SlideShare ist ein Scribd-Unternehmen logo
1 von 26
Downloaden Sie, um offline zu lesen
Who here is 100% confident their organisation
complies with the laws on data protection
today?
And that you are ready for the change in the law
next year?
▪ Jowanna Conboye
▪ IP & IT Associate,
specialising in data protection advice
▪ ip.it@stephens-scown.co.uk
▪ 01872 265112
DATA PROTECTION IN THE NEWS
Charities investigated
for ‘calling vulnerable
people for money’
Source: The Guardian July 2015
ICO fines eleven
more charities
Source: ICO April 2017
RSPCA and British Heart
Foundation fined over
‘wealth screening’ data
breaches
Source: BBC News Dec 2016
GOOGLE IN 1998
BBC IN 1998
THE LAW
GENERAL DATA PROTECTION REGULATION 2016
A new law for
a new age? Increased burden
from Europe or a
golden opportunity?
Passed as law in
May 2016 in the EU
Comes into force in May 2018
with enforcement action due
from day 1.
GDPR
STAYING THE SAME
a) Lawful, fair and transparent
Must satisfy one of the conditions for processing:
• consent
• performance of contract with data subject
• legal obligation
• vital interests
• public interest
• legitimate interests, unless overridden by rights of data subject
The data protection principles
(under article 5)
b) Purpose limitation
• Used only for the reason it was collected
• Notified to the data subject
• “Specified, explicit and legitimate”
c) Data minimisation
• Don’t hold more data than you need
• “Adequate, relevant and necessary”
The data protection principles
(under article 5)
GDPR
STAYING THE SAME
d) Data quality
➢ “Accurate and kept up to date”
➢ Beware of assumptions
➢ When was the last time you updated the data?
e) Storage limitation
➢ Don’t keep data for longer than necessary
➢ Data cleanse!
f) Data security
➢ “Integrity and confidentiality”
The data protection principles
(under article 5)
GDPR
STAYING THE SAME
(Part 1)
• Accountability
➢ data controllers will have to show compliance
➢ high administration burden
➢ ICO says this is the biggest change
GDPR
WHAT HAS CHANGED?
• Enforcement
➢ used to be a maximum of £500k in the UK
➢ now up to €20 million or 4% of worldwide
turnover!
➢ (£17 million under Data Protection Bill)
• Consent
➢ no more implied consent
➢ will have a drastic effect for the charities who collect and use
customer data for fundraising
➢ “freely given, specific, informed and unambiguous”
➢ opt-in only, but what about Privacy and Electronic Communication
Regulations? Soft opt-in and ePrivacy Regulation
➢ beware of “re-contacting” people to refresh their consent – e.g. Flybe
and Honda
➢ underlying message is if you are relying on consent you need to tell
people exactly what you are doing and then get their active
agreement – no tricks!
➢ for legitimate interests, you need a written balancing exercise
(Part 2)
GDPR
WHAT HAS CHANGED?
• Data breaches
➢ Organisations must report any data protection breach within 72 hours. But it might be
unclear whether a breach has happened, so businesses will need a Data Breach
Response Plan
• Pseudonymisation
➢ Processing of personal data so that it cannot be attributed to a specific individual
without additional information
➢ New concept may catch charities that think they deal in anonymous data
➢ Still personal data but potentially subject to fewer restrictions
➢ The key must be kept separately and securely
• Data Processors
➢ Data processors must directly comply with the new law to the same standard as
controllers and also will be liable to fines
GDPR
WHAT HAS CHANGED?
(Part 3)
GDPR
WHAT HAS CHANGED?
(Part 4)
• “Privacy by design”
➢ requirement to implement data protection by design not tagged on at the
end of a project
➢ organisations will need to conduct Privacy Impact Assessments for each
new project that deals with any personal data
➢ how does this apply to existing projects or the business as a whole – will
you need to “re-design”?
➢ Best solution is to conduct a Data Protection Audit
o Right to object to profiling
o Right to data portability
o Right to be forgotten
• Enhanced data subject rights, including:
(Part 5)
GDPR
WHAT HAS CHANGED?
BREXIT
• Key date: GDPR becomes law on 25 May 2018 before we leave EU
• UK bill: UK government have published Data Protection Bill which
absorbs GDPR into UK law
• Timings: DP Bill will become law at the same time the GDPR comes
into force in the EU
• Conclusion: the GDPR is here to stay!
WHAT’S THE RISK OF GETTING IT WRONG?
▪ Huge fines – for data protection breaches, this is up to £500,000 now
and will increase to €20 million or 4% of turnover in 2018
▪ Being made to comply anyway - being forced to change your
procedures by regulators and having to abide by data protection laws
▪ Bad publicity - affect on customer and donor confidence in your
charity can lead to loss of reputation and significant loss of funds
WHAT CAN YOU DO NOW TO PREPARE?
7 TOP TIPS
1. Audit all the personal data you hold:
▪ how do you collect data (both online and offline)?
▪ how do you store data (both hard and soft copy)?
▪ how do you use data (both internally and externally)?
2. Review your fundraising procedures and basis for processing
▪ Are you relying on consent?
▪ Is it opt in or opt out?
▪ What permissions do you have to contact donors and customers?
3. What have you told your donors? Do you know?
WHAT CAN YOU DO NOW TO PREPARE?
7 TOP TIPS
4. Conduct PIAs
5. Make sure you have a the correct policies for each different
type of processing and that you comply with them in practice
6. Talk to your suppliers about whether they are ready for the
GDPR.
7. Ensure your employees are trained in data protection
▪ Jowanna Conboye
▪ IP & IT Associate
▪ ip.it@stephens-scown.co.uk
▪ 01872 265112

Weitere ähnliche Inhalte

Was ist angesagt?

UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?David Erdos
 
Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery, Inc.
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTeEU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTeTrustArc
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
IoT - Attacks and Solutions
IoT - Attacks and SolutionsIoT - Attacks and Solutions
IoT - Attacks and SolutionsUlf Mattsson
 
GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?MediaPost
 
Do You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleDo You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleUlf Mattsson
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.Steven Salter
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...MediaPost
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 

Was ist angesagt? (19)

UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery MCM - May 2016
Ghostery MCM - May 2016
 
DPA and GDPR
DPA and GDPRDPA and GDPR
DPA and GDPR
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTeEU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
IoT - Attacks and Solutions
IoT - Attacks and SolutionsIoT - Attacks and Solutions
IoT - Attacks and Solutions
 
GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?
 
Do You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleDo You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? Article
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 

Ähnlich wie Jowanna Conboye - Stephens Scown

GDPR training
GDPR training GDPR training
GDPR training ASL
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPRSpoon London
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year onInsight Data
 
How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and ExperianHow to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and ExperianPECB
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteClive Rich
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberRachel Aldighieri
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?EngageHub
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...Feroot
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014Rachel Aldighieri
 
Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data OpportunityiCrossing
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberRachel Aldighieri
 

Ähnlich wie Jowanna Conboye - Stephens Scown (20)

GDPR training
GDPR training GDPR training
GDPR training
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year on
 
How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and ExperianHow to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data Opportunity
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 

Kürzlich hochgeladen

Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Hedda Bird
 
Call Now Pooja Mehta : 7738631006 Door Step Call Girls Rate 100% Satisfactio...
Call Now Pooja Mehta :  7738631006 Door Step Call Girls Rate 100% Satisfactio...Call Now Pooja Mehta :  7738631006 Door Step Call Girls Rate 100% Satisfactio...
Call Now Pooja Mehta : 7738631006 Door Step Call Girls Rate 100% Satisfactio...Pooja Nehwal
 
CALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual serviceanilsa9823
 
{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai
{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai
{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, MumbaiPooja Nehwal
 
Agile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxAgile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxalinstan901
 
CEO of Google, Sunder Pichai's biography
CEO of Google, Sunder Pichai's biographyCEO of Google, Sunder Pichai's biography
CEO of Google, Sunder Pichai's biographyHafizMuhammadAbdulla5
 
Day 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC BootcampDay 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC BootcampPLCLeadershipDevelop
 
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...Pooja Nehwal
 
Continuous Improvement Infographics for Learning
Continuous Improvement Infographics for LearningContinuous Improvement Infographics for Learning
Continuous Improvement Infographics for LearningCIToolkit
 
VIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call Girladitipandeya
 
internal analysis on strategic management
internal analysis on strategic managementinternal analysis on strategic management
internal analysis on strategic managementharfimakarim
 
operational plan ppt.pptx nursing management
operational plan ppt.pptx nursing managementoperational plan ppt.pptx nursing management
operational plan ppt.pptx nursing managementTulsiDhidhi1
 
situational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima Ssituational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima Smisbafathima9940
 

Kürzlich hochgeladen (20)

Becoming an Inclusive Leader - Bernadette Thompson
Becoming an Inclusive Leader - Bernadette ThompsonBecoming an Inclusive Leader - Bernadette Thompson
Becoming an Inclusive Leader - Bernadette Thompson
 
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
 
Call Now Pooja Mehta : 7738631006 Door Step Call Girls Rate 100% Satisfactio...
Call Now Pooja Mehta :  7738631006 Door Step Call Girls Rate 100% Satisfactio...Call Now Pooja Mehta :  7738631006 Door Step Call Girls Rate 100% Satisfactio...
Call Now Pooja Mehta : 7738631006 Door Step Call Girls Rate 100% Satisfactio...
 
CALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Charbagh Lucknow best sexual service
 
{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai
{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai
{ 9892124323 }} Call Girls & Escorts in Hotel JW Marriott juhu, Mumbai
 
Unlocking the Future - Dr Max Blumberg, Founder of Blumberg Partnership
Unlocking the Future - Dr Max Blumberg, Founder of Blumberg PartnershipUnlocking the Future - Dr Max Blumberg, Founder of Blumberg Partnership
Unlocking the Future - Dr Max Blumberg, Founder of Blumberg Partnership
 
Disrupt or be Disrupted - Kirk Vallis.pdf
Disrupt or be Disrupted - Kirk Vallis.pdfDisrupt or be Disrupted - Kirk Vallis.pdf
Disrupt or be Disrupted - Kirk Vallis.pdf
 
Agile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxAgile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptx
 
CEO of Google, Sunder Pichai's biography
CEO of Google, Sunder Pichai's biographyCEO of Google, Sunder Pichai's biography
CEO of Google, Sunder Pichai's biography
 
Day 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC BootcampDay 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC Bootcamp
 
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
 
Imagine - Creating Healthy Workplaces - Anthony Montgomery.pdf
Imagine - Creating Healthy Workplaces - Anthony Montgomery.pdfImagine - Creating Healthy Workplaces - Anthony Montgomery.pdf
Imagine - Creating Healthy Workplaces - Anthony Montgomery.pdf
 
Continuous Improvement Infographics for Learning
Continuous Improvement Infographics for LearningContinuous Improvement Infographics for Learning
Continuous Improvement Infographics for Learning
 
VIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls Ameerpet high-profile Call Girl
 
internal analysis on strategic management
internal analysis on strategic managementinternal analysis on strategic management
internal analysis on strategic management
 
Empowering Local Government Frontline Services - Mo Baines.pdf
Empowering Local Government Frontline Services - Mo Baines.pdfEmpowering Local Government Frontline Services - Mo Baines.pdf
Empowering Local Government Frontline Services - Mo Baines.pdf
 
operational plan ppt.pptx nursing management
operational plan ppt.pptx nursing managementoperational plan ppt.pptx nursing management
operational plan ppt.pptx nursing management
 
situational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima Ssituational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima S
 
Discover -CQ Master Class - Rikita Wadhwa.pdf
Discover -CQ Master Class - Rikita Wadhwa.pdfDiscover -CQ Master Class - Rikita Wadhwa.pdf
Discover -CQ Master Class - Rikita Wadhwa.pdf
 
LoveLocalGov - Chris Twigg, Inner Circle
LoveLocalGov - Chris Twigg, Inner CircleLoveLocalGov - Chris Twigg, Inner Circle
LoveLocalGov - Chris Twigg, Inner Circle
 

Jowanna Conboye - Stephens Scown

  • 1.
  • 2. Who here is 100% confident their organisation complies with the laws on data protection today? And that you are ready for the change in the law next year?
  • 3. ▪ Jowanna Conboye ▪ IP & IT Associate, specialising in data protection advice ▪ ip.it@stephens-scown.co.uk ▪ 01872 265112
  • 4. DATA PROTECTION IN THE NEWS Charities investigated for ‘calling vulnerable people for money’ Source: The Guardian July 2015 ICO fines eleven more charities Source: ICO April 2017 RSPCA and British Heart Foundation fined over ‘wealth screening’ data breaches Source: BBC News Dec 2016
  • 7.
  • 8.
  • 9. THE LAW GENERAL DATA PROTECTION REGULATION 2016 A new law for a new age? Increased burden from Europe or a golden opportunity? Passed as law in May 2016 in the EU Comes into force in May 2018 with enforcement action due from day 1.
  • 10.
  • 11. GDPR STAYING THE SAME a) Lawful, fair and transparent Must satisfy one of the conditions for processing: • consent • performance of contract with data subject • legal obligation • vital interests • public interest • legitimate interests, unless overridden by rights of data subject The data protection principles (under article 5)
  • 12. b) Purpose limitation • Used only for the reason it was collected • Notified to the data subject • “Specified, explicit and legitimate” c) Data minimisation • Don’t hold more data than you need • “Adequate, relevant and necessary” The data protection principles (under article 5) GDPR STAYING THE SAME
  • 13. d) Data quality ➢ “Accurate and kept up to date” ➢ Beware of assumptions ➢ When was the last time you updated the data? e) Storage limitation ➢ Don’t keep data for longer than necessary ➢ Data cleanse! f) Data security ➢ “Integrity and confidentiality” The data protection principles (under article 5) GDPR STAYING THE SAME
  • 14.
  • 15. (Part 1) • Accountability ➢ data controllers will have to show compliance ➢ high administration burden ➢ ICO says this is the biggest change GDPR WHAT HAS CHANGED? • Enforcement ➢ used to be a maximum of £500k in the UK ➢ now up to €20 million or 4% of worldwide turnover! ➢ (£17 million under Data Protection Bill)
  • 16. • Consent ➢ no more implied consent ➢ will have a drastic effect for the charities who collect and use customer data for fundraising ➢ “freely given, specific, informed and unambiguous” ➢ opt-in only, but what about Privacy and Electronic Communication Regulations? Soft opt-in and ePrivacy Regulation ➢ beware of “re-contacting” people to refresh their consent – e.g. Flybe and Honda ➢ underlying message is if you are relying on consent you need to tell people exactly what you are doing and then get their active agreement – no tricks! ➢ for legitimate interests, you need a written balancing exercise (Part 2) GDPR WHAT HAS CHANGED?
  • 17. • Data breaches ➢ Organisations must report any data protection breach within 72 hours. But it might be unclear whether a breach has happened, so businesses will need a Data Breach Response Plan • Pseudonymisation ➢ Processing of personal data so that it cannot be attributed to a specific individual without additional information ➢ New concept may catch charities that think they deal in anonymous data ➢ Still personal data but potentially subject to fewer restrictions ➢ The key must be kept separately and securely • Data Processors ➢ Data processors must directly comply with the new law to the same standard as controllers and also will be liable to fines GDPR WHAT HAS CHANGED? (Part 3)
  • 18. GDPR WHAT HAS CHANGED? (Part 4) • “Privacy by design” ➢ requirement to implement data protection by design not tagged on at the end of a project ➢ organisations will need to conduct Privacy Impact Assessments for each new project that deals with any personal data ➢ how does this apply to existing projects or the business as a whole – will you need to “re-design”? ➢ Best solution is to conduct a Data Protection Audit
  • 19. o Right to object to profiling o Right to data portability o Right to be forgotten • Enhanced data subject rights, including: (Part 5) GDPR WHAT HAS CHANGED?
  • 20.
  • 21. BREXIT • Key date: GDPR becomes law on 25 May 2018 before we leave EU • UK bill: UK government have published Data Protection Bill which absorbs GDPR into UK law • Timings: DP Bill will become law at the same time the GDPR comes into force in the EU • Conclusion: the GDPR is here to stay!
  • 22. WHAT’S THE RISK OF GETTING IT WRONG? ▪ Huge fines – for data protection breaches, this is up to £500,000 now and will increase to €20 million or 4% of turnover in 2018 ▪ Being made to comply anyway - being forced to change your procedures by regulators and having to abide by data protection laws ▪ Bad publicity - affect on customer and donor confidence in your charity can lead to loss of reputation and significant loss of funds
  • 23. WHAT CAN YOU DO NOW TO PREPARE? 7 TOP TIPS 1. Audit all the personal data you hold: ▪ how do you collect data (both online and offline)? ▪ how do you store data (both hard and soft copy)? ▪ how do you use data (both internally and externally)? 2. Review your fundraising procedures and basis for processing ▪ Are you relying on consent? ▪ Is it opt in or opt out? ▪ What permissions do you have to contact donors and customers? 3. What have you told your donors? Do you know?
  • 24. WHAT CAN YOU DO NOW TO PREPARE? 7 TOP TIPS 4. Conduct PIAs 5. Make sure you have a the correct policies for each different type of processing and that you comply with them in practice 6. Talk to your suppliers about whether they are ready for the GDPR. 7. Ensure your employees are trained in data protection
  • 25.
  • 26. ▪ Jowanna Conboye ▪ IP & IT Associate ▪ ip.it@stephens-scown.co.uk ▪ 01872 265112