SlideShare ist ein Scribd-Unternehmen logo
1 von 16
Preparing for and complying
with the GDPR
Andrew Rose, Senior Policy Officer, ICO
Leeds
January 2017
Contents
• Demonstrating compliance
• Role of the DPO
• Responsibilities of controllers and processors
• Breach notification
• Preparation and further information
Chapter I: Key definitions
and scope of Act.
Chapter II: Contains the data
protection principles, covers the
bases (equivalent of DPA
conditions) for processing and
outlines the special categories of
data.
Chapter VI: – Sets out the
powers and duties of
supervisory authorities.
Chapter IV: – Outlines the
responsibilities of data controllers and
processors (including security), for
example around breach notification and
employing Data Protection Officers.
Chapter III: Sets out the Rights of the
Data Subject (similar to part II of DPA).
Chapter VIII: – Outlines the right to
Judicial remedy and conditions for
imposing penalties.
Chapter VII: Covers co-operation and
consistency between different
supervisory authorities.
Chapter V: International
transfers.
Chapter IX: Sets out provisions
relating to specific processing
situations.
Chapter X: Delegated acts
and implementing acts.
Chapter XI: Final
provisions.
GDPR contents
Demonstrating compliance
• The controller shall be responsible for,
and be able to demonstrate compliance
with the Principles (Art 5(2))
• The requirement to
appoint a data protection
officer
• Data protection by design
and default
• Codes of conduct
• Certification schemes
• The requirement to implement
appropriate technical and
organisational measures
• Maintaining records on processing
activities
• Data protection impact
assessments
To maintain relevant records
on processing (Art 30).
To implement appropriate
technical and organisational
measures (Art 24).
Demonstrating compliance
Role of the DPO (Arts 35-37)
•Inform and advise the organisation about its
obligations to comply with the GDPR
•Monitor compliance with the GDPR, including
managing internal data protection activities
•Provide training to staff, advise on data protection
impact assessments and conduct internal audits
•First point of contact for supervisory authority
Responsibilities
•Directly report to the highest management level of the
controller or processor
•Not be given instructions on how to carry out duties
and can’t be dismissed for carrying out duties
•Can combine duties if no conflict of interest
•Be contactable by data subjects
•Be provided with necessary resources
Position
Role of the DPO
Appointed on the basis of
professional qualities :-
• Expert knowledge of DP
• Ability to fulfil tasks
Can be a staff member or
contracted
May be designated to act for
several authorities depending on
size and structure
Demonstrating compliance
Lawfulness of processing
(Art 6).
Processing special categories
of personal data (Art 9).
Responsibilities of
controllers and processors
Security responsibilities
Arts (32-34)
Pseudonymisation and encryption –
specifically mentioned as security
measures.
You must be able to ensure the
confidentiality, integrity, availability
and resilience of your systems.
The ability to restore the availability of
and access to data in a timely
manner.
Have a process to test, assess and
evaluate the effectiveness of the
measures you have in place.
Responsibilities of
controllers and processors
Joint controllers
(Art 26)
Transparently determine respective
responsibilities
• Compliance with regulations
• Exercising rights of data subjects
• Provide information required for
Arts 13&14
DS can exercise rights against each
controller
Responsibilities of
controllers and processors
Processors
(Art 28)
Processors must provide sufficient
guarantees that processing will:
• Meet the requirements of the
regulation
• Ensure the protection of the rights
of the data subject
No sub-processors without specific
agreement of controller
Processing subject to contract
Responsibilities of
controllers and processors
Contracts
(Art 28 (3))
Binding contract to cover:
• Process data only on instructions of
controller
• People authorised to access data
are subject to confidentiality
• Ensure security of processing
• Assist the controller in complying
with data subjects rights (where
possible)
• Assist the controller with regard to
security measures, breach
reporting and DPIAs
Mandatory to report to ICO where likely to result in a risk to the rights
and freedoms of the individual.
Without undue delay and no later than 72 hours of discovery (can add
detail later).
Risks include: -
• Loss of control of personal data
• Discrimination
• Identity theft
• Financial loss
• Damage to reputation
• Loss of confidentiality
Breach reporting (Arts 33-34)
What can you do to prepare?
• Published guidance
• 12 steps
• Overview of the GDPR
• Privacy notices code of
practice
• A29 guidance
• Right to data portability
• DPOs
• Identifying a lead
supervisory authority
https://ico.org.uk/for-organisations/data-protection-reform/
What’s the ICO doing?
• Working with DCMS
and A29
• Further guidance
• Internal change
programme
!?
How the ICO can help
• Guidance:
www.ico.org.uk
• Helpline:
0303 123 1113

Weitere ähnliche Inhalte

Was ist angesagt?

MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
Huub de Jong
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
John Greenwood
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
VYTIS MALECKAS
 

Was ist angesagt? (20)

GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 

Andere mochten auch

The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 
UIA Madrid Seminar (17-04-15)
UIA Madrid Seminar (17-04-15)UIA Madrid Seminar (17-04-15)
UIA Madrid Seminar (17-04-15)
Victor Rosello
 
Jump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data ClassificationJump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data Classification
Watchful Software
 
delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1
Jes Breslaw
 

Andere mochten auch (14)

GDPR and technology - details matter
GDPR and technology - details matterGDPR and technology - details matter
GDPR and technology - details matter
 
Housing sector forum pia slides - 20170131
Housing sector forum   pia slides - 20170131Housing sector forum   pia slides - 20170131
Housing sector forum pia slides - 20170131
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Leveraging Best Practice Methods in an Age of Digital Transformation Belfast ...
Leveraging Best Practice Methods in an Age of Digital Transformation Belfast ...Leveraging Best Practice Methods in an Age of Digital Transformation Belfast ...
Leveraging Best Practice Methods in an Age of Digital Transformation Belfast ...
 
Preparing to the GDPR - the next steps
Preparing to the GDPR - the next stepsPreparing to the GDPR - the next steps
Preparing to the GDPR - the next steps
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
UIA Madrid Seminar (17-04-15)
UIA Madrid Seminar (17-04-15)UIA Madrid Seminar (17-04-15)
UIA Madrid Seminar (17-04-15)
 
DMA — Data Protection 2017
DMA — Data Protection 2017 DMA — Data Protection 2017
DMA — Data Protection 2017
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
Jump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data ClassificationJump start EU Data Privacy Compliance with Data Classification
Jump start EU Data Privacy Compliance with Data Classification
 
delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1
 
Impact Assessment for social enterprises and nonprofits
Impact Assessment for social enterprises and nonprofitsImpact Assessment for social enterprises and nonprofits
Impact Assessment for social enterprises and nonprofits
 
Adam w. mosher - geo tagging - atlseccon2011
Adam w. mosher - geo tagging - atlseccon2011Adam w. mosher - geo tagging - atlseccon2011
Adam w. mosher - geo tagging - atlseccon2011
 
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_IstanbulGDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
GDPR Implementation Basics_Igor Mate_2016 CEE GC Summit_Istanbul
 

Ähnlich wie Preparing for general data protection regulations (gdpr) within the hous...

Ähnlich wie Preparing for general data protection regulations (gdpr) within the hous... (20)

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
GDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to KnowGDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to Know
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
The GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farThe GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so far
 
GDPR Breach Notification Demystifying What the Regulators Want
GDPR Breach Notification Demystifying What the Regulators WantGDPR Breach Notification Demystifying What the Regulators Want
GDPR Breach Notification Demystifying What the Regulators Want
 
How MongoDB can accelerate a path to GDPR compliance
How MongoDB can accelerate a path to GDPR complianceHow MongoDB can accelerate a path to GDPR compliance
How MongoDB can accelerate a path to GDPR compliance
 
Business impact of new EU General Data Protection Regulation (GDPR) on organi...
Business impact of new EU General Data Protection Regulation (GDPR) on organi...Business impact of new EU General Data Protection Regulation (GDPR) on organi...
Business impact of new EU General Data Protection Regulation (GDPR) on organi...
 
The general data protection act overview
The general data protection act overviewThe general data protection act overview
The general data protection act overview
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR and Security.pdf
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance
 
Data breaches, privacy programs and what will change for processors
Data breaches, privacy programs and what will change for processorsData breaches, privacy programs and what will change for processors
Data breaches, privacy programs and what will change for processors
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 

Kürzlich hochgeladen

Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
mahikaanand16
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
PoojaGadiya1
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
JosephCanama
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
bd2c5966a56d
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
Airst S
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
Airst S
 

Kürzlich hochgeladen (20)

CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 

Preparing for general data protection regulations (gdpr) within the hous...

  • 1. Preparing for and complying with the GDPR Andrew Rose, Senior Policy Officer, ICO Leeds January 2017
  • 2. Contents • Demonstrating compliance • Role of the DPO • Responsibilities of controllers and processors • Breach notification • Preparation and further information
  • 3. Chapter I: Key definitions and scope of Act. Chapter II: Contains the data protection principles, covers the bases (equivalent of DPA conditions) for processing and outlines the special categories of data. Chapter VI: – Sets out the powers and duties of supervisory authorities. Chapter IV: – Outlines the responsibilities of data controllers and processors (including security), for example around breach notification and employing Data Protection Officers. Chapter III: Sets out the Rights of the Data Subject (similar to part II of DPA). Chapter VIII: – Outlines the right to Judicial remedy and conditions for imposing penalties. Chapter VII: Covers co-operation and consistency between different supervisory authorities. Chapter V: International transfers. Chapter IX: Sets out provisions relating to specific processing situations. Chapter X: Delegated acts and implementing acts. Chapter XI: Final provisions. GDPR contents
  • 4. Demonstrating compliance • The controller shall be responsible for, and be able to demonstrate compliance with the Principles (Art 5(2)) • The requirement to appoint a data protection officer • Data protection by design and default • Codes of conduct • Certification schemes • The requirement to implement appropriate technical and organisational measures • Maintaining records on processing activities • Data protection impact assessments
  • 5. To maintain relevant records on processing (Art 30). To implement appropriate technical and organisational measures (Art 24). Demonstrating compliance
  • 6. Role of the DPO (Arts 35-37) •Inform and advise the organisation about its obligations to comply with the GDPR •Monitor compliance with the GDPR, including managing internal data protection activities •Provide training to staff, advise on data protection impact assessments and conduct internal audits •First point of contact for supervisory authority Responsibilities •Directly report to the highest management level of the controller or processor •Not be given instructions on how to carry out duties and can’t be dismissed for carrying out duties •Can combine duties if no conflict of interest •Be contactable by data subjects •Be provided with necessary resources Position
  • 7. Role of the DPO Appointed on the basis of professional qualities :- • Expert knowledge of DP • Ability to fulfil tasks Can be a staff member or contracted May be designated to act for several authorities depending on size and structure
  • 8. Demonstrating compliance Lawfulness of processing (Art 6). Processing special categories of personal data (Art 9).
  • 9. Responsibilities of controllers and processors Security responsibilities Arts (32-34) Pseudonymisation and encryption – specifically mentioned as security measures. You must be able to ensure the confidentiality, integrity, availability and resilience of your systems. The ability to restore the availability of and access to data in a timely manner. Have a process to test, assess and evaluate the effectiveness of the measures you have in place.
  • 10. Responsibilities of controllers and processors Joint controllers (Art 26) Transparently determine respective responsibilities • Compliance with regulations • Exercising rights of data subjects • Provide information required for Arts 13&14 DS can exercise rights against each controller
  • 11. Responsibilities of controllers and processors Processors (Art 28) Processors must provide sufficient guarantees that processing will: • Meet the requirements of the regulation • Ensure the protection of the rights of the data subject No sub-processors without specific agreement of controller Processing subject to contract
  • 12. Responsibilities of controllers and processors Contracts (Art 28 (3)) Binding contract to cover: • Process data only on instructions of controller • People authorised to access data are subject to confidentiality • Ensure security of processing • Assist the controller in complying with data subjects rights (where possible) • Assist the controller with regard to security measures, breach reporting and DPIAs
  • 13. Mandatory to report to ICO where likely to result in a risk to the rights and freedoms of the individual. Without undue delay and no later than 72 hours of discovery (can add detail later). Risks include: - • Loss of control of personal data • Discrimination • Identity theft • Financial loss • Damage to reputation • Loss of confidentiality Breach reporting (Arts 33-34)
  • 14. What can you do to prepare? • Published guidance • 12 steps • Overview of the GDPR • Privacy notices code of practice • A29 guidance • Right to data portability • DPOs • Identifying a lead supervisory authority https://ico.org.uk/for-organisations/data-protection-reform/
  • 15. What’s the ICO doing? • Working with DCMS and A29 • Further guidance • Internal change programme
  • 16. !? How the ICO can help • Guidance: www.ico.org.uk • Helpline: 0303 123 1113