SlideShare une entreprise Scribd logo
1  sur  20
Télécharger pour lire hors ligne
TATECH Dublin 2018
Shane Gray
The Implications of GDPR for the
Solutions Industry
What is GDPR ?
The European Union’s General Data
Protection Regulation (GPDR) will
take effect on May 25, 2018, bringing
new laws on privacy in regard to
individuals’ personal data and how
it’s processed. GDPR will
significantly strengthen the rights of
individuals and increase the
obligations on organisations even
when they operate outside of
Europe.
Why does this
affect my
organization ?
Most TA Tech vendors are “data
processors” — this means a natural
or legal person, public authority,
agency or other body which
processes personal data on behalf of
a “controller” who is usually your
customer.
Who are the
data
controllers?
A data controller is the individual or
the legal person (entity) who controls
and is responsible for the keeping
and use of personal information.
However most vendors are also
controllers of their own data for
example prospect and customer lists
What is meant by
‘Processing’ ?
Processing’ means any operation or
set of operations which is performed
on personal data or on sets of
personal data, whether or not by
automated means, such as
collection, recording, organisation,
structuring, storage, adaptation or
alteration, retrieval, consultation,
use, disclosure by transmission,
dissemination or otherwise making
available, alignment or combination,
restriction, erasure or destruction.
What is meant by
‘Personal data’ ?
This means any information relating
to an identified or identifiable natural
person (‘data subject’); an identifiable
natural person is one who can be
identified, directly or indirectly, in
particular by reference to an identifier
such as a name, an identification
number, location data, an online
identifier or to one or more factors
specific to the physical,
physiological, genetic, mental,
economic, cultural or social identity
of that natural person.
We are not
based in the
EU, why is this
relevant ?
The principle of “extraterritoriality” in
GDPR means that if your company
processes personal data of EU data
subjects — for recruitment purposes,
for example — then all requirements
of GDPR apply to you, even if you
don’t have a physical presence in the
EU.
What do we need
to do to meet the
requirements of
this regulation?
Do we have the
correct contracts
in place with our
customers?
Contracts need to set out the
subject-matter and duration of the
processing, the nature and purpose of
the processing, the type of personal
data and categories of data subjects
and the obligations and rights of the
controller. In some cases the easiest
approach may be to offer a
supplementary data processing
agreement to avoid contract changes.
Are we in danger
of becoming a
controller?
This is complex issue however as
vendors add more and more algorithmic
processing to their functionality the
answer to this is probably yes. Explicitly
calling out the types of processing in
the contract with the controller may help
mitigate this. More explicitly by
infringing this Regulation by determining
the purposes and means of processing,
the processor shall be considered to be
a controller in respect of that
processing. Enhancing candidate data
or using it for other purposes is a an
example of this.
Have we ensured
that people
authorised to
process the
personal data
have committed
themselves to
confidentiality?
Are we using any
other processors
in our service?
If you are using other data processors
as part of your service, e.g. Fullcontact
or Clearbit API’s then you need to
impose the same obligations on these
processors by way of contract or law. If
the 3rd party processor fails in it’s
obligations then you are fully liable to
the controller. As a processor you
cannot engage another processor
without prior specific or general written
authorisation of the controller and in the
case of general written authorisation,
you need to inform the controller of any
intended changes concerning the
addition or replacement of other
processors.
Do we need to
keep any special
records?
Yes, you will need to maintain a record
of all categories of processing activities
carried out for each controller who you
are acting on behalf of.. There is a
waiver on this for companies of less
than 250 employees except where the
processing carried out is likely to result
in a risk to the rights and freedoms of
data subjects….You could easily argue
this is any recruitment related personal
information.
What about data
security?
As the processor you need to
implement the appropriate technical
and organisational measures to ensure
a level of security appropriate to the risk
to the data subject.
What do we need
to do if we are
hacked?
As a processor you need to notify the
controller without undue delay after
becoming aware of a personal data
breach. The controller then in turn has
to notify the supervising authority within
72 hours.
Can a legal
action be taken
against us?
Yes, each data subject shall have the
right to an effective judicial remedy
where he or she considers that his or
her rights under this Regulation have
been infringed as a result of the
processing of his or her personal data in
non-compliance with this Regulation.
As a processor you are liable for the
damage caused by processing only
where it has not complied with
obligations of GDPR specifically
directed to processors or where you
have acted outside or contrary to lawful
instructions of the controller.
Other things to
think about….
As data controllers our clients have a
different set of obligations understand
them and think about how you can use
your product to help protect them from
human error.
The last word...
This is a new regulation and as such
there are elements that are open to
interpretation, and in the absence of
precedence it can be difficult to give a
black-and-white opinion. However, legal
interpretation is relevant and can draw
on previous experience of existing data
protection regulations. If you’re
concerned, then consult your legal
adviser on the areas you feel may be
applicable to your business.
Thank You
View online
http://bit.ly/ta-gdpr
https://gdpr-info.eu/
Shane Gray
shane@clinchtalent.com
+1 646 642-3283
www.clinchtalent.com

Contenu connexe

Tendances

Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)Exove
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
How does GDPR affect the design of user experiences?
How does GDPR affect the design of user experiences? How does GDPR affect the design of user experiences?
How does GDPR affect the design of user experiences? Exove
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR readyPremier EPOS
 
How will GDPR affect small businesses?
How will GDPR affect small businesses?How will GDPR affect small businesses?
How will GDPR affect small businesses?AllBusinessTemplates
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
Data Protection Audit Checklist
Data Protection Audit ChecklistData Protection Audit Checklist
Data Protection Audit ChecklistDigital Guardian
 
Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...Chris Doolittle
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 

Tendances (20)

Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)Developer view on new EU privacy legislation (GDPR)
Developer view on new EU privacy legislation (GDPR)
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
GDPR
GDPRGDPR
GDPR
 
GDPR
GDPRGDPR
GDPR
 
How does GDPR affect the design of user experiences?
How does GDPR affect the design of user experiences? How does GDPR affect the design of user experiences?
How does GDPR affect the design of user experiences?
 
Data Protection & GDPR Health Check Service Overview
Data Protection & GDPR Health Check Service OverviewData Protection & GDPR Health Check Service Overview
Data Protection & GDPR Health Check Service Overview
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 
How will GDPR affect small businesses?
How will GDPR affect small businesses?How will GDPR affect small businesses?
How will GDPR affect small businesses?
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Data Protection Audit Checklist
Data Protection Audit ChecklistData Protection Audit Checklist
Data Protection Audit Checklist
 
Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Data protection
Data protectionData protection
Data protection
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 

Similaire à The implications of gdpr for the solutions industry tatech 2018

GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoDaniel Smith
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperServersys
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Followetouches
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing MindsetNetworkIQ
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
ICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRBenjamin Dibble
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRJenny Ferguson
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingPromptCloud
 
Common Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsCommon Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsMatheson Law Firm
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRzayadeen2003
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPRAfraAlZadjali
 

Similaire à The implications of gdpr for the solutions industry tatech 2018 (20)

GDPR: Time to Act
GDPR: Time to ActGDPR: Time to Act
GDPR: Time to Act
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist Whitepaper
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Follow
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
ICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPR
 
GDPR Preparing for-the-gdpr-12-steps
GDPR Preparing for-the-gdpr-12-stepsGDPR Preparing for-the-gdpr-12-steps
GDPR Preparing for-the-gdpr-12-steps
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPR
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
 
Common Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsCommon Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A Deals
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPR
 

The implications of gdpr for the solutions industry tatech 2018

  • 2. The Implications of GDPR for the Solutions Industry
  • 3. What is GDPR ? The European Union’s General Data Protection Regulation (GPDR) will take effect on May 25, 2018, bringing new laws on privacy in regard to individuals’ personal data and how it’s processed. GDPR will significantly strengthen the rights of individuals and increase the obligations on organisations even when they operate outside of Europe.
  • 4. Why does this affect my organization ? Most TA Tech vendors are “data processors” — this means a natural or legal person, public authority, agency or other body which processes personal data on behalf of a “controller” who is usually your customer.
  • 5. Who are the data controllers? A data controller is the individual or the legal person (entity) who controls and is responsible for the keeping and use of personal information. However most vendors are also controllers of their own data for example prospect and customer lists
  • 6. What is meant by ‘Processing’ ? Processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • 7. What is meant by ‘Personal data’ ? This means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • 8. We are not based in the EU, why is this relevant ? The principle of “extraterritoriality” in GDPR means that if your company processes personal data of EU data subjects — for recruitment purposes, for example — then all requirements of GDPR apply to you, even if you don’t have a physical presence in the EU.
  • 9. What do we need to do to meet the requirements of this regulation?
  • 10. Do we have the correct contracts in place with our customers? Contracts need to set out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. In some cases the easiest approach may be to offer a supplementary data processing agreement to avoid contract changes.
  • 11. Are we in danger of becoming a controller? This is complex issue however as vendors add more and more algorithmic processing to their functionality the answer to this is probably yes. Explicitly calling out the types of processing in the contract with the controller may help mitigate this. More explicitly by infringing this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing. Enhancing candidate data or using it for other purposes is a an example of this.
  • 12. Have we ensured that people authorised to process the personal data have committed themselves to confidentiality?
  • 13. Are we using any other processors in our service? If you are using other data processors as part of your service, e.g. Fullcontact or Clearbit API’s then you need to impose the same obligations on these processors by way of contract or law. If the 3rd party processor fails in it’s obligations then you are fully liable to the controller. As a processor you cannot engage another processor without prior specific or general written authorisation of the controller and in the case of general written authorisation, you need to inform the controller of any intended changes concerning the addition or replacement of other processors.
  • 14. Do we need to keep any special records? Yes, you will need to maintain a record of all categories of processing activities carried out for each controller who you are acting on behalf of.. There is a waiver on this for companies of less than 250 employees except where the processing carried out is likely to result in a risk to the rights and freedoms of data subjects….You could easily argue this is any recruitment related personal information.
  • 15. What about data security? As the processor you need to implement the appropriate technical and organisational measures to ensure a level of security appropriate to the risk to the data subject.
  • 16. What do we need to do if we are hacked? As a processor you need to notify the controller without undue delay after becoming aware of a personal data breach. The controller then in turn has to notify the supervising authority within 72 hours.
  • 17. Can a legal action be taken against us? Yes, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation. As a processor you are liable for the damage caused by processing only where it has not complied with obligations of GDPR specifically directed to processors or where you have acted outside or contrary to lawful instructions of the controller.
  • 18. Other things to think about…. As data controllers our clients have a different set of obligations understand them and think about how you can use your product to help protect them from human error.
  • 19. The last word... This is a new regulation and as such there are elements that are open to interpretation, and in the absence of precedence it can be difficult to give a black-and-white opinion. However, legal interpretation is relevant and can draw on previous experience of existing data protection regulations. If you’re concerned, then consult your legal adviser on the areas you feel may be applicable to your business.
  • 20. Thank You View online http://bit.ly/ta-gdpr https://gdpr-info.eu/ Shane Gray shane@clinchtalent.com +1 646 642-3283 www.clinchtalent.com