SlideShare ist ein Scribd-Unternehmen logo
1 von 13
GDPR Update for Irish
Food & Drink Businesses
Niall Rooney
05.09.2019
This presentation is for general information
only and is not intended to provide legal advice
General Data Protection Regulation (GDPR)
• EU Regulation
• Effective from 25 May 2018 after two year transition period
• Data Protection Act 2018
 Compliance obligations for businesses and organisations
 “Accountability”
 Stronger data subject rights for individuals
 Right to lodge complaint and take legal action
 Increased powers and sanctions of Data Protection Commission
GDPR scope: ‘processing’ of ‘personal data’
• ‘processing’
• anything you can do with or to personal data, electronically or in manual
records, e.g. collecting, using, retaining, amending, sharing, deleting…
• ‘personal data’
• any information relating to an identified or identifiable living person
o special category data
• racial or ethnic origin
• political opinions, religious beliefs
• trade union membership
• genetic data
• biometric data
• data concerning health
• data concerning a person's sex life or sexual orientation
o criminal offence data
The Data Protection Principles (A 5)
a) You must process personal data lawfully, fairly and transparently
b) You must collect personal data for specified purposes, and not use it for
incompatible purposes
c) The personal data must be limited to what is necessary for the purposes
d) You must keep personal data accurate, and up to date if necessary
e) You must not keep personal data for any longer than is necessary for
the purposes
f) You must ensure security of the personal data, including confidentiality,
integrity and availability
 You (data controller) are responsible for complying with the principles
and you have to be able to demonstrate your compliance
What does GDPR “compliance” look like?
1 Maintain a Record of Processing Activities containing specified information A 30
2 Provide individuals with Privacy Notices containing mandatory information A 13-14
3 Appoint a Data Protection Officer, if required A 37
4 Technical and organisational measures to ensure and demonstrate compliance A 5, 24
5 Data security measures appropriate to the risks A 32
6 Facilitate the exercise of data subject rights A 12, 15-22
7 Record and report personal data breaches A 33-34
8 Contracts with data processors (third parties processing on your behalf) A 28
9 International data transfer safeguards, unless adequacy A 44-47
10 Data protection by design and by default approach A 25
11 Data Protection Impact Assessment (DPIA) prior to likely high-risk processing A 35-36
12 Joint controller arrangement, if relevant A 26
Data Security & Personal Data Breaches
• Ensure appropriate security of personal data (A 5)
• Implement appropriate technical and organisational measures to ensure a
level of security appropriate to the risks of processing (A 32)
• Identify, report and notify personal data breaches (“a breach of security
leading to the accidental or unlawful destruction, loss, alteration, unauthorised
disclosure of, or access to, personal data transmitted, stored or processed”)
 Notify breach to DPC within 72 hours of becoming aware if the breach is
likely to result in a risk to individuals (A 33)
 Communicate breach to affected individuals without undue delay if the
breach is likely to result in a high risk to individuals * (A 34)
 Data controller must document every personal data breach, including the
facts, effects, and remedial actions taken (A 33(5))
Data Subject Rights
Individuals have rights in relation to their personal data –
• The right to be informed (Privacy Notice)
• The right of access (Subject Access Request)
• The right to erasure (‘right to be forgotten’)
• The right to object to certain processing
• The right to rectification (correction)
• The right to restrict processing
• The right to data portability
• Rights in relation to automated decision making and profiling
• The data controller must facilitate the exercise of data subject rights, and
must be able to demonstrate its compliance in this regard…
Right of Access (SAR)
• Individuals have the right to get information about how their personal data is
being processed and to obtain a copy of the personal data
• No formality requirements and requester motive is irrelevant
• Data controller has one month to respond (may extend by two months where
requests are complex or numerous)
• No fee or refusal allowed (unless manifestly unfounded or excessive)
• Limited restrictions, including that disclosure of personal data concerning the
requester would adversely affect the rights and freedoms of others
• Data controller must provide the personal data to the requester securely
• Data controller must be able to demonstrate compliance
Third Parties
1. Data Controller + Data Processor
 Third party processing personal data on the data controller’s behalf
 GDPR due diligence
 Written contract with mandatory terms (A 28)
 Liability issues
2. Joint Controllers
 Jointly decide the purposes and means of processing of personal data
 “Arrangement” setting out respective GDPR responsibilities (A 26)
3. Data Controller + Data Controller
 Disclosure or sharing of personal data to or between independent parties
 Separate compliance responsibilities as separate data controllers
 Data Sharing Agreement is recommended
4. Third Party Data Request
 Usually from a law enforcement body
 Section 41 Data Protection Act 2018 – disclosure is “necessary and
proportionate” for purposes specified in the section, e.g. detecting,
investigating or prosecuting criminal offences
 No obligation to comply with a S41 request, data controller bears risk..
International Data Transfers
Transfer of personal data to a country outside EEA prohibited unless either –
1. The country is subject of a European Commission adequacy decision
• includes AR, CA*, IL, IOM, JP*, JE, NZ, CH, UY
• EU-US Privacy Shield*
2. Appropriate safeguards are provided
• Standard Contractual Clauses; or
• Binding Corporate Rules (BCRs)
3. An article 49 GDPR specific derogation applies (caution…)
See:
https://www.dataprotection.ie/en/organisations/international-transfers
https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-
data-protection_en
‘No-Deal’ Brexit preparation tips
• Even if UK can qualify for adequacy, this will not be in place on exit day, and it would
take some time to negotiate…
• When UK leaves the EU, transfer of personal data from Ireland to UK will be prohibited
unless you have safeguards in place, such as Standard Contractual Clauses (until
there’s a Commission adequacy decision, if that happens).
 Review data flows and identify where you transfer personal data to NI and GB
 Prepare to put SCC contracts in place to ensure that personal data can continue
to flow once the UK is outside the EU
 Review your Privacy Notices and internal compliance documentation to identify
what will need updating when the UK leaves the EU
 Make sure key people in your business are aware of the issues and risks
 Stay up to date on developments, monitor DPC and ICO website updates
Questions?
FP Logue Solicitors
Data Protection, Privacy & Information Law
01 531 3510 | info@fplogue.com | www.fplogue.com

Weitere ähnliche Inhalte

Was ist angesagt?

Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Michael Adamberry
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonBrowne Jacobson LLP
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamBrowne Jacobson LLP
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterBrowne Jacobson LLP
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamBrowne Jacobson LLP
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...m-hance
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
GDPR Compliance: What You Need to Know Before May 2018
GDPR Compliance:  What You Need to Know Before May 2018GDPR Compliance:  What You Need to Know Before May 2018
GDPR Compliance: What You Need to Know Before May 2018Infosec
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Aoife Flynn
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 

Was ist angesagt? (20)

Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
GDPR Compliance: What You Need to Know Before May 2018
GDPR Compliance:  What You Need to Know Before May 2018GDPR Compliance:  What You Need to Know Before May 2018
GDPR Compliance: What You Need to Know Before May 2018
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Privacy 101
Privacy 101Privacy 101
Privacy 101
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 

Ähnlich wie Niall Rooney FD Event 05.09.19

GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPRJessvin Thomas
 
GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)Erik Vollebregt
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRzayadeen2003
 
GDPR: Protecting Your Data
GDPR: Protecting Your DataGDPR: Protecting Your Data
GDPR: Protecting Your DataUlf Mattsson
 
Medical device data protection and security
Medical device data protection and security Medical device data protection and security
Medical device data protection and security Erik Vollebregt
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPRJessvin Thomas
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...Brian Miller, Solicitor
 
EU General Data Protection Regulation top 8 operational impacts in personal c...
EU General Data Protection Regulation top 8 operational impacts in personal c...EU General Data Protection Regulation top 8 operational impacts in personal c...
EU General Data Protection Regulation top 8 operational impacts in personal c...Erik Vollebregt
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 

Ähnlich wie Niall Rooney FD Event 05.09.19 (20)

GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
GDPR: Protecting Your Data
GDPR: Protecting Your DataGDPR: Protecting Your Data
GDPR: Protecting Your Data
 
Medical device data protection and security
Medical device data protection and security Medical device data protection and security
Medical device data protection and security
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
 
EU General Data Protection Regulation top 8 operational impacts in personal c...
EU General Data Protection Regulation top 8 operational impacts in personal c...EU General Data Protection Regulation top 8 operational impacts in personal c...
EU General Data Protection Regulation top 8 operational impacts in personal c...
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 

Kürzlich hochgeladen

INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxnyabatejosphat1
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxRRR Chambers
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxRRR Chambers
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhaiShashankKumar441258
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881mayurchatre90
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxRRR Chambers
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | DelhiFULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhisoniya singh
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书E LSS
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)Delhi Call girls
 
Debt Collection in India - General Procedure
Debt Collection in India  - General ProcedureDebt Collection in India  - General Procedure
Debt Collection in India - General ProcedureBridgeWest.eu
 
Divorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdfDivorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdfdigitalnikesh24
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx2020000445musaib
 

Kürzlich hochgeladen (20)

INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptx
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | DelhiFULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
Debt Collection in India - General Procedure
Debt Collection in India  - General ProcedureDebt Collection in India  - General Procedure
Debt Collection in India - General Procedure
 
Divorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdfDivorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdf
 
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 

Niall Rooney FD Event 05.09.19

  • 1. GDPR Update for Irish Food & Drink Businesses Niall Rooney 05.09.2019 This presentation is for general information only and is not intended to provide legal advice
  • 2. General Data Protection Regulation (GDPR) • EU Regulation • Effective from 25 May 2018 after two year transition period • Data Protection Act 2018  Compliance obligations for businesses and organisations  “Accountability”  Stronger data subject rights for individuals  Right to lodge complaint and take legal action  Increased powers and sanctions of Data Protection Commission
  • 3. GDPR scope: ‘processing’ of ‘personal data’ • ‘processing’ • anything you can do with or to personal data, electronically or in manual records, e.g. collecting, using, retaining, amending, sharing, deleting… • ‘personal data’ • any information relating to an identified or identifiable living person o special category data • racial or ethnic origin • political opinions, religious beliefs • trade union membership • genetic data • biometric data • data concerning health • data concerning a person's sex life or sexual orientation o criminal offence data
  • 4. The Data Protection Principles (A 5) a) You must process personal data lawfully, fairly and transparently b) You must collect personal data for specified purposes, and not use it for incompatible purposes c) The personal data must be limited to what is necessary for the purposes d) You must keep personal data accurate, and up to date if necessary e) You must not keep personal data for any longer than is necessary for the purposes f) You must ensure security of the personal data, including confidentiality, integrity and availability  You (data controller) are responsible for complying with the principles and you have to be able to demonstrate your compliance
  • 5. What does GDPR “compliance” look like? 1 Maintain a Record of Processing Activities containing specified information A 30 2 Provide individuals with Privacy Notices containing mandatory information A 13-14 3 Appoint a Data Protection Officer, if required A 37 4 Technical and organisational measures to ensure and demonstrate compliance A 5, 24 5 Data security measures appropriate to the risks A 32 6 Facilitate the exercise of data subject rights A 12, 15-22 7 Record and report personal data breaches A 33-34 8 Contracts with data processors (third parties processing on your behalf) A 28 9 International data transfer safeguards, unless adequacy A 44-47 10 Data protection by design and by default approach A 25 11 Data Protection Impact Assessment (DPIA) prior to likely high-risk processing A 35-36 12 Joint controller arrangement, if relevant A 26
  • 6. Data Security & Personal Data Breaches • Ensure appropriate security of personal data (A 5) • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks of processing (A 32) • Identify, report and notify personal data breaches (“a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or processed”)  Notify breach to DPC within 72 hours of becoming aware if the breach is likely to result in a risk to individuals (A 33)  Communicate breach to affected individuals without undue delay if the breach is likely to result in a high risk to individuals * (A 34)  Data controller must document every personal data breach, including the facts, effects, and remedial actions taken (A 33(5))
  • 7. Data Subject Rights Individuals have rights in relation to their personal data – • The right to be informed (Privacy Notice) • The right of access (Subject Access Request) • The right to erasure (‘right to be forgotten’) • The right to object to certain processing • The right to rectification (correction) • The right to restrict processing • The right to data portability • Rights in relation to automated decision making and profiling • The data controller must facilitate the exercise of data subject rights, and must be able to demonstrate its compliance in this regard…
  • 8. Right of Access (SAR) • Individuals have the right to get information about how their personal data is being processed and to obtain a copy of the personal data • No formality requirements and requester motive is irrelevant • Data controller has one month to respond (may extend by two months where requests are complex or numerous) • No fee or refusal allowed (unless manifestly unfounded or excessive) • Limited restrictions, including that disclosure of personal data concerning the requester would adversely affect the rights and freedoms of others • Data controller must provide the personal data to the requester securely • Data controller must be able to demonstrate compliance
  • 9. Third Parties 1. Data Controller + Data Processor  Third party processing personal data on the data controller’s behalf  GDPR due diligence  Written contract with mandatory terms (A 28)  Liability issues 2. Joint Controllers  Jointly decide the purposes and means of processing of personal data  “Arrangement” setting out respective GDPR responsibilities (A 26) 3. Data Controller + Data Controller  Disclosure or sharing of personal data to or between independent parties  Separate compliance responsibilities as separate data controllers  Data Sharing Agreement is recommended 4. Third Party Data Request  Usually from a law enforcement body  Section 41 Data Protection Act 2018 – disclosure is “necessary and proportionate” for purposes specified in the section, e.g. detecting, investigating or prosecuting criminal offences  No obligation to comply with a S41 request, data controller bears risk..
  • 10. International Data Transfers Transfer of personal data to a country outside EEA prohibited unless either – 1. The country is subject of a European Commission adequacy decision • includes AR, CA*, IL, IOM, JP*, JE, NZ, CH, UY • EU-US Privacy Shield* 2. Appropriate safeguards are provided • Standard Contractual Clauses; or • Binding Corporate Rules (BCRs) 3. An article 49 GDPR specific derogation applies (caution…) See: https://www.dataprotection.ie/en/organisations/international-transfers https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension- data-protection_en
  • 11. ‘No-Deal’ Brexit preparation tips • Even if UK can qualify for adequacy, this will not be in place on exit day, and it would take some time to negotiate… • When UK leaves the EU, transfer of personal data from Ireland to UK will be prohibited unless you have safeguards in place, such as Standard Contractual Clauses (until there’s a Commission adequacy decision, if that happens).  Review data flows and identify where you transfer personal data to NI and GB  Prepare to put SCC contracts in place to ensure that personal data can continue to flow once the UK is outside the EU  Review your Privacy Notices and internal compliance documentation to identify what will need updating when the UK leaves the EU  Make sure key people in your business are aware of the issues and risks  Stay up to date on developments, monitor DPC and ICO website updates
  • 12.
  • 13. Questions? FP Logue Solicitors Data Protection, Privacy & Information Law 01 531 3510 | info@fplogue.com | www.fplogue.com