SlideShare ist ein Scribd-Unternehmen logo
1 von 36
GDPR: Sink or Swim
14th November 2017
Overwhelmed
What should I do?
Does it apply to me?
What does it mean?
Where is my data?
Arrrggh!
GDPR?!?
General Data Protection
Regulation (GDPR)
Accountability Transparency
Individuals’ Rights
GDPR Myths
I don’t need to
do anything
until May 2018
We won’t be in
the EU soon, it
won’t apply
Consent is the
only way I can
process data
My database
is secure, I’m
ready
GDPR is Coming…
New law applies if:
• Established in the EU; or
• Offer goods and services to EU residents; or
• Monitor behaviour of EU residents.
Full enforcement: 25th May 2018
• Businesses large and small will need to meet the requirements
by 2018.
• From May 2018 a breach could cost up to €20 million or 4% of
annual turnover.
Be Prepared!
134
Working Days
to Go!
People
Who is responsible for
Data Protection within your business?
IT	
HR	
Marke+ng	
Legal
Board	of	Directors	
Staff	
None	of	the	above
Data Protection Officer (DPO)
Consider where this role sits with
organisational structure and
governance.
All organisations allocate somebody to take
responsibility for data protection compliance
Senior executive,
reporting to board.
Data Protection Officer
(DPO)
Assess whether your organisation needs to formally
designate the role of DPO.
• A public authority (except for courts acting in their
judicial capacity)
• An organisation that carries out the regular and
systematic monitoring of individuals on a large scale; or
• An organisation that carries out large scale processing
of special categories of data, such as health records, or
information about criminal convictions.
What is the attitude towards data
protection in your organisation?
Data
Definition of Personal Data
• Personal data: is data about a living individual who can be
identified either directly from the data or indirectly by reference to
other information.
• Includes IP Address and Location data
** where dataset is small, a person may be identifiable without
their name being recorded **
Definition of
Personal Sensitive Data
• Personal Sensitive: Data consisting of racial or ethnic origin,
political opinions, religious beliefs, trade union membership,
genetic data, biometric data, data concerning health or data
concerning an individual’s sex life or sexual orientation
Data Mapping
When	you	think	about	your	business	data:	
• Do	you	know	what	personal	data	you	have?	
• Do	you	know	where	your	personal	data	is?	
• Do	you	know	how	long	you	can	store	the	data?
Personal Data
Most organisations collect, store, move
and access personal data in their daily activities
Sales
Customer
Relationship
Management
Marketing Recruitment
Employees Suppliers
Third party
Photos
CCTV
Personal data
Why are you holding personal data?
How are you going to use it?
What is your legal basis for processing personal
data?
Legal Basis for Processing
Personal Data
• Consent
• Contract
• Vital Interests
• Public Task
• Comply with legal obligation
• Legitimate Interests
Consent under GDPR
Yes I want your newsletter
Active (Opt in, not opt-out)
Freely given
Informed
Ability to withdraw at any time
Retrospective
Data Controller & Data Processor
Relationship
Must maintain register of data
processing activities
Must report every data breach to
the data controller
Check for data provenance
Data ProcessorData Controller
High duty of care
Contract to include details and
duration of processing
Contract to outline expectations -
e.g.data breach, audit assistance
Process
Subject Access Requests
Dear Company A,
My name is Kellie Peters. I would
like to know what information
your company has about me?
How would you handle this request?
Right to Erasure
Dear Company A,
My name is Kellie Peters. I would
like you to delete the information
your company holds on me.
How would you handle this request?
Data Breaches
Information Commissioner’s Office (ICO) report found that the
majority of individuals do not trust organisations with their
personal data.
Customers, staff & regulators have zero tolerance towards data
breaches. Whether a breach was malicious or an accident, as a
business you have a responsibility to protect personal data
Data Breaches
What is your current approach to
dealing with a data breach?
Under GDPR, what timeframe MUST
you report a data breach within?
Data Accuracy
Inaccurate data leads to wasted
• marketing spend
• resources
• staff time
Potentially up to 12% of revenue according to Experian
Fundamental principle of data protection, currently & under
GDPR, is to only collect data that is needed and you must
maintain its accuracy
People
Data Protection by Design
• Data Privacy needs to be at the heart of all future
projects that involve personal/personal sensitive
data.
• Organisations need to be able to demonstrate their
compliance with GDPR principles, including:
• adopting “data protection by design” measures
e.g. the use of pseudonymisation techniques;
• detailed privacy impact assessment.
Be Transparent
• Tell people who you are, how you’ll use their data
and if you intend to share it
• Review privacy notices to include:
• legal basis for processing the data
• how long you’ll hold the data
• what to do if they believe there’s a problem with
your processing.
Employee Training
All staff involved in
processing personal data
must have a basic
understanding of data
protection
Employee Training
Staff with specialist skills such as:
Marketing
IT & Security
Database Management
HR
May need additional data protection
training to cover rules relevant to their role
Question
Data is awesome
Business Insight
Data is valuable
Engaged staff
Secure data
Confident
Next steps to take
Our Recommendations for
Action
• Involve people
• Set accountability
• Map data flows
• Determine legal basis
• Implement / Update processes
• Be transparent
• Engage people
How are you going to prepare?
GDPR Support
Awareness
Engagement
Training
Ownership
What?
Where?
When?
Why?
Policy
Systems
Process
Feedback
Thank You
regina.lally@dbxuk.com
www.dbxuk.com / @DbxUK

Weitere ähnliche Inhalte

Was ist angesagt?

Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
GDPR Data Life Cycle
GDPR Data Life CycleGDPR Data Life Cycle
GDPR Data Life CycleJatin Kochhar
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceIDERA Software
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?Jatin Kochhar
 
Data protection ppt
Data protection pptData protection ppt
Data protection pptgrahamwell
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Actmrmwood
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityDean Sappey
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRRotary International
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
A very clear gdpr story for normal people
A very clear gdpr story for normal peopleA very clear gdpr story for normal people
A very clear gdpr story for normal peopleHans Demeyer
 
GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOUCliff Gibson
 

Was ist angesagt? (20)

Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
GDPR Seminar Slides
GDPR Seminar SlidesGDPR Seminar Slides
GDPR Seminar Slides
 
GDPR Data Life Cycle
GDPR Data Life CycleGDPR Data Life Cycle
GDPR Data Life Cycle
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
What does GDPR mean for your charity?
What does GDPR mean for your charity?What does GDPR mean for your charity?
What does GDPR mean for your charity?
 
GDPR Data Lifecycle
GDPR Data LifecycleGDPR Data Lifecycle
GDPR Data Lifecycle
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to Opportunity
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
A very clear gdpr story for normal people
A very clear gdpr story for normal peopleA very clear gdpr story for normal people
A very clear gdpr story for normal people
 
GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOU
 

Ähnlich wie GDPR - Sink or Swim

GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Forums financiers de Wallonie
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxTimBee1
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Lauren Isaacs
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxTimBee1
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Followetouches
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Software Integrity Group
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteClive Rich
 

Ähnlich wie GDPR - Sink or Swim (20)

GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Follow
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 

Mehr von Guy Griffiths

Sales KPIs and Re-engaging Ex-members
Sales KPIs and Re-engaging Ex-membersSales KPIs and Re-engaging Ex-members
Sales KPIs and Re-engaging Ex-membersGuy Griffiths
 
ukactive Leisure Trends
ukactive Leisure Trendsukactive Leisure Trends
ukactive Leisure TrendsGuy Griffiths
 
DataHub Refining Data
DataHub Refining DataDataHub Refining Data
DataHub Refining DataGuy Griffiths
 
Sales & Retention Convention Spring'17 - Prospecting
Sales & Retention Convention Spring'17 - ProspectingSales & Retention Convention Spring'17 - Prospecting
Sales & Retention Convention Spring'17 - ProspectingGuy Griffiths
 
Sales & Retention Convention Spring'17 - Mystery Shopping
Sales & Retention Convention Spring'17 - Mystery ShoppingSales & Retention Convention Spring'17 - Mystery Shopping
Sales & Retention Convention Spring'17 - Mystery ShoppingGuy Griffiths
 
Sales & Retention April'17 - The Tour
Sales & Retention April'17 - The TourSales & Retention April'17 - The Tour
Sales & Retention April'17 - The TourGuy Griffiths
 
Sales & Retention Convention - Managing Online Reviews
Sales & Retention Convention - Managing Online ReviewsSales & Retention Convention - Managing Online Reviews
Sales & Retention Convention - Managing Online ReviewsGuy Griffiths
 
Sales & Retention Convention - Referral - session 3
Sales & Retention Convention - Referral - session 3Sales & Retention Convention - Referral - session 3
Sales & Retention Convention - Referral - session 3Guy Griffiths
 
Sales & Retention Convention - Outreach - Session 1
Sales & Retention Convention - Outreach - Session 1Sales & Retention Convention - Outreach - Session 1
Sales & Retention Convention - Outreach - Session 1Guy Griffiths
 
Sales & Retention Convention - Part 6
Sales & Retention Convention - Part 6Sales & Retention Convention - Part 6
Sales & Retention Convention - Part 6Guy Griffiths
 

Mehr von Guy Griffiths (10)

Sales KPIs and Re-engaging Ex-members
Sales KPIs and Re-engaging Ex-membersSales KPIs and Re-engaging Ex-members
Sales KPIs and Re-engaging Ex-members
 
ukactive Leisure Trends
ukactive Leisure Trendsukactive Leisure Trends
ukactive Leisure Trends
 
DataHub Refining Data
DataHub Refining DataDataHub Refining Data
DataHub Refining Data
 
Sales & Retention Convention Spring'17 - Prospecting
Sales & Retention Convention Spring'17 - ProspectingSales & Retention Convention Spring'17 - Prospecting
Sales & Retention Convention Spring'17 - Prospecting
 
Sales & Retention Convention Spring'17 - Mystery Shopping
Sales & Retention Convention Spring'17 - Mystery ShoppingSales & Retention Convention Spring'17 - Mystery Shopping
Sales & Retention Convention Spring'17 - Mystery Shopping
 
Sales & Retention April'17 - The Tour
Sales & Retention April'17 - The TourSales & Retention April'17 - The Tour
Sales & Retention April'17 - The Tour
 
Sales & Retention Convention - Managing Online Reviews
Sales & Retention Convention - Managing Online ReviewsSales & Retention Convention - Managing Online Reviews
Sales & Retention Convention - Managing Online Reviews
 
Sales & Retention Convention - Referral - session 3
Sales & Retention Convention - Referral - session 3Sales & Retention Convention - Referral - session 3
Sales & Retention Convention - Referral - session 3
 
Sales & Retention Convention - Outreach - Session 1
Sales & Retention Convention - Outreach - Session 1Sales & Retention Convention - Outreach - Session 1
Sales & Retention Convention - Outreach - Session 1
 
Sales & Retention Convention - Part 6
Sales & Retention Convention - Part 6Sales & Retention Convention - Part 6
Sales & Retention Convention - Part 6
 

Kürzlich hochgeladen

The byproduct of sericulture in different industries.pptx
The byproduct of sericulture in different industries.pptxThe byproduct of sericulture in different industries.pptx
The byproduct of sericulture in different industries.pptxShobhayan Kirtania
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Celine George
 
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...Sapna Thakur
 
social pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajansocial pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajanpragatimahajan3
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 
mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docxPoojaSen20
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxSayali Powar
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsTechSoup
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
Measures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDMeasures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDThiyagu K
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformChameera Dedduwage
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 

Kürzlich hochgeladen (20)

The byproduct of sericulture in different industries.pptx
The byproduct of sericulture in different industries.pptxThe byproduct of sericulture in different industries.pptx
The byproduct of sericulture in different industries.pptx
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17
 
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
 
social pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajansocial pharmacy d-pharm 1st year by Pragati K. Mahajan
social pharmacy d-pharm 1st year by Pragati K. Mahajan
 
Advance Mobile Application Development class 07
Advance Mobile Application Development class 07Advance Mobile Application Development class 07
Advance Mobile Application Development class 07
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 
mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docx
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
Measures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDMeasures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SD
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy Reform
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 

GDPR - Sink or Swim

  • 1. GDPR: Sink or Swim 14th November 2017
  • 2. Overwhelmed What should I do? Does it apply to me? What does it mean? Where is my data? Arrrggh! GDPR?!?
  • 3.
  • 4. General Data Protection Regulation (GDPR) Accountability Transparency Individuals’ Rights
  • 5. GDPR Myths I don’t need to do anything until May 2018 We won’t be in the EU soon, it won’t apply Consent is the only way I can process data My database is secure, I’m ready
  • 6. GDPR is Coming… New law applies if: • Established in the EU; or • Offer goods and services to EU residents; or • Monitor behaviour of EU residents. Full enforcement: 25th May 2018 • Businesses large and small will need to meet the requirements by 2018. • From May 2018 a breach could cost up to €20 million or 4% of annual turnover.
  • 9. Who is responsible for Data Protection within your business? IT HR Marke+ng Legal Board of Directors Staff None of the above
  • 10. Data Protection Officer (DPO) Consider where this role sits with organisational structure and governance. All organisations allocate somebody to take responsibility for data protection compliance Senior executive, reporting to board.
  • 11. Data Protection Officer (DPO) Assess whether your organisation needs to formally designate the role of DPO. • A public authority (except for courts acting in their judicial capacity) • An organisation that carries out the regular and systematic monitoring of individuals on a large scale; or • An organisation that carries out large scale processing of special categories of data, such as health records, or information about criminal convictions.
  • 12. What is the attitude towards data protection in your organisation?
  • 13. Data
  • 14. Definition of Personal Data • Personal data: is data about a living individual who can be identified either directly from the data or indirectly by reference to other information. • Includes IP Address and Location data ** where dataset is small, a person may be identifiable without their name being recorded **
  • 15. Definition of Personal Sensitive Data • Personal Sensitive: Data consisting of racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning an individual’s sex life or sexual orientation
  • 16. Data Mapping When you think about your business data: • Do you know what personal data you have? • Do you know where your personal data is? • Do you know how long you can store the data?
  • 17. Personal Data Most organisations collect, store, move and access personal data in their daily activities Sales Customer Relationship Management Marketing Recruitment Employees Suppliers Third party Photos CCTV
  • 18. Personal data Why are you holding personal data? How are you going to use it? What is your legal basis for processing personal data?
  • 19. Legal Basis for Processing Personal Data • Consent • Contract • Vital Interests • Public Task • Comply with legal obligation • Legitimate Interests
  • 20. Consent under GDPR Yes I want your newsletter Active (Opt in, not opt-out) Freely given Informed Ability to withdraw at any time Retrospective
  • 21. Data Controller & Data Processor Relationship Must maintain register of data processing activities Must report every data breach to the data controller Check for data provenance Data ProcessorData Controller High duty of care Contract to include details and duration of processing Contract to outline expectations - e.g.data breach, audit assistance
  • 23. Subject Access Requests Dear Company A, My name is Kellie Peters. I would like to know what information your company has about me? How would you handle this request?
  • 24. Right to Erasure Dear Company A, My name is Kellie Peters. I would like you to delete the information your company holds on me. How would you handle this request?
  • 25. Data Breaches Information Commissioner’s Office (ICO) report found that the majority of individuals do not trust organisations with their personal data. Customers, staff & regulators have zero tolerance towards data breaches. Whether a breach was malicious or an accident, as a business you have a responsibility to protect personal data
  • 26. Data Breaches What is your current approach to dealing with a data breach? Under GDPR, what timeframe MUST you report a data breach within?
  • 27. Data Accuracy Inaccurate data leads to wasted • marketing spend • resources • staff time Potentially up to 12% of revenue according to Experian Fundamental principle of data protection, currently & under GDPR, is to only collect data that is needed and you must maintain its accuracy
  • 29. Data Protection by Design • Data Privacy needs to be at the heart of all future projects that involve personal/personal sensitive data. • Organisations need to be able to demonstrate their compliance with GDPR principles, including: • adopting “data protection by design” measures e.g. the use of pseudonymisation techniques; • detailed privacy impact assessment.
  • 30. Be Transparent • Tell people who you are, how you’ll use their data and if you intend to share it • Review privacy notices to include: • legal basis for processing the data • how long you’ll hold the data • what to do if they believe there’s a problem with your processing.
  • 31. Employee Training All staff involved in processing personal data must have a basic understanding of data protection
  • 32. Employee Training Staff with specialist skills such as: Marketing IT & Security Database Management HR May need additional data protection training to cover rules relevant to their role
  • 33. Question Data is awesome Business Insight Data is valuable Engaged staff Secure data Confident Next steps to take
  • 34. Our Recommendations for Action • Involve people • Set accountability • Map data flows • Determine legal basis • Implement / Update processes • Be transparent • Engage people How are you going to prepare?