoned justification” for the delay.
o There is an exception to the supervisory authority notification
requirement that states notice is not required if the personal data
breach is unlikely to result in a risk for the rights and freedoms of
individuals.
-­‐ When notifying the supervisory authority, the notification must:
• Describe the nature of the personal data breach, including the number
and categories of data subjects and data records affected;
• Provide the data protection officer’s contact information;
• Describe the likely consequences of the personal data breach; and
• Describe how the controller proposes to address the breach, including
any mitigation efforts.
16. Data subjects will also need to be notified “without undue delay” where a
breach poses a high risk to the data subject’s rights and freedoms. However,
there is an exception to the requirement to notify data subjects in the following
circumstances:
o The controller has “implemented appropriate technical and
organizational protection measures” that “render the data
unintelligible to any person who is not authorized to access it, such as
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   6
encryption;”
o The controller takes actions subsequent to the personal data breach
to “ensure that the high risk for the rights and freedoms of data
subjects” is unlikely to materialize; or
o When notification to each data subject would “involve
disproportionate effort,” in which case alternative communication
measures may be used.
17. Limit data collection to the minimum necessary (data minimization) and adopt a
“privacy by design” approach to projects, which promotes privacy and data
protection compliance from the beginning.
-­‐ Ensure the company collects the minimum amount of personal data
necessary for the proper performance of the products and services.
18. Controllers and Processors of personal information must designate a Data
Protection Officer (DPO) when:
-­‐ The processing is carried out by a public authority or body; or
-­‐ The controller’s or processor’s core activities require regular and systematic
monitoring of data subjects on a large scale or consist of “processing on a
large scale of special categories of data.”
19. The DPO must be “designated on the basis of professional qualities and, in
particular, expert knowledge of data protection law and practices.”
The DPO must have the authority and independence to inform the company of
its obligations under GDPR, and must have the ability to fulfill the tasks
designated, such as regulatory compliance, training staff on proper data handling
and coordinating with the supervisory authority, with an ability to understand
and balance data processing risks.
The DPO also needs to monitor compliance and conduct internal audits.
The DPO will be the company’s point of contact for data subjects’ inquiries,
withdrawals of consent, right to be forgotten requests and other related rights.
NOTE: Our law firm will be providing these services to companies.
20. Consider putting systems in place to verify individuals’ ages and to gather
224 Townsend Street
San Francisco, CA 94107
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
  
	
   7
parental or guardian consent for any data processing activity involving children
under thirteen (13) years of age. If such information is involved, the privacy
notice will need to be drafted in a manner understandable by children.
21. Review Binding Corporate Rules (BCRs) or Standard Contractual Clauses
(SCCs) for trans-Atlantic data flows for compliance with new requirements of
GDPR.
Draft addendums to SCCs and other contracts as necessary to address the
onward transfer restrictions, which includes ensuring that downstream entities
comply with limitations on purpose and meet all the requirements, including
remediating any unauthorized processing by the downstream entity.
Contact Gagnier Margossian today to discuss how we can help
with your international privacy compliance.
Christina Gagnier
Managing Partner, Internet. Intellectual Property & Technology
gagnier@gamallp.com
909.493.6447

Contenu connexe

Tendances

Tendances (20)

An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
CCPA for CISOs: What You Need to Know
CCPA for CISOs: What You Need to KnowCCPA for CISOs: What You Need to Know
CCPA for CISOs: What You Need to Know
 
GDPR
GDPRGDPR
GDPR
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Is Ukraine safe for software development outsourcing?
Is Ukraine safe for software development outsourcing? Is Ukraine safe for software development outsourcing?
Is Ukraine safe for software development outsourcing?
 
Anti-Bribery Forensics and Compliance on a Multi-National Scale: Challenges a...
Anti-Bribery Forensics and Compliance on a Multi-National Scale: Challenges a...Anti-Bribery Forensics and Compliance on a Multi-National Scale: Challenges a...
Anti-Bribery Forensics and Compliance on a Multi-National Scale: Challenges a...
 
"If we're leaving the EU, does GDPR even matter?" And other FAQs
"If we're leaving the EU, does GDPR even matter?" And other FAQs"If we're leaving the EU, does GDPR even matter?" And other FAQs
"If we're leaving the EU, does GDPR even matter?" And other FAQs
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
GDPR 12 Steps infographic
GDPR 12 Steps infographic GDPR 12 Steps infographic
GDPR 12 Steps infographic
 
General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018
 
12 steps to prepare for GDPR
12 steps to prepare for GDPR12 steps to prepare for GDPR
12 steps to prepare for GDPR
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 

Similaire à European Union Privacy Law - General Data Protection Regulation Checklist

New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
Ulf Mattsson
 

Similaire à European Union Privacy Law - General Data Protection Regulation Checklist (20)

European Union General Data Protection Regulation (GDPR) Checklist
European Union General Data Protection Regulation (GDPR) ChecklistEuropean Union General Data Protection Regulation (GDPR) Checklist
European Union General Data Protection Regulation (GDPR) Checklist
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Top 10 GDPR Requirements
Top 10 GDPR RequirementsTop 10 GDPR Requirements
Top 10 GDPR Requirements
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPR
 
EU Privacy Shield Self Certification
EU Privacy Shield Self Certification EU Privacy Shield Self Certification
EU Privacy Shield Self Certification
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Data protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdData protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and Bird
 
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdfData Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 

Plus de Christina Gagnier

Plus de Christina Gagnier (20)

The United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsThe United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin Offerings
 
Regulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarRegulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in Gibraltar
 
China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"
 
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaInitial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
 
Conducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsConducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and Considerations
 
SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017
 
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
 
Student Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomStudent Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the Classroom
 
Gender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsGender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All Students
 
ABC's of Privacy and Security
ABC's of Privacy and SecurityABC's of Privacy and Security
ABC's of Privacy and Security
 
Starting a Business: The Legal Details
Starting a Business: The Legal DetailsStarting a Business: The Legal Details
Starting a Business: The Legal Details
 
GAMABrief: What Every School Needs to Know About Copyright Law
GAMABrief: What Every School Needs to Know About Copyright LawGAMABrief: What Every School Needs to Know About Copyright Law
GAMABrief: What Every School Needs to Know About Copyright Law
 
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
 
GAMABrief: Preparing for the Capital Gains Tax Hike
GAMABrief: Preparing for the Capital Gains Tax HikeGAMABrief: Preparing for the Capital Gains Tax Hike
GAMABrief: Preparing for the Capital Gains Tax Hike
 
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
 
Revenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentRevenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without Consent
 
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
 
Seth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingSeth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" Bullying
 
Student Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomStudent Privacy Rights in the Classroom
Student Privacy Rights in the Classroom
 
Employees, Employers & Social Media
Employees, Employers & Social MediaEmployees, Employers & Social Media
Employees, Employers & Social Media
 

Dernier

PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
ca2or2tx
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
bd2c5966a56d
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
ShashankKumar441258
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
PoojaGadiya1
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
SS A
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
SS A
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
MollyBrown86
 

Dernier (20)

589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labour
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
 
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
 

European Union Privacy Law - General Data Protection Regulation Checklist

  • 1. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     1 RE: European Union General Data Protection Regulation (GDPR) Checklist Greetings, Our firm has prepared an overview of the General Data Protection Regulation that was approved by the European Commission in April 2016. As of today’s date, this regulation has yet to go into effect, but companies will have to be in full compliance by 2018. As our firm gets further information about the approval and implementation of this regulatory regime, an update to the EU Data Privacy Directive of 1995, our firm is ready to work with your company to execute the proper procedures for compliance. The GDPR imposes enhanced requirements on all businesses operating in the EU, which includes those processing personal data in the EU and transferring data from the EU. It aims to create a more consistent data protection regime, while providing EU citizens better control over the use of their information by creating new rights. The following is a checklist of items that serves as a guideline for what companies have to do before 2018 to ensure GDPR compliance. Gagnier Margossian LLP is advising its current and potential clients to begin this compliance implementation alongside compliance with other legal changes in the European Union in the wake of the Schrems decision in October 2015 and the prospective EU-U.S. Privacy Shield program (yet to be approved and details for compliance yet to be released). Item Compliance Status 1. Assess the risk and identify areas that could cause compliance problems under the GDPR. -­‐ Fines for non-compliance can be up to 20 million Euros or 4% of the company’s annual global turnover. -­‐ Additionally, collective actions can be filed by consumer associations. 2. Make sure to document: -­‐ The personal data the company holds/collects; -­‐ Where the information came from; -­‐ Where the information is stored; -­‐ How the information is processed; -­‐ How the information it protected; and -­‐ With whom it is shared (annual audits are now a necessity for recordkeeping).
  • 2. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     2 3. Maintain detailed records of the processing performed on personal data. This must include: -­‐ Determining the types of data processing being carried out; -­‐ Identifying the basis for carrying it out; and -­‐ Documenting the basis. -­‐ The company will have to explain their legal basis for processing data in their privacy notice and when they respond to a subject access request. 4. Evaluate the company’s policies and procedures to ensure they take into account all the rights individuals have under the GDPR, including the: -­‐ Right to access information; -­‐ Right to correct inaccuracies; -­‐ Right to have information erased (the right to be forgotten) without undue delay; and -­‐ Right to withdraw consent at any time, which must be an easy to access process. 5. Companies must also: -­‐ Prevent direct marketing; -­‐ Prevent automated decision-making and profiling; and -­‐ Provide data electronically and in a commonly used format (data portability). 6. Draft or revise security policies, which should include implementing appropriate technical and organizational measures, taking into account the nature, scope, context and purposes for processing as well as the risk of varying likelihood and severity for the rights and freedoms of individuals. Security actions may include: -­‐ The pseudonymisation and encryption of personal data; -­‐ The ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services processing personal data; -­‐ The ability to restore the availability and access to data in a timely manner in the event of a physical or technical incident; and -­‐ A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measure for ensuring the security of the processing. -­‐ NOTE: Controllers or processors that adhere to either an approved code of conduct or an approved certification mechanism can use these tools to demonstrate compliance with the GDPR’s security standards.
  • 3. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     3 7. Ensure procedures are in place to continually monitor compliance with these policies, including the security policies, prior to, during and after processing of personal data. -­‐ Additionally, perform a gap assessment and consider participation in certification programs. 8. Before collecting personal data, the company must disclose: -­‐ The identity of the controller; -­‐ The purposes for processing; -­‐ Any recipients of personal data; and How long the data will be stored. -­‐ Disclosures must be intelligible and easily accessible, using clear and plain language. 9. Additionally, the company must inform data subjects of their: -­‐ Right to withdraw consent at any time; -­‐ Right to request access, rectification or restriction of processing; and -­‐ Right to lodge a complaint to a supervisory authority. 10. Review how the company is seeking, obtaining and recording consent. The company must comply with the following requirements. -­‐ Consent must be “freely given, specific, informed and unambiguous (opt in),” or it is explicit (the higher standard). This should include assessing whether the company’s audit trail for such consent is effective and whether they need to make any changes. Consent must be referenced in the company Privacy Policy. o Consent is not freely given if there is a clear imbalance between the data subject and the controller, in particular, where the controller is a public authority. o Additionally, the controller cannot make a service conditional upon consent, unless the processing is necessary for the service.
  • 4. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     4 -­‐ To show consent, the data subject must signal agreement by “a statement or clear affirmative action.” -­‐ Consent must be specific to each data processing operations. -­‐ Data subjects must be informed about their right to withdraw consent at anytime, before they give their consent. -­‐ The controller must provide “accurate and full information on all relevant issues,” including the nature of the data that will be process, the purposes of processing, the identity of the controller and the identity of any other recipients of the data. -­‐ Your company’s customers should explicitly reference use of your company’s platform and technologies in their policies. This is a reliable means to put the public on Notice and ensure Consent at this juncture. 11. Review current privacy notices and make necessary changes to include the additional communication requirements to individuals on: -­‐ The legal basis for processing data; -­‐ The data retention periods; and -­‐ The individual’s right to complain if the individual believes the data is being mishandled. 12. Update the company’s procedures and/or amend retention policies if necessary to comply with GDPR requirements, including: -­‐ Privacy policies are easily accessible, written in clear and plain language, and include full disclosure of your data collection and processing; -­‐ Disclosure of data retention policies; -­‐ Respect to access requests within a month; and -­‐ Allow individuals to correct inaccurate information about them. 13. The company should conduct a thorough data privacy impact assessment where data processing operations may lead to high risks to data subjects’ personal data. -­‐ The company should refer and implement the provisions of the Information Commissioners Office’s guidance on Privacy Impact Assessments. 14. Ensure the company has proper procedures in place to detect, report and investigate a data breach in which individuals are likely to suffer some form of
  • 5. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     5 damage. To comply with this requirement, the company should do the following: -­‐ Assess the types of data the company holds; -­‐ Document which type of data would trigger notice if there was a breach; and -­‐ Develop appropriate policies and procedures. 15. The company must comply with the following notification requirements when a breach occurs: -­‐ If a data processor experiences a personal data breach, it must notify the controller but otherwise has no other notification or reported obligation under the GDPR. -­‐ If a breach occurs the company (controller) is required to notify privacy regulators of the data breach within seventy-two (72) hours after the breach is discovered. o If notification is not made within seventy-two (72) hours, the controller must provide a “reasoned justification” for the delay. o There is an exception to the supervisory authority notification requirement that states notice is not required if the personal data breach is unlikely to result in a risk for the rights and freedoms of individuals. -­‐ When notifying the supervisory authority, the notification must: • Describe the nature of the personal data breach, including the number and categories of data subjects and data records affected; • Provide the data protection officer’s contact information; • Describe the likely consequences of the personal data breach; and • Describe how the controller proposes to address the breach, including any mitigation efforts. 16. Data subjects will also need to be notified “without undue delay” where a breach poses a high risk to the data subject’s rights and freedoms. However, there is an exception to the requirement to notify data subjects in the following circumstances: o The controller has “implemented appropriate technical and organizational protection measures” that “render the data unintelligible to any person who is not authorized to access it, such as
  • 6. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     6 encryption;” o The controller takes actions subsequent to the personal data breach to “ensure that the high risk for the rights and freedoms of data subjects” is unlikely to materialize; or o When notification to each data subject would “involve disproportionate effort,” in which case alternative communication measures may be used. 17. Limit data collection to the minimum necessary (data minimization) and adopt a “privacy by design” approach to projects, which promotes privacy and data protection compliance from the beginning. -­‐ Ensure the company collects the minimum amount of personal data necessary for the proper performance of the products and services. 18. Controllers and Processors of personal information must designate a Data Protection Officer (DPO) when: -­‐ The processing is carried out by a public authority or body; or -­‐ The controller’s or processor’s core activities require regular and systematic monitoring of data subjects on a large scale or consist of “processing on a large scale of special categories of data.” 19. The DPO must be “designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices.” The DPO must have the authority and independence to inform the company of its obligations under GDPR, and must have the ability to fulfill the tasks designated, such as regulatory compliance, training staff on proper data handling and coordinating with the supervisory authority, with an ability to understand and balance data processing risks. The DPO also needs to monitor compliance and conduct internal audits. The DPO will be the company’s point of contact for data subjects’ inquiries, withdrawals of consent, right to be forgotten requests and other related rights. NOTE: Our law firm will be providing these services to companies. 20. Consider putting systems in place to verify individuals’ ages and to gather
  • 7. 224 Townsend Street San Francisco, CA 94107 T: 415.795.1572 F: 909.972.1639 gamallp.com     7 parental or guardian consent for any data processing activity involving children under thirteen (13) years of age. If such information is involved, the privacy notice will need to be drafted in a manner understandable by children. 21. Review Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs) for trans-Atlantic data flows for compliance with new requirements of GDPR. Draft addendums to SCCs and other contracts as necessary to address the onward transfer restrictions, which includes ensuring that downstream entities comply with limitations on purpose and meet all the requirements, including remediating any unauthorized processing by the downstream entity. Contact Gagnier Margossian today to discuss how we can help with your international privacy compliance. Christina Gagnier Managing Partner, Internet. Intellectual Property & Technology gagnier@gamallp.com 909.493.6447