SlideShare une entreprise Scribd logo
1  sur  24
GDPRIntroduction and Overview
16 March 2018
Jane Lambert
Topics to be discussed
● What is the GDPR?
● What is data protection?
● Why we need data protection legislation
● Data Protection Principles
● Lawfulness of processing
● Consent to processing
● Law Enforcement Data Protection Directive
● Data Protection and Brexit
● Data Protection Bill
● Basic Preparation for Small Businesses
What is the GDPR?
● “General Data Protection Regulation”.
● Regulation (EU) 2016/679 of the European Parliament and Council of 27 April
2016 on the protection of natural persons with regard to the processing of
personal data and on the free movement of such data, and repealing
Directive 95/46/EC.
● Directive 95/46/EC is the present source of law
● GDPR will supersede Data Protection Act 1998 for 25 May
What is Data Protection?
● Data protection is a set of rules for processing personal data.
● “Personal data” means any information relating to an identified or identifiable
natural person (art 4 (1) GDPR)
● “Processing” means any operation or set of operations which is performed on
personal data or on sets of personal data (art 4 (2) GDPR).
● It includes collection, collation, storage and transmission.
Why we need Data Protection Legislation?
● Younger report on privacy identified computers as a potential threat to privacy
in 1972
● Lindop recommended legislation to regulate this threat in further report
● Sweden enacted the first data protection law in 1973
● Swedish data protection banned export of data to UK
● OECD Guidelines on Transborder Data Flow in 1980
● Council of Europe Data Protection Convention in 1981
Structure of GDPR
Regulation consists of 173 recitals and 99 articles divided into the following
chapters and sections:
● Chapter I: General Provisions
● Chapter II: Principles
● Chapter III: Rights of Data Subjects
○ §1 - Transparency and modalities
○ §2 - Information and access to personal data
○ §3 - Rectification and erasure
○ §4 - Right to object and automated decision making
○ §5 - Restrictions
Structure of GDPR
● Chapter IV: Controller and Processor
○ §1 - General Obligations
○ S2 - Security of Personal Data
○ §3 - Data Protection Impact Assessment and Prior Consultation
○ §4 - Data Protection Officer
○ §5 - Codes of Conduct and Certification
● Chapter V: Transfers of Data to Third Countries and International
Organzations
● Chapter VI: Independent Supervisory Authorities
○ Independent Status
○ Competence, Tasks and Powers
Structure of GDPR
● Chapter VII: Cooperation and Consistency
○ §1 - Cooperation
○ §2 - Consistency
○ §3 - European Data Protection Board
● Chapter VIII: Remedies, Liabilities and Penalties
● Chapter IX: Provisions Relating to Specific Processing
● Chapter X: Delegated Acts and Implementing Acts
● Chapter XI: Final Provisions
Data Protection Principles
Art 5 of GDPR requires personal data to be:
● (a) processed lawfully, fairly and in a transparent manner in relation to the
data subject (‘lawfulness, fairness and transparency’);
● (b) collected for specified, explicit and legitimate purposes and not further
processed in a manner that is incompatible with those purposes; …..
(‘purpose limitation’);
Data Protection Principles
● (c) adequate, relevant and limited to what is necessary in relation to the
purposes for which they are processed (‘data minimization’);
● (d) accurate and, where necessary, kept up to date; every reasonable step
must be taken to ensure that personal data that are inaccurate, having regard
to the purposes for which they are processed, are erased or rectified without
delay (‘accuracy’);
Data Protection Principles
● (e) kept in a form which permits identification of data subjects for no longer
than is necessary for the purposes for which the personal data are processed;
……………………. (‘storage limitation’);
Data Protection Principles
● (f) processed in a manner that ensures appropriate security of the personal
data, including protection against unauthorised or unlawful processing and
against accidental loss, destruction or damage, using appropriate technical or
organisational measures (‘integrity and confidentiality’)."
Art 6 (2) provides: “The controller shall be responsible for, and be able to
demonstrate compliance with, paragraph 1 (‘accountability’).”
Lawfulness, Fairness and Transparency
● Art 6 (1) provides 6 grounds upon which data controllers can justify their
processing of personal data.
● One of those grounds is tha the data subject has given his or her consent to
the processing of his or her personal data for one or more specific purposes
(art 6 (1) (a)).
● Data controllers tend to rely on that ground because it is easy
to prove compliance.
● That is important because art 5(2) requires data controllers
not only to comply with the data protection principles but to
demonstrate compliance.
Consent to Processing
● By definition, consent must be freely given, specific, informed and
unambiguous (see art 4 (11) GDPR).
● Art 7 sets out the conditions for consent which must be complied with if it is to
be binding.
● Consent need not be in writing but it probably must be recorded if it is be
binding.
● Para 171 of recitals makes clear that consent obtained under
existing law is effective so long as it meets the conditions of
art 7
Consent to Processing
● Consent can be obtained on a form that includes other matter but the
provision relating to consent must be clear and cover all the purposes for
which consent is required.
● Data subjects must be informed of their right to withdraw consent at any time
and withdrawing consent should be as easy as giving it.
● If the data controller and data subject have unequal bargaining
power the controller should not use (or give the impression of
using) his leverage to extract consent.
● Parental consent is required for data subjects aged 16 or less,
Law Enforcement Data Protection Directive
Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April
2016 on the protection of natural persons with regard to the processing of
personal data by competent authorities for the purposes of the prevention,
investigation, detection or prosecution of criminal offences or the execution of
criminal penalties, and on the free movement of such data, and repealing Council
Framework Decision 2008/977/JHA
Art 63 (1) requires it to be implemented by 6 May 2018
Data Protection and Brexit
Art 50 (3) Treaty of European Union:
“The Treaties shall cease to apply to the State in question from the date of entry
into force of the withdrawal agreement or, failing that, two years after the
notification referred to in paragraph 2, unless the European Council, in agreement
with the Member State concerned, unanimously decides to extend this period.”
Data Protection and Brexit
Art 67 Draft Withdrawal Agreement:
“Union law on the protection of personal data shall apply in the United Kingdom in
respect of the processing of personal data of data subjects outside the United
Kingdom, provided that the personal data:
(a) were processed in accordance with Union law in the United Kingdom before
the end of the transition period; or
(b) are processed in the United Kingdom after the end of the transition period on
the basis of this Agreement.”
Data Protection Bill
● Makes consequential provision for the GDPR
● Repeals the Data Protection Act 1998
● Implements the Data Protection Law Enforcement Directive
● Preserves the GDPR after 29 March 2019 or 31 Dec 2020 if a transition
period after 29 March 2019 is agreed
● Passed the Lords and is now in committee in the Commons
Basic Preparation for Small Businesses
Information Commissioner published on 12 March 2018 “Getting ready for the new
UK data protection law Eight practical steps for micro business owners and sole
traders”
● “Know the law is changing – which you now do, so that’s one thing you’ve
done already!
● Make sure you have a record of the personal data you hold and
why.
Basic Preparation for Small Businesses
● Identify why you have personal data and how you use it.
● Have a plan in case people ask about their rights regarding the personal
information you hold about them.
● Ask yourself: before I collect their data, do I clearly tell people why I need it
and how I will use it
Basic Preparation for Small Businesses
● Check your security. This can include locking filing cabinets and password
protecting any of your devices and cloud storage that hold your staff or
customers’ personal data.
● Develop a process to make sure you know what to do if you breach data
protection rules.
● Don’t panic: we’re here to help ………………”
Further Information
● Office of the Information Commissioner (https://ico.org.uk/)
● Jane Lambert Another Data Protection Act! "You're joking! Not another one!" -
A Short History of Data Protection Legislation in the UK 23 Sept 2017
(www.nipclaw.com)
● NIPC Data Protection Blog (http://nipcdp.blogspot.co.uk)
Links to existing legislation, GDPR and Directive, Data
Protection Bill, Commission, Department of Culture, Media and
Sport and Information Commissioner’s Office
Any Questions?
Jane Lambert
4-5 Gray’s Inn Square
London
WC1R 5AH
Tel 020 7404n 5252
Mob 07966 373922
E jlambert@4-5.co.uk
www.nipclaw.com

Contenu connexe

Tendances

Tendances (20)

What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR
GDPRGDPR
GDPR
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Urgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data PribadiUrgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data Pribadi
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to Compliance
 
Data protection
Data protectionData protection
Data protection
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
GDPR training
GDPR training GDPR training
GDPR training
 
Data protection
Data protectionData protection
Data protection
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 

Similaire à GDPR Introduction and overview

#CyberSafeLambeth
#CyberSafeLambeth#CyberSafeLambeth
#CyberSafeLambeth
The Integrate Agency CIC
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
John Greenwood
 

Similaire à GDPR Introduction and overview (20)

"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
GDPR - New European Union Legislation
GDPR - New European Union LegislationGDPR - New European Union Legislation
GDPR - New European Union Legislation
 
Tech Connect Live 30th May 2018 ,GDPR Summit John Ghent
Tech Connect Live 30th May 2018 ,GDPR Summit John GhentTech Connect Live 30th May 2018 ,GDPR Summit John Ghent
Tech Connect Live 30th May 2018 ,GDPR Summit John Ghent
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
#CyberSafeLambeth
#CyberSafeLambeth#CyberSafeLambeth
#CyberSafeLambeth
 
GDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdfGDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdf
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
VIAF GDPR
VIAF GDPRVIAF GDPR
VIAF GDPR
 
GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360
 
Data protection regulation
Data protection regulationData protection regulation
Data protection regulation
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
 
Cyber safe lambeth | GDPR taster
Cyber safe lambeth | GDPR tasterCyber safe lambeth | GDPR taster
Cyber safe lambeth | GDPR taster
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 
The Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and ProtectionThe Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and Protection
 
General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 

Plus de Jane Lambert

Plus de Jane Lambert (20)

Small Claims Track Checklist
Small Claims Track Checklist Small Claims Track Checklist
Small Claims Track Checklist
 
The UK YORUBA Trade Mark Registration
The UK YORUBA Trade Mark RegistrationThe UK YORUBA Trade Mark Registration
The UK YORUBA Trade Mark Registration
 
Copyright Licensing and ICT
Copyright Licensing and ICT Copyright Licensing and ICT
Copyright Licensing and ICT
 
IP After Brexit
IP After BrexitIP After Brexit
IP After Brexit
 
What every Business in Wales needs to know about Intellectual Property
What every Business in Wales needs to know about Intellectual PropertyWhat every Business in Wales needs to know about Intellectual Property
What every Business in Wales needs to know about Intellectual Property
 
What every business in Bradford needs to know about Intellectual Property
What every business in Bradford needs to know about Intellectual PropertyWhat every business in Bradford needs to know about Intellectual Property
What every business in Bradford needs to know about Intellectual Property
 
IP After Brexit
IP After BrexitIP After Brexit
IP After Brexit
 
How Brexit has changed IP Law
How Brexit has changed IP LawHow Brexit has changed IP Law
How Brexit has changed IP Law
 
The Supreme Court Rules on FRAND
The Supreme Court Rules on FRANDThe Supreme Court Rules on FRAND
The Supreme Court Rules on FRAND
 
Understanding Intellectual Property
Understanding Intellectual PropertyUnderstanding Intellectual Property
Understanding Intellectual Property
 
Patents 101 Part 1 The Basics
Patents 101 Part 1  The BasicsPatents 101 Part 1  The Basics
Patents 101 Part 1 The Basics
 
Patents 101 Part 5 - Infringement
Patents 101 Part 5 - InfringementPatents 101 Part 5 - Infringement
Patents 101 Part 5 - Infringement
 
Patents101 Part 5 -Infringement
Patents101 Part 5 -InfringementPatents101 Part 5 -Infringement
Patents101 Part 5 -Infringement
 
Patents 101 Part 4 - Applying for a Patent
Patents 101 Part 4 - Applying for a PatentPatents 101 Part 4 - Applying for a Patent
Patents 101 Part 4 - Applying for a Patent
 
Patents101 Part 4 - Applying for a Patent
Patents101 Part 4 - Applying for a PatentPatents101 Part 4 - Applying for a Patent
Patents101 Part 4 - Applying for a Patent
 
Patents 101 Part 3 - Patentability
Patents 101  Part 3 - PatentabilityPatents 101  Part 3 - Patentability
Patents 101 Part 3 - Patentability
 
Patents 101 Part 3 - Patentability
Patents 101 Part 3 - PatentabilityPatents 101 Part 3 - Patentability
Patents 101 Part 3 - Patentability
 
Patents 101 Part 2 The Law
Patents 101 Part 2 The LawPatents 101 Part 2 The Law
Patents 101 Part 2 The Law
 
Patents 101 - Part 2 The Law
Patents 101 - Part 2  The LawPatents 101 - Part 2  The Law
Patents 101 - Part 2 The Law
 
Patents101- The Basics
Patents101- The BasicsPatents101- The Basics
Patents101- The Basics
 

Dernier

一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
A AA
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
bd2c5966a56d
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
irst
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
JosephCanama
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
e9733fc35af6
 

Dernier (20)

CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. Steering
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptx
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptxAnalysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
 
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 

GDPR Introduction and overview

  • 1. GDPRIntroduction and Overview 16 March 2018 Jane Lambert
  • 2. Topics to be discussed ● What is the GDPR? ● What is data protection? ● Why we need data protection legislation ● Data Protection Principles ● Lawfulness of processing ● Consent to processing ● Law Enforcement Data Protection Directive ● Data Protection and Brexit ● Data Protection Bill ● Basic Preparation for Small Businesses
  • 3. What is the GDPR? ● “General Data Protection Regulation”. ● Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC. ● Directive 95/46/EC is the present source of law ● GDPR will supersede Data Protection Act 1998 for 25 May
  • 4. What is Data Protection? ● Data protection is a set of rules for processing personal data. ● “Personal data” means any information relating to an identified or identifiable natural person (art 4 (1) GDPR) ● “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data (art 4 (2) GDPR). ● It includes collection, collation, storage and transmission.
  • 5. Why we need Data Protection Legislation? ● Younger report on privacy identified computers as a potential threat to privacy in 1972 ● Lindop recommended legislation to regulate this threat in further report ● Sweden enacted the first data protection law in 1973 ● Swedish data protection banned export of data to UK ● OECD Guidelines on Transborder Data Flow in 1980 ● Council of Europe Data Protection Convention in 1981
  • 6. Structure of GDPR Regulation consists of 173 recitals and 99 articles divided into the following chapters and sections: ● Chapter I: General Provisions ● Chapter II: Principles ● Chapter III: Rights of Data Subjects ○ §1 - Transparency and modalities ○ §2 - Information and access to personal data ○ §3 - Rectification and erasure ○ §4 - Right to object and automated decision making ○ §5 - Restrictions
  • 7. Structure of GDPR ● Chapter IV: Controller and Processor ○ §1 - General Obligations ○ S2 - Security of Personal Data ○ §3 - Data Protection Impact Assessment and Prior Consultation ○ §4 - Data Protection Officer ○ §5 - Codes of Conduct and Certification ● Chapter V: Transfers of Data to Third Countries and International Organzations ● Chapter VI: Independent Supervisory Authorities ○ Independent Status ○ Competence, Tasks and Powers
  • 8. Structure of GDPR ● Chapter VII: Cooperation and Consistency ○ §1 - Cooperation ○ §2 - Consistency ○ §3 - European Data Protection Board ● Chapter VIII: Remedies, Liabilities and Penalties ● Chapter IX: Provisions Relating to Specific Processing ● Chapter X: Delegated Acts and Implementing Acts ● Chapter XI: Final Provisions
  • 9. Data Protection Principles Art 5 of GDPR requires personal data to be: ● (a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’); ● (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; ….. (‘purpose limitation’);
  • 10. Data Protection Principles ● (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’); ● (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
  • 11. Data Protection Principles ● (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; ……………………. (‘storage limitation’);
  • 12. Data Protection Principles ● (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)." Art 6 (2) provides: “The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).”
  • 13. Lawfulness, Fairness and Transparency ● Art 6 (1) provides 6 grounds upon which data controllers can justify their processing of personal data. ● One of those grounds is tha the data subject has given his or her consent to the processing of his or her personal data for one or more specific purposes (art 6 (1) (a)). ● Data controllers tend to rely on that ground because it is easy to prove compliance. ● That is important because art 5(2) requires data controllers not only to comply with the data protection principles but to demonstrate compliance.
  • 14. Consent to Processing ● By definition, consent must be freely given, specific, informed and unambiguous (see art 4 (11) GDPR). ● Art 7 sets out the conditions for consent which must be complied with if it is to be binding. ● Consent need not be in writing but it probably must be recorded if it is be binding. ● Para 171 of recitals makes clear that consent obtained under existing law is effective so long as it meets the conditions of art 7
  • 15. Consent to Processing ● Consent can be obtained on a form that includes other matter but the provision relating to consent must be clear and cover all the purposes for which consent is required. ● Data subjects must be informed of their right to withdraw consent at any time and withdrawing consent should be as easy as giving it. ● If the data controller and data subject have unequal bargaining power the controller should not use (or give the impression of using) his leverage to extract consent. ● Parental consent is required for data subjects aged 16 or less,
  • 16. Law Enforcement Data Protection Directive Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA Art 63 (1) requires it to be implemented by 6 May 2018
  • 17. Data Protection and Brexit Art 50 (3) Treaty of European Union: “The Treaties shall cease to apply to the State in question from the date of entry into force of the withdrawal agreement or, failing that, two years after the notification referred to in paragraph 2, unless the European Council, in agreement with the Member State concerned, unanimously decides to extend this period.”
  • 18. Data Protection and Brexit Art 67 Draft Withdrawal Agreement: “Union law on the protection of personal data shall apply in the United Kingdom in respect of the processing of personal data of data subjects outside the United Kingdom, provided that the personal data: (a) were processed in accordance with Union law in the United Kingdom before the end of the transition period; or (b) are processed in the United Kingdom after the end of the transition period on the basis of this Agreement.”
  • 19. Data Protection Bill ● Makes consequential provision for the GDPR ● Repeals the Data Protection Act 1998 ● Implements the Data Protection Law Enforcement Directive ● Preserves the GDPR after 29 March 2019 or 31 Dec 2020 if a transition period after 29 March 2019 is agreed ● Passed the Lords and is now in committee in the Commons
  • 20. Basic Preparation for Small Businesses Information Commissioner published on 12 March 2018 “Getting ready for the new UK data protection law Eight practical steps for micro business owners and sole traders” ● “Know the law is changing – which you now do, so that’s one thing you’ve done already! ● Make sure you have a record of the personal data you hold and why.
  • 21. Basic Preparation for Small Businesses ● Identify why you have personal data and how you use it. ● Have a plan in case people ask about their rights regarding the personal information you hold about them. ● Ask yourself: before I collect their data, do I clearly tell people why I need it and how I will use it
  • 22. Basic Preparation for Small Businesses ● Check your security. This can include locking filing cabinets and password protecting any of your devices and cloud storage that hold your staff or customers’ personal data. ● Develop a process to make sure you know what to do if you breach data protection rules. ● Don’t panic: we’re here to help ………………”
  • 23. Further Information ● Office of the Information Commissioner (https://ico.org.uk/) ● Jane Lambert Another Data Protection Act! "You're joking! Not another one!" - A Short History of Data Protection Legislation in the UK 23 Sept 2017 (www.nipclaw.com) ● NIPC Data Protection Blog (http://nipcdp.blogspot.co.uk) Links to existing legislation, GDPR and Directive, Data Protection Bill, Commission, Department of Culture, Media and Sport and Information Commissioner’s Office
  • 24. Any Questions? Jane Lambert 4-5 Gray’s Inn Square London WC1R 5AH Tel 020 7404n 5252 Mob 07966 373922 E jlambert@4-5.co.uk www.nipclaw.com