SlideShare ist ein Scribd-Unternehmen logo
1 von 19
Prepare for upcoming
charity regulations with
Microsoft solutions
Thursday 11th May 2017
GDPR
(what difference will it make….?)
11 May 2017
• To summarise and explain the changes in data protection
obligations that have followed the introduction of the
General Data Protection Regulation (GDPR)
• To explore and discuss some of the implications for
organisations in the sector
Purpose of the session
• A specialist information systems consultancy
• We only work with membership organisations, charities,
associations, trusts and others in the NfP sector
• We are completely supplier-independent
• Our consultants have held senior positions in a broad
range of different organisations
• Our advice and guidance is based on practical experience
gained over many years
Adapta Consulting
Data Protection – a potted history
DPA
1998
PECR
2003
GDPR
25 May 2018
Will be replaced by GDPR Will be updated in time for GDPR Will apply regardless of Brexit
• Data Protection Act 1984 and 1998 – in place for 30+ years
• Provides rules for organisations that collect and use personal information
– applies to manual and electronic records
• EU General Data Protection Regulation (GDPR) comes into force in May
2018 …. regardless of Brexit
• GDPR builds on DPA but there are significant changes too
Data protection
• The British Heart Foundation - secretly screened millions of their donors so they could target them
for more money - £18,000 fine
• The RSPCA - secretly screened millions of their donors so they could target them for more money -
£25,000 fine
• The Alzheimer’s Society - volunteers used personal email addresses to receive and share
information about people who use the charity, stored unencrypted data on their home computers and
failed to keep paper records locked away. They were not trained in data protection, the charity’s policies
and procedures were not explained to them and they had little supervision from staff – enforcement
• The British Pregnancy Advice Service – exposed thousands of personal details to a malicious
hacker - £200,000 fine
The ICO issued fines of £6K- £18k to 11 charities earlier this year for a combinations of breaches
which included sharing data with other charities, finding out information about people that they didn’t
provide, and ranking people according to their wealth.
This included the NSPCC, GOSHCC, Oxfam, Macmillan Cancer Support, WWF-UK, the Royal British Legion,
Guide Dogs for the Blind Association, Cancer Support UK, Cancer Research UK, Battersea Dogs and Cats’
Home, The International Fund for Animal Welfare
When things go wrong … some recent sector examples
• The Nursing and Midwifery Council … lost dvds ... unencrypted.. £150k fine
• North East Lincolnshire Council … missing unencrypted memory stick …£80k fine
• Greater Manchester Police … stolen USB stick … unencrypted, no password protection …
£150k fine
• Royal Veterinary College … loss of a memory card … signed undertaking
When things go wrong … more examples, common mistakes
• Surrey County Council … misdirected emails
with attached files … not encrypted or password
protected … £120k fine
• North Somerset Council … sent unencrypted
emails with personal data to wrong NHS employee
… £60k fine
Complying with the Act
When processing personal and sensitive personal data
we have to comply with the 8 principles which are ……
1. Data must be collected lawfully and fairly
2. It must be used only for specified purposes
3. The quantity of data collected should be appropriate
4. The data should be accurate and up to date
5. It should be kept only as long as necessary
6. It should be processed in accordance with the rights of those it concerns
7. It should be kept securely
8. It should not be transferred out of the EEA unless it is to an area which has similar standards
What changes with GDPR
Active consent
Accountability
& governance
Right to erasure
Portability
Right to be
informed
Privacy by design
€20 million fines
Right to
rectification
Faster reporting of data
breaches
Data protection
impact assessments
Faster subject
access
Recent
consent
Demonstrate
consent
DPA:
• Fines of up to £500k
• Comparatively low-profile penalties (historically)
GDPR:
• Penalties likely to be higher profile (consequent reputational risk)
• Fines of up to 4% of annual global turnover or 20 million euros
(whichever is greater)
• Civil and criminal liability for officers and key employees
• High risk data breaches must be reported to the supervisory
authority within 72 hours
Changes – breaches
• New accountability requirement - GDPR requires you to show
how you comply with the principles
• Appropriate technical and organisational measures are needed
to ensure and demonstrate that you comply e.g. internal data
protection policies such as staff training, internal audits of
processing activities, impact assessments
• Records of processing activities must be kept where processing
personal data that could result in a risk to the rights and
freedoms of individuals
Changes – governance & accountability
• Valid consent to process personal data will be
needed instead of implicit consent - a person has
actually done something actively to provide their
consent
• Pre-ticked opt in boxes and empty opt-out boxes
(which have to be ticked by the person in order to
opt out) will no longer be sufficient
• Demonstrate that consent has been given
• Consent must be given freely - performance of a
contract must not depend upon consent being given
when the processing is not actually required to
perform the contract
• Parental consent will be required to process the
personal data of children under the age of 16 (or
possibly 13)
Changes – consent
Changes – the right to be informed
Subjects have the right to be informed about …..
• Identity and contact details of the controller and where applicable, the controller’s representative, and the
data protection officer • Purpose of the processing and the legal basis for the processing • The legitimate
interests of the controller or third party, where applicable • Categories of personal data • Any recipient or
categories of recipients of the personal data • Details of transfers to third country and safeguards • Retention
period or criteria used to determine the retention period • The existence of each of data subject’s rights • The
right to withdraw consent at any time, where relevant • The right to lodge a complaint with a supervisory
authority • The source the personal data originates from and whether it came from publicly accessible sources
• Whether the provision of personal data part of a statutory or contractual requirement or obligation and
possible consequences of failing to provide the personal data • The existence of automated decision making,
including profiling and information about how decisions are made, the significance and the consequences •
Information about the processing of personal data must be:
• Concise, transparent, intelligible and easily accessible
• Written in clear and plain language, particularly if addressed to a child
• Free of charge
• Subject access – usually within a month and for no fee
• Right to erasure - right to be forgotten … a data subject has
the right to request personal data is erased when it is no longer
being processed
• Data portability - personal data must be in a format where it
can be easily and electronically transferred to another
processing system
• Right to rectification – if personal data is inaccurate or
incomplete
Changes – users’ rights
• Data processors will have direct and increased responsibilities
- they can be held responsible for data breaches
• There is still a responsibility on your organisation to ensure
that:
• Contracts with data processors comply with GDPR
• You choose appropriate data processors
• Data processors comply with data protection and the
GDPR
Changes – data processors
• Compliance must be considered in the design and
implementation of all processes, from start to finish
• Data protection can no longer be an afterthought
• Data Protection Impact Assessments (DPIA) must be
undertaken when appropriate (e.g. when using new
technologies and the processing is likely to result in a high
risk to the rights and freedoms of individuals)
Changes – privacy by design
Get ready for GDPR compliance
• Develop a strategy for obtaining consent – and a practical as well as legal level of
granularity
• Consider and document the legal basis for holding personal data
• Be able to evidence consent
• Plan for subjects’ increased right to be informed – know your data and data
handling processes
• Update existing and develop new data protection policies and procedures for
GDPR compliance …. and implement
• Train staff on GDPR requirements, revised policies and procedures
• Design and integrate a ‘privacy by design’ approach (e.g. for procurement of
products and services, and data and digital development projects)
Questions, comments and a bit of discussion..?

Weitere ähnliche Inhalte

Was ist angesagt?

MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
Huub de Jong
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
Pavol Balaj
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
Stephanie Vasey
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 

Was ist angesagt? (19)

General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...Preparing for general data protection regulations (gdpr) within the hous...
Preparing for general data protection regulations (gdpr) within the hous...
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 

Ähnlich wie GDPR – what does it mean for charities and what you need to consider - Iain Pritchard, Adapta Consulting

Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
Rachel Aldighieri
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
CFG
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
Rachel Aldighieri
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
Rachel Aldighieri
 

Ähnlich wie GDPR – what does it mean for charities and what you need to consider - Iain Pritchard, Adapta Consulting (20)

Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
Legal update
Legal updateLegal update
Legal update
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
 

Mehr von m-hance

Mehr von m-hance (20)

Webinar - Year-end Processing in Microsoft Dynamics GP
Webinar - Year-end Processing in Microsoft Dynamics GPWebinar - Year-end Processing in Microsoft Dynamics GP
Webinar - Year-end Processing in Microsoft Dynamics GP
 
Webinar - Back up and Disaster Recovery
Webinar - Back up and Disaster RecoveryWebinar - Back up and Disaster Recovery
Webinar - Back up and Disaster Recovery
 
D365 Business Central Not-for-Profit Webinar 2019
D365 Business Central Not-for-Profit Webinar 2019D365 Business Central Not-for-Profit Webinar 2019
D365 Business Central Not-for-Profit Webinar 2019
 
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
Microsoft dynamics 365 for small and medium sized charities - session 2 gdprMicrosoft dynamics 365 for small and medium sized charities - session 2 gdpr
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
 
Microsoft dynamics 365 for small and medium sized charities - session 1 m-hance
Microsoft dynamics 365 for small and medium sized charities - session 1 m-hanceMicrosoft dynamics 365 for small and medium sized charities - session 1 m-hance
Microsoft dynamics 365 for small and medium sized charities - session 1 m-hance
 
The future of Microsoft Dynamics GP - Journey to the cloud - session 4
The future of Microsoft Dynamics GP - Journey to the cloud - session 4The future of Microsoft Dynamics GP - Journey to the cloud - session 4
The future of Microsoft Dynamics GP - Journey to the cloud - session 4
 
Demystifying Dynamics 365 - Part 2 - Journey to the cloud session 3
Demystifying Dynamics 365 - Part 2 - Journey to the cloud   session 3Demystifying Dynamics 365 - Part 2 - Journey to the cloud   session 3
Demystifying Dynamics 365 - Part 2 - Journey to the cloud session 3
 
Considering the Cloud - Journey to the cloud session 1
Considering the Cloud - Journey to the cloud   session 1Considering the Cloud - Journey to the cloud   session 1
Considering the Cloud - Journey to the cloud session 1
 
Event closure: Journey to the cloud session 5
Event closure: Journey to the cloud session 5Event closure: Journey to the cloud session 5
Event closure: Journey to the cloud session 5
 
Prepare for upcoming regulations with Microsoft solutions
Prepare for upcoming regulations with Microsoft solutionsPrepare for upcoming regulations with Microsoft solutions
Prepare for upcoming regulations with Microsoft solutions
 
Event Closing keynote - #TheFutureOfCloud
Event Closing keynote - #TheFutureOfCloudEvent Closing keynote - #TheFutureOfCloud
Event Closing keynote - #TheFutureOfCloud
 
Accelerating Growth by moving to the cloud keynote - #TheFutureOfCloud
Accelerating Growth by moving to the cloud keynote - #TheFutureOfCloudAccelerating Growth by moving to the cloud keynote - #TheFutureOfCloud
Accelerating Growth by moving to the cloud keynote - #TheFutureOfCloud
 
Disruptonomics keynote - #TheFutureOfCloud
Disruptonomics keynote - #TheFutureOfCloudDisruptonomics keynote - #TheFutureOfCloud
Disruptonomics keynote - #TheFutureOfCloud
 
Cloud Considerations keynote - #TheFutureOfCloud
Cloud Considerations keynote - #TheFutureOfCloudCloud Considerations keynote - #TheFutureOfCloud
Cloud Considerations keynote - #TheFutureOfCloud
 
Event introduction - Microsoft for Charities Event Ireland
Event introduction - Microsoft for Charities Event IrelandEvent introduction - Microsoft for Charities Event Ireland
Event introduction - Microsoft for Charities Event Ireland
 
Introducing NfP 360 for Microsoft Dynamics CRM - Microsoft for Charities Even...
Introducing NfP 360 for Microsoft Dynamics CRM - Microsoft for Charities Even...Introducing NfP 360 for Microsoft Dynamics CRM - Microsoft for Charities Even...
Introducing NfP 360 for Microsoft Dynamics CRM - Microsoft for Charities Even...
 
Microsoft Dynamics GP for Not for Porfit organisations
Microsoft Dynamics GP for Not for Porfit organisations Microsoft Dynamics GP for Not for Porfit organisations
Microsoft Dynamics GP for Not for Porfit organisations
 
Microsoft Dynamics CRM 2015 for Not for Profit organisations
Microsoft Dynamics CRM 2015 for Not for Profit organisationsMicrosoft Dynamics CRM 2015 for Not for Profit organisations
Microsoft Dynamics CRM 2015 for Not for Profit organisations
 
Microsoft story
Microsoft storyMicrosoft story
Microsoft story
 
Cloud and collaboration for Not for Profit organisations
Cloud and collaboration for Not for Profit organisationsCloud and collaboration for Not for Profit organisations
Cloud and collaboration for Not for Profit organisations
 

Kürzlich hochgeladen

Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night StandCall Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
amitlee9823
 
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
amitlee9823
 
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
ZurliaSoop
 
Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...
Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...
Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...
amitlee9823
 
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get CytotecAbortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Riyadh +966572737505 get cytotec
 
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
amitlee9823
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
MarinCaroMartnezBerg
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al BarshaAl Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
AroojKhan71
 

Kürzlich hochgeladen (20)

Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night StandCall Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
 
CebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxCebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptx
 
Invezz.com - Grow your wealth with trading signals
Invezz.com - Grow your wealth with trading signalsInvezz.com - Grow your wealth with trading signals
Invezz.com - Grow your wealth with trading signals
 
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
 
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
 
Capstone Project on IBM Data Analytics Program
Capstone Project on IBM Data Analytics ProgramCapstone Project on IBM Data Analytics Program
Capstone Project on IBM Data Analytics Program
 
Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...
Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...
Vip Mumbai Call Girls Thane West Call On 9920725232 With Body to body massage...
 
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
 
Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interaction
 
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
 
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get CytotecAbortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
 
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
 
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightCheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
 
Predicting Loan Approval: A Data Science Project
Predicting Loan Approval: A Data Science ProjectPredicting Loan Approval: A Data Science Project
Predicting Loan Approval: A Data Science Project
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFx
 
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al BarshaAl Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
 
April 2024 - Crypto Market Report's Analysis
April 2024 - Crypto Market Report's AnalysisApril 2024 - Crypto Market Report's Analysis
April 2024 - Crypto Market Report's Analysis
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptx
 

GDPR – what does it mean for charities and what you need to consider - Iain Pritchard, Adapta Consulting

  • 1. Prepare for upcoming charity regulations with Microsoft solutions Thursday 11th May 2017
  • 2. GDPR (what difference will it make….?) 11 May 2017
  • 3. • To summarise and explain the changes in data protection obligations that have followed the introduction of the General Data Protection Regulation (GDPR) • To explore and discuss some of the implications for organisations in the sector Purpose of the session
  • 4. • A specialist information systems consultancy • We only work with membership organisations, charities, associations, trusts and others in the NfP sector • We are completely supplier-independent • Our consultants have held senior positions in a broad range of different organisations • Our advice and guidance is based on practical experience gained over many years Adapta Consulting
  • 5. Data Protection – a potted history DPA 1998 PECR 2003 GDPR 25 May 2018 Will be replaced by GDPR Will be updated in time for GDPR Will apply regardless of Brexit
  • 6. • Data Protection Act 1984 and 1998 – in place for 30+ years • Provides rules for organisations that collect and use personal information – applies to manual and electronic records • EU General Data Protection Regulation (GDPR) comes into force in May 2018 …. regardless of Brexit • GDPR builds on DPA but there are significant changes too Data protection
  • 7. • The British Heart Foundation - secretly screened millions of their donors so they could target them for more money - £18,000 fine • The RSPCA - secretly screened millions of their donors so they could target them for more money - £25,000 fine • The Alzheimer’s Society - volunteers used personal email addresses to receive and share information about people who use the charity, stored unencrypted data on their home computers and failed to keep paper records locked away. They were not trained in data protection, the charity’s policies and procedures were not explained to them and they had little supervision from staff – enforcement • The British Pregnancy Advice Service – exposed thousands of personal details to a malicious hacker - £200,000 fine The ICO issued fines of £6K- £18k to 11 charities earlier this year for a combinations of breaches which included sharing data with other charities, finding out information about people that they didn’t provide, and ranking people according to their wealth. This included the NSPCC, GOSHCC, Oxfam, Macmillan Cancer Support, WWF-UK, the Royal British Legion, Guide Dogs for the Blind Association, Cancer Support UK, Cancer Research UK, Battersea Dogs and Cats’ Home, The International Fund for Animal Welfare When things go wrong … some recent sector examples
  • 8. • The Nursing and Midwifery Council … lost dvds ... unencrypted.. £150k fine • North East Lincolnshire Council … missing unencrypted memory stick …£80k fine • Greater Manchester Police … stolen USB stick … unencrypted, no password protection … £150k fine • Royal Veterinary College … loss of a memory card … signed undertaking When things go wrong … more examples, common mistakes • Surrey County Council … misdirected emails with attached files … not encrypted or password protected … £120k fine • North Somerset Council … sent unencrypted emails with personal data to wrong NHS employee … £60k fine
  • 9. Complying with the Act When processing personal and sensitive personal data we have to comply with the 8 principles which are …… 1. Data must be collected lawfully and fairly 2. It must be used only for specified purposes 3. The quantity of data collected should be appropriate 4. The data should be accurate and up to date 5. It should be kept only as long as necessary 6. It should be processed in accordance with the rights of those it concerns 7. It should be kept securely 8. It should not be transferred out of the EEA unless it is to an area which has similar standards
  • 10. What changes with GDPR Active consent Accountability & governance Right to erasure Portability Right to be informed Privacy by design €20 million fines Right to rectification Faster reporting of data breaches Data protection impact assessments Faster subject access Recent consent Demonstrate consent
  • 11. DPA: • Fines of up to £500k • Comparatively low-profile penalties (historically) GDPR: • Penalties likely to be higher profile (consequent reputational risk) • Fines of up to 4% of annual global turnover or 20 million euros (whichever is greater) • Civil and criminal liability for officers and key employees • High risk data breaches must be reported to the supervisory authority within 72 hours Changes – breaches
  • 12. • New accountability requirement - GDPR requires you to show how you comply with the principles • Appropriate technical and organisational measures are needed to ensure and demonstrate that you comply e.g. internal data protection policies such as staff training, internal audits of processing activities, impact assessments • Records of processing activities must be kept where processing personal data that could result in a risk to the rights and freedoms of individuals Changes – governance & accountability
  • 13. • Valid consent to process personal data will be needed instead of implicit consent - a person has actually done something actively to provide their consent • Pre-ticked opt in boxes and empty opt-out boxes (which have to be ticked by the person in order to opt out) will no longer be sufficient • Demonstrate that consent has been given • Consent must be given freely - performance of a contract must not depend upon consent being given when the processing is not actually required to perform the contract • Parental consent will be required to process the personal data of children under the age of 16 (or possibly 13) Changes – consent
  • 14. Changes – the right to be informed Subjects have the right to be informed about ….. • Identity and contact details of the controller and where applicable, the controller’s representative, and the data protection officer • Purpose of the processing and the legal basis for the processing • The legitimate interests of the controller or third party, where applicable • Categories of personal data • Any recipient or categories of recipients of the personal data • Details of transfers to third country and safeguards • Retention period or criteria used to determine the retention period • The existence of each of data subject’s rights • The right to withdraw consent at any time, where relevant • The right to lodge a complaint with a supervisory authority • The source the personal data originates from and whether it came from publicly accessible sources • Whether the provision of personal data part of a statutory or contractual requirement or obligation and possible consequences of failing to provide the personal data • The existence of automated decision making, including profiling and information about how decisions are made, the significance and the consequences • Information about the processing of personal data must be: • Concise, transparent, intelligible and easily accessible • Written in clear and plain language, particularly if addressed to a child • Free of charge
  • 15. • Subject access – usually within a month and for no fee • Right to erasure - right to be forgotten … a data subject has the right to request personal data is erased when it is no longer being processed • Data portability - personal data must be in a format where it can be easily and electronically transferred to another processing system • Right to rectification – if personal data is inaccurate or incomplete Changes – users’ rights
  • 16. • Data processors will have direct and increased responsibilities - they can be held responsible for data breaches • There is still a responsibility on your organisation to ensure that: • Contracts with data processors comply with GDPR • You choose appropriate data processors • Data processors comply with data protection and the GDPR Changes – data processors
  • 17. • Compliance must be considered in the design and implementation of all processes, from start to finish • Data protection can no longer be an afterthought • Data Protection Impact Assessments (DPIA) must be undertaken when appropriate (e.g. when using new technologies and the processing is likely to result in a high risk to the rights and freedoms of individuals) Changes – privacy by design
  • 18. Get ready for GDPR compliance • Develop a strategy for obtaining consent – and a practical as well as legal level of granularity • Consider and document the legal basis for holding personal data • Be able to evidence consent • Plan for subjects’ increased right to be informed – know your data and data handling processes • Update existing and develop new data protection policies and procedures for GDPR compliance …. and implement • Train staff on GDPR requirements, revised policies and procedures • Design and integrate a ‘privacy by design’ approach (e.g. for procurement of products and services, and data and digital development projects)
  • 19. Questions, comments and a bit of discussion..?

Hinweis der Redaktion

  1. 2
  2. 6
  3. 7
  4. 8
  5. 9
  6. 10
  7. 11
  8. 12
  9. 13
  10. 14
  11. 15
  12. 16
  13. 17
  14. 19