SlideShare a Scribd company logo
1 of 18
Drinks
sponsors:
Partner
sponsor:
Lead
sponsor:
Media
partner:
Tech
partner:
DATA PROTECTION:
YOUR CHARITY’S
BIGGEST RISK?
CHAIR
ELIZABETH CHAMBERLAIN
HEAD OF POLICY AND PUBLIC SERVICES,
NCVO
SPEAKERS
LAWRIE SIMANOWITZ
PARTNER, BATES WELLS BRAITHWAITE
RICHARD MARBROW
GROUP MANAGER, CORPORATE
GOVERNANCE, INFORMATION
COMMISSIONER'S OFFICE
Data Protection and
preparing for GDPR
NCVO
14 November 2017
Introduction
Big developments in data protection in last year – possibly more for
charities than any other sector:
• ICO issued monetary penalty notices to 11 charities
• GDPR implementation 25 May 2018
• Resulting changes to the Fundraising Regulator’s code and (at times
confused) “guidance”
• Replacement of PECR – new e-privacy directive
• Data Protection Bill, published 13 September 2017
A lot of changes required – but no fundamental changes in principle.
Consent (1)
• Biggest area of concern for data controllers at the moment.
• Starting point – consent is not always required.
• Legitimate interest is often a valid alternative to consent and will
remain under GDPR except for public bodies – which will need to
move to a more consent-based system.
• Consent is, and will continue to be, main route to processing sensitive
personal data, and sending direct marketing electronically (email, text,
social media, and non-TPS registered phone numbers).
Consent (2)
• In fact not much change and, contrary to popular myth, tick box opt-in
will not be the only way of obtaining consent.
• Consent must be:
– Specific (not new)
– Informed (not new)
– Freely given (more detail on this in GDPR)
– Unambiguous (new but doesn’t add much)
– An affirmative act (new, but no change from current ICO guidance)
Consent (3)
• Key practical consequence is greater granularity:
• GDPR requires separate consent for different processing
“operations” (purposes) (eg fundraising, volunteering, wealth
screening (?)). ICO draft guidance says this applies “wherever
appropriate” and not if it is unduly disruptive. At a minimum consent
must cover all purposes.
• GDPR says there must be consent for each activity. Unclear what
activities are, but assumed to include channels of communication.
But ICO draft guidance says not if the activities are interdependent (so
may not need to all be listed – better to do so if possible, in privacy
policy). At a minimum consent must cover all activities.
Consent (4)
Other consent issues of note:
• Opt-out versus opt-in? An affirmative act is required – doesn’t have to
be tick box opt-in. If individuals freely give you their details and you
offer them an opportunity to opt out of DM, then you have lawfully
obtained consent.
• What if existing consent is not GDPR compliant? Key point is that you
have consent for the activities you wish to undertake. If insufficiently
granular then seems unlikely to be top of the list for ICO compliance
unless there are other concerns.
• How long is consent valid for? Two years is safe. Four to five years
is probably safe – try to get evidence. Longer than that, only if
specific justification.
Consent (5)
More consent issues of note:
• Keep clear records to demonstrate compliance – what individuals
were told, when and how they consented
• The right to withdraw consent must be stated at time consent is
collected
• Giving consent must not be mandatory if buying goods or services
(but, arguably, technically compliant if mandatory when giving a
donation)
Privacy statements/other communications with data subjects
Generally more onerous requirements. Privacy statements or other
communications with individuals must include:
• Identity and contact details of data controller
• Purposes of the processing
• Legal basis for processing (e.g. consent or legitimate interest - and what your
legitimate interest is)
• Recipient/categories of recipient of the personal data
• Transfer of data outside EEA
• How long data will be held for
• Existence of automatic decision making
• Individuals’ rights
• Right to lodge a complaint with ICO
• Right to withdraw consent
The statement is an opportunity to achieve fairness
ICO guidance
Data Protection Officer
• GDPR requires data controllers and data processes to appoint a DPO
– in relatively limited circumstances.
• Careful analysis required.
• If not mandatory for your charity then sensible to appoint someone to
be lead on data protection issues but possibly without formal status of
DPO.
What will the DPO do?
GDPR specifically provides that:
• Must be involved in all issues relating to data protection properly and
in a timely manner
• Advisory role
• Monitor compliance with GDPR and other DP legislation including
internal policies
• Contact point for ICO and data subjects (contact details published)
• Advise on DPIAs
• Expert knowledge of data protection law and practices
• Need active support by senior management – must report directly to
highest management level
• May not be dismissed or penalised for performing tasks
Do we need to appoint a DPO?
Article 37(1) GDPR sets out when you must appoint a DPO
1. Processing is carried out by a public authority or body (except
courts)
2. Core activities involve regular and systematic monitoring of
individuals on a large scale
3. Core activities involve processing sensitive personal data (or data
relating to criminal convictions and offences) on a large scale
EU or national law may require appointment of DPOs in other situations
Working with third party data processors (1)
Some aspects of DPA will apply directly to data processors:
• Implement appropriate security measures
• Report breaches to data controller (not to the ICO)
• Appoint Data Protection Officer (where required – see earlier slide)
• Keep records of processing
Working with third party data processors (2)
Data controllers required to seek guarantees – in particular specific
provisions must go into contracts with data processors.
• Only to process data on instructions of data controller, and keep data
secure (not new)
• More detail about the processing (including duration)
• Comply with data controller’s requirements on transferring data
outside of the EEA
• Ensure staff are under a duty of confidence
• Assist controllers to comply with subject access requests
• Obtain authority to appoint sub-processors (and pass on obligations)
• Appoint DPO (if required)
• Return or delete data at end of agreement
• Demonstrate compliance and allow the data controller to audit
Other changes
Greater rights for individuals including:
– Right to be forgotten
– Right to object
– Right of access (subject access request) now within one month and
cannot charge a fee
• Data privacy impact assessments
• Mandatory reporting of security breaches within 72 hours unless the
breach is unlikely to result in a risk to the rights and freedoms of
individuals
• “Notification” (i.e. registration) abolished
What next?
• Audit
• Mapping exercise?
• Our view is that key areas of focus should be:
– Data protection policy, privacy policy
– Collection of consent and fair processing information
– Data retention policy
– Record keeping
– Agreements with data processors
– Training of staff in data protection compliance
Lawrence Simanowitz
Partner
Bates Wells Braithwaite
Tel: 020 7551 7796
l.simanowitz@bwbllp.com

More Related Content

What's hot

Improving liquidity management: Scenario-based cash forecasting
Improving liquidity management: Scenario-based cash forecastingImproving liquidity management: Scenario-based cash forecasting
Improving liquidity management: Scenario-based cash forecastingDeloitte United States
 
Trading and legal structures
Trading and legal structuresTrading and legal structures
Trading and legal structureswalescva
 
EU General Data Protection Regulation: Practical steps for compliance, third ...
EU General Data Protection Regulation: Practical steps for compliance, third ...EU General Data Protection Regulation: Practical steps for compliance, third ...
EU General Data Protection Regulation: Practical steps for compliance, third ...Deloitte United States
 
The unique and complex considerations of digital asset custody
The unique and complex considerations of digital asset custodyThe unique and complex considerations of digital asset custody
The unique and complex considerations of digital asset custodyDeloitte United States
 
Cyber wargaming: Building cyber resilience in an era of cyberattacks
Cyber wargaming: Building cyber resilience in an era of cyberattacksCyber wargaming: Building cyber resilience in an era of cyberattacks
Cyber wargaming: Building cyber resilience in an era of cyberattacksDeloitte United States
 
FAQ's about the new FASB leases standard: You're not alone
FAQ's about the new FASB leases standard: You're not aloneFAQ's about the new FASB leases standard: You're not alone
FAQ's about the new FASB leases standard: You're not aloneDeloitte United States
 
Protecting Nonprofit Status 2011
Protecting Nonprofit Status 2011Protecting Nonprofit Status 2011
Protecting Nonprofit Status 2011Miriam Robeson
 
As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...
As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...
As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...Deloitte United States
 
2010 Smalll Business Presentation for HAUL
2010 Smalll Business Presentation for HAUL2010 Smalll Business Presentation for HAUL
2010 Smalll Business Presentation for HAULErin McClarty
 
Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks
Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks
Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks Deloitte United States
 
Status of Beneficial Ownership Transparency in Canada
Status of Beneficial Ownership Transparency in CanadaStatus of Beneficial Ownership Transparency in Canada
Status of Beneficial Ownership Transparency in CanadaAlessa
 
Beneficial Ownership Rules: Global and Canada Perspective
Beneficial Ownership Rules: Global and Canada PerspectiveBeneficial Ownership Rules: Global and Canada Perspective
Beneficial Ownership Rules: Global and Canada PerspectiveAlessa
 
Mines and Money Access Africa
Mines and Money Access AfricaMines and Money Access Africa
Mines and Money Access Africabrandonmunro
 
Modernizing compliance: A tech lens on value protection and creation
Modernizing compliance: A tech lens on value protection and creationModernizing compliance: A tech lens on value protection and creation
Modernizing compliance: A tech lens on value protection and creationDeloitte United States
 
Hedge accounting: Simplifying the accounting for hedging activities
Hedge accounting: Simplifying the accounting for hedging activitiesHedge accounting: Simplifying the accounting for hedging activities
Hedge accounting: Simplifying the accounting for hedging activitiesDeloitte United States
 
Legal Issues for Early-Stage Companies
Legal Issues for Early-Stage CompaniesLegal Issues for Early-Stage Companies
Legal Issues for Early-Stage CompaniesQuarles & Brady
 
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...Deloitte United States
 

What's hot (20)

Law Firm Planning
Law Firm PlanningLaw Firm Planning
Law Firm Planning
 
Improving liquidity management: Scenario-based cash forecasting
Improving liquidity management: Scenario-based cash forecastingImproving liquidity management: Scenario-based cash forecasting
Improving liquidity management: Scenario-based cash forecasting
 
The ethics of crowdfunding, revisited
The ethics of crowdfunding, revisitedThe ethics of crowdfunding, revisited
The ethics of crowdfunding, revisited
 
Trading and legal structures
Trading and legal structuresTrading and legal structures
Trading and legal structures
 
EU General Data Protection Regulation: Practical steps for compliance, third ...
EU General Data Protection Regulation: Practical steps for compliance, third ...EU General Data Protection Regulation: Practical steps for compliance, third ...
EU General Data Protection Regulation: Practical steps for compliance, third ...
 
The unique and complex considerations of digital asset custody
The unique and complex considerations of digital asset custodyThe unique and complex considerations of digital asset custody
The unique and complex considerations of digital asset custody
 
Cyber wargaming: Building cyber resilience in an era of cyberattacks
Cyber wargaming: Building cyber resilience in an era of cyberattacksCyber wargaming: Building cyber resilience in an era of cyberattacks
Cyber wargaming: Building cyber resilience in an era of cyberattacks
 
FAQ's about the new FASB leases standard: You're not alone
FAQ's about the new FASB leases standard: You're not aloneFAQ's about the new FASB leases standard: You're not alone
FAQ's about the new FASB leases standard: You're not alone
 
Protecting Nonprofit Status 2011
Protecting Nonprofit Status 2011Protecting Nonprofit Status 2011
Protecting Nonprofit Status 2011
 
As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...
As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...
As Enforcement Funding Increases, Organizations Report Varied Anti-Human Traf...
 
2010 Smalll Business Presentation for HAUL
2010 Smalll Business Presentation for HAUL2010 Smalll Business Presentation for HAUL
2010 Smalll Business Presentation for HAUL
 
The Current M&A Environment
The Current M&A EnvironmentThe Current M&A Environment
The Current M&A Environment
 
Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks
Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks
Executives’ Ransomware Concerns Are High, But Few Are Prepared for Such Attacks
 
Status of Beneficial Ownership Transparency in Canada
Status of Beneficial Ownership Transparency in CanadaStatus of Beneficial Ownership Transparency in Canada
Status of Beneficial Ownership Transparency in Canada
 
Beneficial Ownership Rules: Global and Canada Perspective
Beneficial Ownership Rules: Global and Canada PerspectiveBeneficial Ownership Rules: Global and Canada Perspective
Beneficial Ownership Rules: Global and Canada Perspective
 
Mines and Money Access Africa
Mines and Money Access AfricaMines and Money Access Africa
Mines and Money Access Africa
 
Modernizing compliance: A tech lens on value protection and creation
Modernizing compliance: A tech lens on value protection and creationModernizing compliance: A tech lens on value protection and creation
Modernizing compliance: A tech lens on value protection and creation
 
Hedge accounting: Simplifying the accounting for hedging activities
Hedge accounting: Simplifying the accounting for hedging activitiesHedge accounting: Simplifying the accounting for hedging activities
Hedge accounting: Simplifying the accounting for hedging activities
 
Legal Issues for Early-Stage Companies
Legal Issues for Early-Stage CompaniesLegal Issues for Early-Stage Companies
Legal Issues for Early-Stage Companies
 
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
 

Similar to A5: Data protection: Your charity's biggest risk?

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?TAG Alliances
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Big data needs big protection
Big data needs big protectionBig data needs big protection
Big data needs big protectionNoel Hatch
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection RegulationGrittyCC
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 

Similar to A5: Data protection: Your charity's biggest risk? (20)

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Big data needs big protection
Big data needs big protectionBig data needs big protection
Big data needs big protection
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 

More from NCVO - National Council for Voluntary Organisations

More from NCVO - National Council for Voluntary Organisations (20)

AGM 2022: Vision for Volunteering
AGM 2022: Vision for VolunteeringAGM 2022: Vision for Volunteering
AGM 2022: Vision for Volunteering
 
AGM 2022: Building networks
AGM 2022: Building networksAGM 2022: Building networks
AGM 2022: Building networks
 
AGM 2022: Membership
AGM 2022: MembershipAGM 2022: Membership
AGM 2022: Membership
 
AGM 2022: Time Well Spent
AGM 2022: Time Well SpentAGM 2022: Time Well Spent
AGM 2022: Time Well Spent
 
AGM 2022: Undertaking a governace review
AGM 2022: Undertaking a governace reviewAGM 2022: Undertaking a governace review
AGM 2022: Undertaking a governace review
 
National Volunteering Forum: Engaging volunteers and paid staff
National Volunteering Forum: Engaging volunteers and paid staffNational Volunteering Forum: Engaging volunteers and paid staff
National Volunteering Forum: Engaging volunteers and paid staff
 
Improving organisational resilience: What trustees need to consider
Improving organisational resilience: What trustees need to considerImproving organisational resilience: What trustees need to consider
Improving organisational resilience: What trustees need to consider
 
NCVO webinar: An update on changes to the Charity Governance Code
NCVO webinar: An update on changes to the Charity Governance CodeNCVO webinar: An update on changes to the Charity Governance Code
NCVO webinar: An update on changes to the Charity Governance Code
 
Undertaking a governance effectiveness review
Undertaking a governance effectiveness reviewUndertaking a governance effectiveness review
Undertaking a governance effectiveness review
 
NCVO/Zurich webinar: Beyond cyber essentials
NCVO/Zurich webinar: Beyond cyber essentialsNCVO/Zurich webinar: Beyond cyber essentials
NCVO/Zurich webinar: Beyond cyber essentials
 
NCVO/Zurich webinar: Safeguarding through covid-19 and beyond
NCVO/Zurich webinar: Safeguarding through covid-19 and beyondNCVO/Zurich webinar: Safeguarding through covid-19 and beyond
NCVO/Zurich webinar: Safeguarding through covid-19 and beyond
 
Decision making in a crisis: Collaboration and merger
Decision making in a crisis: Collaboration and mergerDecision making in a crisis: Collaboration and merger
Decision making in a crisis: Collaboration and merger
 
Easing of lockdown practical considerations for managing and support staff
Easing of lockdown practical considerations for managing and support staffEasing of lockdown practical considerations for managing and support staff
Easing of lockdown practical considerations for managing and support staff
 
How to manage operational change in a time of uncertainty
How to manage operational change in a time of uncertaintyHow to manage operational change in a time of uncertainty
How to manage operational change in a time of uncertainty
 
Easing of lockdown – practical considerations for managing and supporting staff
Easing of lockdown – practical considerations for managing and supporting staffEasing of lockdown – practical considerations for managing and supporting staff
Easing of lockdown – practical considerations for managing and supporting staff
 
NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...
NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...
NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...
 
NCVO webinar: UK Civil Society Almanac 2020: What the latest data tells us
NCVO webinar: UK Civil Society Almanac 2020: What the latest data tells usNCVO webinar: UK Civil Society Almanac 2020: What the latest data tells us
NCVO webinar: UK Civil Society Almanac 2020: What the latest data tells us
 
NCVO Webinar: Legal and practical considerations for returning to work
NCVO Webinar: Legal and practical considerations for returning to workNCVO Webinar: Legal and practical considerations for returning to work
NCVO Webinar: Legal and practical considerations for returning to work
 
NCVO Webinar: Board Leadership: Supporting your charity through the next phas...
NCVO Webinar: Board Leadership: Supporting your charity through the next phas...NCVO Webinar: Board Leadership: Supporting your charity through the next phas...
NCVO Webinar: Board Leadership: Supporting your charity through the next phas...
 
NCVO/CFG Webinar: Financial management and accessing government funding combi...
NCVO/CFG Webinar: Financial management and accessing government funding combi...NCVO/CFG Webinar: Financial management and accessing government funding combi...
NCVO/CFG Webinar: Financial management and accessing government funding combi...
 

Recently uploaded

UN DESA: Finance for Development 2024 Report
UN DESA: Finance for Development 2024 ReportUN DESA: Finance for Development 2024 Report
UN DESA: Finance for Development 2024 ReportEnergy for One World
 
Build Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor StudentsBuild Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor StudentsSERUDS INDIA
 
GOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATION
GOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATIONGOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATION
GOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATIONShivamShukla147857
 
2024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 232024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 23JSchaus & Associates
 
2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdf2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdfilocosnortegovph
 
2024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 242024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 24JSchaus & Associates
 
NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...
NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...
NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...Amil Baba Dawood bangali
 
In credit? Assessing where Universal Credit’s long rollout has left the benef...
In credit? Assessing where Universal Credit’s long rollout has left the benef...In credit? Assessing where Universal Credit’s long rollout has left the benef...
In credit? Assessing where Universal Credit’s long rollout has left the benef...ResolutionFoundation
 
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.Christina Parmionova
 
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...Energy for One World
 
Digital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical ImplicationsDigital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical ImplicationsBeat Estermann
 
Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...
Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...
Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...Christina Parmionova
 
Canadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdfCanadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdfAndrew Griffith
 
NL-FR Partnership - Water management roundtable 20240403.pdf
NL-FR Partnership - Water management roundtable 20240403.pdfNL-FR Partnership - Water management roundtable 20240403.pdf
NL-FR Partnership - Water management roundtable 20240403.pdfBertrand Coppin
 
Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...
Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...
Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...Amil baba
 
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.Christina Parmionova
 
Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...
Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...
Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...MartMantilla1
 
If there is a Hell on Earth, it is the Lives of Children in Gaza.pdf
If there is a Hell on Earth, it is the Lives of Children in Gaza.pdfIf there is a Hell on Earth, it is the Lives of Children in Gaza.pdf
If there is a Hell on Earth, it is the Lives of Children in Gaza.pdfKatrina Sriranpong
 
23rd Infopoverty World Conference - Agenda programme
23rd Infopoverty World Conference - Agenda programme23rd Infopoverty World Conference - Agenda programme
23rd Infopoverty World Conference - Agenda programmeChristina Parmionova
 
Pope Francis Teaching: Dignitas Infinita- On Human Dignity
Pope Francis Teaching: Dignitas Infinita- On Human DignityPope Francis Teaching: Dignitas Infinita- On Human Dignity
Pope Francis Teaching: Dignitas Infinita- On Human DignityEnergy for One World
 

Recently uploaded (20)

UN DESA: Finance for Development 2024 Report
UN DESA: Finance for Development 2024 ReportUN DESA: Finance for Development 2024 Report
UN DESA: Finance for Development 2024 Report
 
Build Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor StudentsBuild Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor Students
 
GOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATION
GOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATIONGOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATION
GOVERNMENT OF NCT OF DELHI DIRECTORATE OF EDUCATION
 
2024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 232024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 23
 
2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdf2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdf
 
2024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 242024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 24
 
NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...
NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...
NO1 Certified Best vashikaran specialist in UK USA UAE London Dubai Canada Am...
 
In credit? Assessing where Universal Credit’s long rollout has left the benef...
In credit? Assessing where Universal Credit’s long rollout has left the benef...In credit? Assessing where Universal Credit’s long rollout has left the benef...
In credit? Assessing where Universal Credit’s long rollout has left the benef...
 
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -16 April.
 
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
 
Digital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical ImplicationsDigital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical Implications
 
Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...
Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...
Youth shaping sustainable and innovative solution - Reinforcing the 2030 agen...
 
Canadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdfCanadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdf
 
NL-FR Partnership - Water management roundtable 20240403.pdf
NL-FR Partnership - Water management roundtable 20240403.pdfNL-FR Partnership - Water management roundtable 20240403.pdf
NL-FR Partnership - Water management roundtable 20240403.pdf
 
Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...
Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...
Uk-NO1 Black magic Specialist Expert in Uk Usa Uae London Canada England Amer...
 
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
 
Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...
Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...
Republic Act 11032 (Ease of Doing Business and Efficient Government Service D...
 
If there is a Hell on Earth, it is the Lives of Children in Gaza.pdf
If there is a Hell on Earth, it is the Lives of Children in Gaza.pdfIf there is a Hell on Earth, it is the Lives of Children in Gaza.pdf
If there is a Hell on Earth, it is the Lives of Children in Gaza.pdf
 
23rd Infopoverty World Conference - Agenda programme
23rd Infopoverty World Conference - Agenda programme23rd Infopoverty World Conference - Agenda programme
23rd Infopoverty World Conference - Agenda programme
 
Pope Francis Teaching: Dignitas Infinita- On Human Dignity
Pope Francis Teaching: Dignitas Infinita- On Human DignityPope Francis Teaching: Dignitas Infinita- On Human Dignity
Pope Francis Teaching: Dignitas Infinita- On Human Dignity
 

A5: Data protection: Your charity's biggest risk?

  • 1. Drinks sponsors: Partner sponsor: Lead sponsor: Media partner: Tech partner: DATA PROTECTION: YOUR CHARITY’S BIGGEST RISK? CHAIR ELIZABETH CHAMBERLAIN HEAD OF POLICY AND PUBLIC SERVICES, NCVO SPEAKERS LAWRIE SIMANOWITZ PARTNER, BATES WELLS BRAITHWAITE RICHARD MARBROW GROUP MANAGER, CORPORATE GOVERNANCE, INFORMATION COMMISSIONER'S OFFICE
  • 2. Data Protection and preparing for GDPR NCVO 14 November 2017
  • 3. Introduction Big developments in data protection in last year – possibly more for charities than any other sector: • ICO issued monetary penalty notices to 11 charities • GDPR implementation 25 May 2018 • Resulting changes to the Fundraising Regulator’s code and (at times confused) “guidance” • Replacement of PECR – new e-privacy directive • Data Protection Bill, published 13 September 2017 A lot of changes required – but no fundamental changes in principle.
  • 4. Consent (1) • Biggest area of concern for data controllers at the moment. • Starting point – consent is not always required. • Legitimate interest is often a valid alternative to consent and will remain under GDPR except for public bodies – which will need to move to a more consent-based system. • Consent is, and will continue to be, main route to processing sensitive personal data, and sending direct marketing electronically (email, text, social media, and non-TPS registered phone numbers).
  • 5. Consent (2) • In fact not much change and, contrary to popular myth, tick box opt-in will not be the only way of obtaining consent. • Consent must be: – Specific (not new) – Informed (not new) – Freely given (more detail on this in GDPR) – Unambiguous (new but doesn’t add much) – An affirmative act (new, but no change from current ICO guidance)
  • 6. Consent (3) • Key practical consequence is greater granularity: • GDPR requires separate consent for different processing “operations” (purposes) (eg fundraising, volunteering, wealth screening (?)). ICO draft guidance says this applies “wherever appropriate” and not if it is unduly disruptive. At a minimum consent must cover all purposes. • GDPR says there must be consent for each activity. Unclear what activities are, but assumed to include channels of communication. But ICO draft guidance says not if the activities are interdependent (so may not need to all be listed – better to do so if possible, in privacy policy). At a minimum consent must cover all activities.
  • 7. Consent (4) Other consent issues of note: • Opt-out versus opt-in? An affirmative act is required – doesn’t have to be tick box opt-in. If individuals freely give you their details and you offer them an opportunity to opt out of DM, then you have lawfully obtained consent. • What if existing consent is not GDPR compliant? Key point is that you have consent for the activities you wish to undertake. If insufficiently granular then seems unlikely to be top of the list for ICO compliance unless there are other concerns. • How long is consent valid for? Two years is safe. Four to five years is probably safe – try to get evidence. Longer than that, only if specific justification.
  • 8. Consent (5) More consent issues of note: • Keep clear records to demonstrate compliance – what individuals were told, when and how they consented • The right to withdraw consent must be stated at time consent is collected • Giving consent must not be mandatory if buying goods or services (but, arguably, technically compliant if mandatory when giving a donation)
  • 9. Privacy statements/other communications with data subjects Generally more onerous requirements. Privacy statements or other communications with individuals must include: • Identity and contact details of data controller • Purposes of the processing • Legal basis for processing (e.g. consent or legitimate interest - and what your legitimate interest is) • Recipient/categories of recipient of the personal data • Transfer of data outside EEA • How long data will be held for • Existence of automatic decision making • Individuals’ rights • Right to lodge a complaint with ICO • Right to withdraw consent The statement is an opportunity to achieve fairness
  • 11. Data Protection Officer • GDPR requires data controllers and data processes to appoint a DPO – in relatively limited circumstances. • Careful analysis required. • If not mandatory for your charity then sensible to appoint someone to be lead on data protection issues but possibly without formal status of DPO.
  • 12. What will the DPO do? GDPR specifically provides that: • Must be involved in all issues relating to data protection properly and in a timely manner • Advisory role • Monitor compliance with GDPR and other DP legislation including internal policies • Contact point for ICO and data subjects (contact details published) • Advise on DPIAs • Expert knowledge of data protection law and practices • Need active support by senior management – must report directly to highest management level • May not be dismissed or penalised for performing tasks
  • 13. Do we need to appoint a DPO? Article 37(1) GDPR sets out when you must appoint a DPO 1. Processing is carried out by a public authority or body (except courts) 2. Core activities involve regular and systematic monitoring of individuals on a large scale 3. Core activities involve processing sensitive personal data (or data relating to criminal convictions and offences) on a large scale EU or national law may require appointment of DPOs in other situations
  • 14. Working with third party data processors (1) Some aspects of DPA will apply directly to data processors: • Implement appropriate security measures • Report breaches to data controller (not to the ICO) • Appoint Data Protection Officer (where required – see earlier slide) • Keep records of processing
  • 15. Working with third party data processors (2) Data controllers required to seek guarantees – in particular specific provisions must go into contracts with data processors. • Only to process data on instructions of data controller, and keep data secure (not new) • More detail about the processing (including duration) • Comply with data controller’s requirements on transferring data outside of the EEA • Ensure staff are under a duty of confidence • Assist controllers to comply with subject access requests • Obtain authority to appoint sub-processors (and pass on obligations) • Appoint DPO (if required) • Return or delete data at end of agreement • Demonstrate compliance and allow the data controller to audit
  • 16. Other changes Greater rights for individuals including: – Right to be forgotten – Right to object – Right of access (subject access request) now within one month and cannot charge a fee • Data privacy impact assessments • Mandatory reporting of security breaches within 72 hours unless the breach is unlikely to result in a risk to the rights and freedoms of individuals • “Notification” (i.e. registration) abolished
  • 17. What next? • Audit • Mapping exercise? • Our view is that key areas of focus should be: – Data protection policy, privacy policy – Collection of consent and fair processing information – Data retention policy – Record keeping – Agreements with data processors – Training of staff in data protection compliance
  • 18. Lawrence Simanowitz Partner Bates Wells Braithwaite Tel: 020 7551 7796 l.simanowitz@bwbllp.com