SlideShare ist ein Scribd-Unternehmen logo
1 von 22
Co-Author: Trevor Clarence
GDPR Accredited
Presenter: Gary Raven
What Is GDPR?
•The General Data Protection Regulation
(GDPR) (Regulation (EU) 2016/679) is a
regulation the European Parliament, the
Council of the European Union and the
European Commission have strengthened to
unify data protection for all individuals within
the European Union (EU).
The Six Principles of GDPR?
Transparent, Specific, Limited,
Accurate,Time limited & Secure
The collection, storage and use
of personal data should be…
The Orders From Europe
Directives
•Requires each country to interpret the direction, then create
their own laws
(there is a lot of ‘varied interpretation’ across Europe)
Regulation •Immediately applicable law in each county
Enforcement
If breaches of the regulation are apparent, sanctions and fines
can be applied
Timeline
Directive Personal data Directive was introduced in 1995
Regulation
May 2016- Regulation entered into force following
publication in the EU Official Journal
Enforcement
25th May 2018 - Following a 2 year post-adoption grace
period, the GDPR will become fully enforceable throughout
the European Union.
Post
Brexit
The regulation has been created with a lot
of input from and the full support of, the UK
Government who have committed to the
enforcement of GDPR.
It should be noted that non-EU countries /
organisations who intend to do business
with EU members MUST comply with the
GDPR regulation.
Data Subject
An identified natural
person
Data Controller:
Determines the
‘Purpose and Means’ of
the processing
Data Processor:
Processes personal data
on behalf of the
controller
Components of the Regulation
Example
Data Subject -YOU Data Processor - ADP
Personal data
Data Controller - ASL
Personal data
1. Name Trevor Clarence
2. Private email Trevclarence123@gmail.com
3. Photograph
4. Work email Trevor.clarence@asl-group.co.uk
5. IP Address 67.34.252.101
6. Bank Details 60876334-20-23-83
7. Trade Union No 12345678
8. Biometric number AE-17-B3-FG-4B-A3-G8
What is Personal Data?
Important Note: The regulation applies to information held ‘digitally’ &/or on ‘Paper’
Question: Which elements of this information are classed as ‘Special Category’?
Personal data means ‘any information’ that can be used to identify a
natural person (either directly or indirectly)
Note: Company addresses, departmental emails and web
addresses are NOT classed as personal data.
• Data Profiling is a method of searching data with
mathematical algorithms to identify trends and hidden
patterns, profile customers, and then predict how these
trends or customers will behave in the future.
Data Profiling
Mr Data Subject
DOB: 18/01/99
Email: dsubject@gmail.com
Union Number: DS125769879uk
• Lawful Reason - To meet a contractual obligation
• We promise to deliver within 48 hours! (we will need your
address)
• Legitimate Reason – To fulfill an assumed requirement
• Your support is about to end, we want to contact you to offer the
renewal
• Consent
• Please tick this box if you want to receive information about
similar products
Reasons for ‘holding/processing’
personal data
As a business, which should be the last reason you rely on?

• What data do you have on me?
• What consent do you have for processing my data?
• What are you doing with my data?
• Where is the data held?
• Who has access to my data?
• How long will you keep my data?
• I no longer want you to keep my data (forget me!)
What rights does a Data Subject have?
• Every Organisation that holds or processes Personal data
• Public Authorities
• Schools, Colleges and Academies
• County & district councils
• Charities and charitable groups
Who is affected?
• Businesses (large, Medium and Small)
• SMEs
• Facebook, Amazon etc
• Kyocera
• ASL
Is it another Millennium bug?
•No: Very serious project involving a lot of people and a lot of
money
Is it important? Is there any scaremongering?
• There are two tiers of administrative fines that can be levied:
• 1) Up to €10 million, or 2% annual global turnover – whichever is
higher.
• 2) Up to €20 million, or 4% annual global turnover – whichever is
higher.
• The fines are based on the specific articles of the Regulation that the
organisation has breached.
Top 20 ICO FinesTo Date
• The Independent Enquiry into Child Sex Abuse £200,000 Sent a bulk email identifying possible victims of abuseOct-17
• Newday Limited £230,000 Unsolicited emails Nov-18
• Barrington Claims £250,000 Unrequested automated marketing calls Sep-17
• Yahoo £250,000 500 million user accounts compromised Sep-18
• EasyLeads Limited £260,00016.7 million automated marketing callsSep-18
• Road Accident Consulting (trading as MediaTactics) £270,000 22 million unsolicted personal injury calls Mar-17
• Holmes Financial Solutions £300,000 8.8 million marketing calls Jan-18
• Brighton & Sussex University Hospital FoundationTrust £325,000The trust was fined when a contractor hired to delete
personal data from PC hard drives sold the drives on Ebay Jun-17
• The Crown Prosecution Service £325,000 Lost unencrypted DVDs of video recorded testimony from victims of child
abuse May-18
Top 20 ICO FinesTo Date
• Miss-Sold Products UK £350,000 75 million unsolicted PPI claim calls Jan-18
• Your Money Rights £350,000 146 million unsolicted PPI claim calls Sep-17
• Uber £385,000 Paying off hackers who stole personal data on 2.7 million customers and neglected to tell the customers
this had happened Nov-18
• Carphone Warehouse £400,0003 million credit card data records lost to hackers Jan-18
• Kuerboom Communications £400,00099 million nuisance PPI calls May-17
• TalkTalk £400,000157,000 data records lost to hackers including bank sort and account numbers Oct-16
• Equifax £500,000 15 million data records lost to hackers including name, address, bank and driving licence
detailsSep-18
• Facebook £500,000 87 million FB users information shared with Cambridge Analytica Oct-18
Do organisations need to take it seriously?
Our customers have rights under the legislation
Data Subject requests are a possibility
Telephone calls already to ASL
What is ASL’s policy?
Requests inTenders
The ‘data privacy aspects’ of the contract between the customer and ASL.
What assurances can be given to the customer that ASL is fully compliant with GDPR?
Is it important?
Is there any scaremongering?
Buy-in from the Board
Department Heads
In-house project
Review all processes that hold-process Personal Data
What data,What do we do with it, Where held, Who access, How long etc
What are ASL doing?
Staff training/overview of GDPR
Sales Opportunities
Sales/marketing gain interest from the customer (Mail-Shot, Sales meetings)
Detailed customer review from Professional services
PDF with 4 sections
GDPR Overview
How ASL can help with GDPR compliance
Extending GDPR compliance with Cyber Security
ASL’s Commitment to GDPR (Statement from the MD)
How ASL can help it’s customers
(with the products & services supplied by ASL)
• Your Printer/MFD may have an internal (HDD) Hard Disk
Drive or (SSD) Solid State Drive, these drive's hold data and
complete varies functions in the processing of scanning,
copying and printing (user settings, device information, image
data etc).The sensitive or confidential information that is
stored on these drives should not be leaked from the
MFD/Printer, the various protection methods include:
• HDD/SSD Encryption.
• Automatic HDD Overwrite.
Business culture
• ICO = Information Commissioning Office -
we want to see a business culture
• GDPR is not a ‘Tick Box’ regulation
By design and default
• ICO = Personal data protection should be a
business fundamental
The fines and business drivers
• 20 Million Euros
• Can you respond within 1 month to a Data
Subject Request?
GDPR ‘gossip’
Data Subject Requests
Can beVerbal
Know what to do if you get one!
The ‘right’ to complain
If I’m not satisfied, I will report you to the ICO
DPO (Data Protection Officer)
Must have if: Public body, or high risk to data
subjects
Is GDPR the new PPI?
Are people mis-selling the importance of the
GDPR
Lawyers are getting ready to support the claims
Data Subject: An identified natural person
Data Controller: Determines the ‘Purpose and Means’ of the processing
Data Processor: Processes personal data on behalf of the controller
Data Processing: Collection, storage, making available, use, alteration
Data Profiling: Automated processing to predict: interests, wealth etc
Six Principles Transparent, Specific, Limited, Accurate, Duration, Secure
ICO: The UK GDPR supervisors (advertising campaign)
Data Breach: Loss, destruction, unauthorised disclosure
GDPR Key Definitions
Data Subject Request: Take any contact details
Ascertain the nature of the request
Pass this to your line manager – preferably in writing (email)
If your line manager is unavailable –Trevor Clarence
GDPR Key Staff Actions
ASL Policy Request: Take contact details - Pass this to your line manager –
preferably in writing (email)
Ascertain the nature of the request
Send a copy of the GDPR PDF document
Steer the contact to the GDPR section of the ASL website
Co-Author: Trevor Clarence
GDPR Accredited
Presenter: Gary Raven

Weitere ähnliche Inhalte

Was ist angesagt?

EY-treating-customers-fairly-an-in-depth-look-at-GN-16
EY-treating-customers-fairly-an-in-depth-look-at-GN-16EY-treating-customers-fairly-an-in-depth-look-at-GN-16
EY-treating-customers-fairly-an-in-depth-look-at-GN-16
Jayshree Luthra
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
SaimaRafiq
 

Was ist angesagt? (20)

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Présentation RGPD/GDPR 2018
Présentation RGPD/GDPR 2018Présentation RGPD/GDPR 2018
Présentation RGPD/GDPR 2018
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 
Data protection
Data protectionData protection
Data protection
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
EY-treating-customers-fairly-an-in-depth-look-at-GN-16
EY-treating-customers-fairly-an-in-depth-look-at-GN-16EY-treating-customers-fairly-an-in-depth-look-at-GN-16
EY-treating-customers-fairly-an-in-depth-look-at-GN-16
 
GDPR
GDPRGDPR
GDPR
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR and Security.pdf
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
Rodo reakcja na_naruszenia
Rodo  reakcja na_naruszeniaRodo  reakcja na_naruszenia
Rodo reakcja na_naruszenia
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR
GDPRGDPR
GDPR
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 

Ähnlich wie GDPR training

Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
iof_events
 

Ähnlich wie GDPR training (20)

Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
GDPR Information
GDPR InformationGDPR Information
GDPR Information
 
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
CASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disasterCASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disaster
 
Dai Davies - GDPR Presentation
Dai Davies - GDPR PresentationDai Davies - GDPR Presentation
Dai Davies - GDPR Presentation
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
 
The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR will be the new regulation on may 2018
GDPR will be the new regulation on may 2018GDPR will be the new regulation on may 2018
GDPR will be the new regulation on may 2018
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
Data Protection and Comnpliance with the GDPR Event 22 september 2016
Data Protection and Comnpliance with the GDPR Event 22 september 2016 Data Protection and Comnpliance with the GDPR Event 22 september 2016
Data Protection and Comnpliance with the GDPR Event 22 september 2016
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 

Mehr von ASL (9)

Safety Footwear
Safety FootwearSafety Footwear
Safety Footwear
 
Ricoh Pro - Charis training
Ricoh Pro - Charis trainingRicoh Pro - Charis training
Ricoh Pro - Charis training
 
Ricoh Pro - Baron training
Ricoh Pro - Baron trainingRicoh Pro - Baron training
Ricoh Pro - Baron training
 
Safety Glasses
Safety GlassesSafety Glasses
Safety Glasses
 
Hearing Protection
Hearing ProtectionHearing Protection
Hearing Protection
 
Gloves
GlovesGloves
Gloves
 
Safe Use of PPE
Safe Use of PPESafe Use of PPE
Safe Use of PPE
 
ASL Fire Safety
ASL Fire SafetyASL Fire Safety
ASL Fire Safety
 
Manual Handling
Manual HandlingManual Handling
Manual Handling
 

Kürzlich hochgeladen

If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Kayode Fayemi
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
Kayode Fayemi
 
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
Sheetaleventcompany
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
raffaeleoman
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
amilabibi1
 

Kürzlich hochgeladen (20)

If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
 
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verifiedSector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
Dreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video TreatmentDreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video Treatment
 
Air breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsAir breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animals
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
 
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
 

GDPR training

  • 1. Co-Author: Trevor Clarence GDPR Accredited Presenter: Gary Raven
  • 2. What Is GDPR? •The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation the European Parliament, the Council of the European Union and the European Commission have strengthened to unify data protection for all individuals within the European Union (EU).
  • 3. The Six Principles of GDPR? Transparent, Specific, Limited, Accurate,Time limited & Secure The collection, storage and use of personal data should be…
  • 4. The Orders From Europe Directives •Requires each country to interpret the direction, then create their own laws (there is a lot of ‘varied interpretation’ across Europe) Regulation •Immediately applicable law in each county Enforcement If breaches of the regulation are apparent, sanctions and fines can be applied
  • 5. Timeline Directive Personal data Directive was introduced in 1995 Regulation May 2016- Regulation entered into force following publication in the EU Official Journal Enforcement 25th May 2018 - Following a 2 year post-adoption grace period, the GDPR will become fully enforceable throughout the European Union.
  • 6. Post Brexit The regulation has been created with a lot of input from and the full support of, the UK Government who have committed to the enforcement of GDPR. It should be noted that non-EU countries / organisations who intend to do business with EU members MUST comply with the GDPR regulation.
  • 7. Data Subject An identified natural person Data Controller: Determines the ‘Purpose and Means’ of the processing Data Processor: Processes personal data on behalf of the controller Components of the Regulation Example Data Subject -YOU Data Processor - ADP Personal data Data Controller - ASL Personal data
  • 8. 1. Name Trevor Clarence 2. Private email Trevclarence123@gmail.com 3. Photograph 4. Work email Trevor.clarence@asl-group.co.uk 5. IP Address 67.34.252.101 6. Bank Details 60876334-20-23-83 7. Trade Union No 12345678 8. Biometric number AE-17-B3-FG-4B-A3-G8 What is Personal Data? Important Note: The regulation applies to information held ‘digitally’ &/or on ‘Paper’ Question: Which elements of this information are classed as ‘Special Category’? Personal data means ‘any information’ that can be used to identify a natural person (either directly or indirectly) Note: Company addresses, departmental emails and web addresses are NOT classed as personal data.
  • 9. • Data Profiling is a method of searching data with mathematical algorithms to identify trends and hidden patterns, profile customers, and then predict how these trends or customers will behave in the future. Data Profiling Mr Data Subject DOB: 18/01/99 Email: dsubject@gmail.com Union Number: DS125769879uk
  • 10. • Lawful Reason - To meet a contractual obligation • We promise to deliver within 48 hours! (we will need your address) • Legitimate Reason – To fulfill an assumed requirement • Your support is about to end, we want to contact you to offer the renewal • Consent • Please tick this box if you want to receive information about similar products Reasons for ‘holding/processing’ personal data As a business, which should be the last reason you rely on? 
  • 11. • What data do you have on me? • What consent do you have for processing my data? • What are you doing with my data? • Where is the data held? • Who has access to my data? • How long will you keep my data? • I no longer want you to keep my data (forget me!) What rights does a Data Subject have?
  • 12. • Every Organisation that holds or processes Personal data • Public Authorities • Schools, Colleges and Academies • County & district councils • Charities and charitable groups Who is affected? • Businesses (large, Medium and Small) • SMEs • Facebook, Amazon etc • Kyocera • ASL
  • 13. Is it another Millennium bug? •No: Very serious project involving a lot of people and a lot of money Is it important? Is there any scaremongering? • There are two tiers of administrative fines that can be levied: • 1) Up to €10 million, or 2% annual global turnover – whichever is higher. • 2) Up to €20 million, or 4% annual global turnover – whichever is higher. • The fines are based on the specific articles of the Regulation that the organisation has breached.
  • 14. Top 20 ICO FinesTo Date • The Independent Enquiry into Child Sex Abuse £200,000 Sent a bulk email identifying possible victims of abuseOct-17 • Newday Limited £230,000 Unsolicited emails Nov-18 • Barrington Claims £250,000 Unrequested automated marketing calls Sep-17 • Yahoo £250,000 500 million user accounts compromised Sep-18 • EasyLeads Limited £260,00016.7 million automated marketing callsSep-18 • Road Accident Consulting (trading as MediaTactics) £270,000 22 million unsolicted personal injury calls Mar-17 • Holmes Financial Solutions £300,000 8.8 million marketing calls Jan-18 • Brighton & Sussex University Hospital FoundationTrust £325,000The trust was fined when a contractor hired to delete personal data from PC hard drives sold the drives on Ebay Jun-17 • The Crown Prosecution Service £325,000 Lost unencrypted DVDs of video recorded testimony from victims of child abuse May-18
  • 15. Top 20 ICO FinesTo Date • Miss-Sold Products UK £350,000 75 million unsolicted PPI claim calls Jan-18 • Your Money Rights £350,000 146 million unsolicted PPI claim calls Sep-17 • Uber £385,000 Paying off hackers who stole personal data on 2.7 million customers and neglected to tell the customers this had happened Nov-18 • Carphone Warehouse £400,0003 million credit card data records lost to hackers Jan-18 • Kuerboom Communications £400,00099 million nuisance PPI calls May-17 • TalkTalk £400,000157,000 data records lost to hackers including bank sort and account numbers Oct-16 • Equifax £500,000 15 million data records lost to hackers including name, address, bank and driving licence detailsSep-18 • Facebook £500,000 87 million FB users information shared with Cambridge Analytica Oct-18
  • 16. Do organisations need to take it seriously? Our customers have rights under the legislation Data Subject requests are a possibility Telephone calls already to ASL What is ASL’s policy? Requests inTenders The ‘data privacy aspects’ of the contract between the customer and ASL. What assurances can be given to the customer that ASL is fully compliant with GDPR? Is it important? Is there any scaremongering?
  • 17. Buy-in from the Board Department Heads In-house project Review all processes that hold-process Personal Data What data,What do we do with it, Where held, Who access, How long etc What are ASL doing? Staff training/overview of GDPR Sales Opportunities Sales/marketing gain interest from the customer (Mail-Shot, Sales meetings) Detailed customer review from Professional services PDF with 4 sections GDPR Overview How ASL can help with GDPR compliance Extending GDPR compliance with Cyber Security ASL’s Commitment to GDPR (Statement from the MD)
  • 18. How ASL can help it’s customers (with the products & services supplied by ASL) • Your Printer/MFD may have an internal (HDD) Hard Disk Drive or (SSD) Solid State Drive, these drive's hold data and complete varies functions in the processing of scanning, copying and printing (user settings, device information, image data etc).The sensitive or confidential information that is stored on these drives should not be leaked from the MFD/Printer, the various protection methods include: • HDD/SSD Encryption. • Automatic HDD Overwrite.
  • 19. Business culture • ICO = Information Commissioning Office - we want to see a business culture • GDPR is not a ‘Tick Box’ regulation By design and default • ICO = Personal data protection should be a business fundamental The fines and business drivers • 20 Million Euros • Can you respond within 1 month to a Data Subject Request? GDPR ‘gossip’ Data Subject Requests Can beVerbal Know what to do if you get one! The ‘right’ to complain If I’m not satisfied, I will report you to the ICO DPO (Data Protection Officer) Must have if: Public body, or high risk to data subjects Is GDPR the new PPI? Are people mis-selling the importance of the GDPR Lawyers are getting ready to support the claims
  • 20. Data Subject: An identified natural person Data Controller: Determines the ‘Purpose and Means’ of the processing Data Processor: Processes personal data on behalf of the controller Data Processing: Collection, storage, making available, use, alteration Data Profiling: Automated processing to predict: interests, wealth etc Six Principles Transparent, Specific, Limited, Accurate, Duration, Secure ICO: The UK GDPR supervisors (advertising campaign) Data Breach: Loss, destruction, unauthorised disclosure GDPR Key Definitions
  • 21. Data Subject Request: Take any contact details Ascertain the nature of the request Pass this to your line manager – preferably in writing (email) If your line manager is unavailable –Trevor Clarence GDPR Key Staff Actions ASL Policy Request: Take contact details - Pass this to your line manager – preferably in writing (email) Ascertain the nature of the request Send a copy of the GDPR PDF document Steer the contact to the GDPR section of the ASL website
  • 22. Co-Author: Trevor Clarence GDPR Accredited Presenter: Gary Raven