Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

Size: px
Start display at page:

Download "Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)"

Transcription

1 Customer Data Protection Temenos module for the General Data Protection Regulation (GDPR)

2 Contents Glossary 03 GDPR Geographical Scope 03 GDPR implementation status 03 Overview of GDPR 03 Financial Institutions and the GDPR 04 Main areas of the GDPR 05 GDPR Applicability 06 DPD and GDPR 07 Strategy from Temenos for GDPR 08 Customer Data Protection 09 Contacts 10 2

3 Glossary GDPR = General Data Protection Regulation DPD = Data Protection Directive DPO = Data Protection Officer GDPR Geographical Scope The GDPR directly affects organisations established inside the European Union. Any institution based within the EU must recognise that personal data is to be processed in accordance to the GDPR. However, the scope of the Regulation also extends to businesses established outside of the EU; if they are providing services to, or monitoring the behavior of individuals within the EU. GDPR implementation status: 4 th May 2016 Adopted 25 th May 2018 To be enforced Overview of GDPR The European Parliament and the Council of the European Union have published the GDPR to replace the outdated terms of the Data Protection Directive from 1995, with updated regulations that reflect the advancement of modern technology. A focal point of the GDPR is the processing of personal data. In banking, large amounts of personal data held and processed for business purpose such as; financial transactions and marketing. Going forward the Regulation will ensure the lawfulness, accuracy and legitimacy of all personal data that is stored and subsequently processed by businesses. The GDPR tightens a number of rights for individuals and allows them to have a greater control over their personal data. The regulation provides a framework for businesses to ensure a consistent approach to data protection across the EU. The legislation will be in force from 25th May 2018 and there is an expectation that financial institutions already have a solid data protection policy in place due to the previous and existing data protection legislation. However, the GDPR brings a number of new challenges banks will need to overcome to be compliant as of May

4 Financial Institutions and the GDPR The overview of the GDPR project is summarised by the following analysis, answering the four important questions: WHAT does this mean for banks? Financial Institutions process huge amounts of personal and sensitive data. Personal data held on customers who are bound by contract (both current and former) are pertinent. However, the safeguarding of data is also relevant to individuals who may not be direct customers of the bank, but have shared personal information, for example on platforms such as online chat-bots or other channels. The method of collecting personal data (and its ongoing processing) is to be reformed under the Regulation. Customers have the right to know exactly what data their bank stores about them, the purpose it is being held or processed and, if applicable, who this information is shared with. It is a legal obligation for businesses to process data in accordance with the Regulation or face penalties of up to 20 million or 4% of global annual turnover, whichever is the greater amount. Breaches are to be notified to the supervisory authority by the data controller within 72 hours. Large penalties and potential reputational damage could be detrimental to businesses, so it is key for banks to maintain good reputation for data protection, and more importantly, retain customer trust. 4 WHO is affected? The GDPR affects all businesses that process data of EU citizens. Therefore, all banks and financial institutions are required to comply with the Regulation. Any bank providing services within the European Union or to individuals within the EU, will need to consider their customers as data subjects within scope of the Regulation. WHEN will the Regulation be enforced? The General Data Protection Regulation will be in force from 25th May It is essential that organisations are compliant with the GDPR, with adequate policies in place, prior to this date to avoid hefty penalties. WHY is this regulatory change needed? Digital growth has caused an influx of data creation. Recent technological advances have left the previous Directive s past terms outdated and inadequate in proportion. Technology considered fundamental in banking today did not exist at the time the previous Directive was enacted; combining this with the expansion of FinTech; an updated Regulation is required to accommodate this evolution of technology. In the age of EU wide digital data flows the GDPR gives data subjects confidence in the free movement of data. The regulation comes into direct effect within each country of the EU, so standardizing the approach to data protection in all EU member states.

5 Main areas of the GDPR The Regulation sets out a number of rights for data subjects. Right to... Be Informed Access Erasure (forgotten) Rectification Restrict Processing Data Portability Object Rights Related to Automated Decision Making and Profiling The Right to be Informed Banks are required to inform their customers exactly what data is stored on them, how it is processed, and who it is shared with. The Right to Access A customer is able to submit a Subject Access Request to request for a copy of all their personal data that is held by the bank. The Right of Erasure (Right to be Forgotten) A bank must erase personal data held on a customer or individual when there is no longer a lawful purpose for holding the data. The Right to Rectification If there is a concern regarding the accuracy of personal data held on a customer, the customer has the right to request these inaccuracies are investigated and rectified. The Right to Restrict Processing If a customer believes data held is being processed illegitimately, a restriction to data processing can be applied until its processing is validated. The Right to Data Portability Banks are required to provide a customer with data previously provided to the bank by the customer, free of charge and in a commonly used machine readable format. This should be provided directly to the customer or ported by the controller externally on request of the data subject. The Right to Object A customer is able to object to certain processing of their data. Objections should be logged and exercised if appropriate, but can be overridden by the bank in the case of legitimate reasoning. Rights Related to Automated Decision Making and Profiling Automated decisions are not definitive and can be queried by customers if the result can legally or significantly affect them in any way. Recording Consent Where the bank is processing data on the basis of consent (E.g. for direct marketing purposes) the consent must be unambiguous and specific, separately given from other matters and use clear, plain language. The consent must be recorded. Transfer of Data Outside EU Banks may only transfer personal data outside the EU if they comply with the requirements of the Rregulation and thereby ensure there are adequate safeguards in place to protect the data. 5

6 GDPR Applicability Data Minimization Privacy Impact Assessments Appoint Data Protection Officer Customers= Data Subjects Personal Data BANK Processing is based on Yes Legitimate, In Scope of the GDPR Legal, Consent or Yes Contractual purpose? GDPR Enforced 25 th May 2018 Start Based in EU (Data Processors and Data Controllers) BANK Providing services or monitoring the bahaviours of data subjects within the EU or relating to data subjects within the EU Privacy by Design No Storing or processing data is illegal Based outside EU No Not in Scope of GDPR processing This is a high level overview of the applicability of GDPR and is not intended to be relied upon. Banks must take their own legal advice on the applicability of the GDPR. This is not legal advice and is provided for illustrative purposes only. Any Financial Institution must do its own investigation to understand the applicability of the Regulation to its business. Customers have the right to; Access Be Informed Portability Rectification Erasure Object Restrict Processing Rights related to Automated decision making and profiling Lawful Processing under GDPR

7 Key differences between the DPD (1995) and GDPR Area Data Protection Directive General Data Protection Regulation Directive VS Regulation Personal Data definition (and other terminology) Rights (and consent) Breach notification and fines Liability on Data Controllers and Data Processors Privacy by Design, Privacy Impact Assessments and Accountability Geographical Impact The Directive set a generic level of data protection principles to be achieved. Each Member State devised its own laws and sanctions; meaning procedures and implications were inconsistent throughout the region. The definitions and terminology; such as personal data ; are broad, unspecific and outdated. A number of rights outlined for individuals. As a result of the Directive, EU Member States published their own terms for breaches and fines; with no limit or guidelines as standard. Only data controllers could be held accountable for breaches. No defined strategy for general approaches to data protection or governance within organisations. Extended only to EU Member States and is no more expansive in its territorial reach. The Regulation is a binding legal legislation coming into affect within all EU Member States. This means data protection laws should be harmonised across the EU. However, it is worth noting there still remains areas of derogation for each member state (e.g. law enforcement) Definition of personal data is expanded upon to be more relevant to current technology; i.e. the inclusion of IP addresses and biometric data as personal identifiers. The specificity of definitions within the document are modernised. A number of rights are highlighted and enhanced for data subjects. A higher requirement of consent is cited throughout. Pre ticked boxes or silence do not signify consent. All data controllers are required to inform the relevant supervisory authority of any data breach within 72 hours. Harsher fines sanctions are imposed to act as a more serious deterrent of misconduct; fines of up to 4% annual global turnover or 20 million can be sanctioned for breaches. Processors can also be held accountable for data breaches a contract is required with the data controller to process data. A Data Protection Officer (DPO) is required to be appointed within organisations (when specific conditions are met). Companies must adopt practices to ensure processes give greater assurance in relation to the privacy of individuals. For example, privacy impact assessments must be undertaken prior to commencing processing, pseudonymisation and encryption must be considered.. Systems must be designed with privacy in mind, with settings defaulting to maximize privacy. EU law affecting any company that provides services to or monitors the behaviours with the EU or its citizens. Adequate levels of data protection are required when transferring data to countries outside of the EU. If there is uncertainty, specific authorisations may be required. 7

8 Strategy from Temenos for GDPR How Temenos Can Help? Applying our functional and technical understanding of the rules of data protection and our experience of working within the financial sector, we are able to assist clients to analyse business models to help them understand the practical and financial implications of the new Regulation and develop strategies for dealing with such implications within their usage of Temenos products. With the arrival of the GDPR, it is more important than ever to plan for the impact of regulatory rules and design an efficient response. Temenos can assist with our knowledge and experience. Our experience in developing and implementing regulatory solutions at various banks across the globe will benefit our clients; assisting clients to meet regulatory obligations with limited disruption to their business. Key offerings as part of the Customer Data Protection module in Temenos Products Temenos aims to provide a system that will assist a company s capability in maintaining personal data and complying with the Regulation. Enabling the rights of data subjects to be performed in a simple and intuitive way. New functionality will be provided that addresses potential gaps identified in data protection impact assessments our clients may recently have undertaken. The Customer Data Protection module will provide clients more functionality, and therefore more control, of personal data and processing throughout the systems. Privacy by Design is fundamental to implementing banking solutions that manage personal data. The module will include; Definition of Personal Data Temenos functionality allows the bank to set a customisable definition of personal data permitting the bank to manage and track such data. A predefined list of applicable fields holding personal data; including name, location data etc. will be provided and can be tailored per client; to be inclusive of company specific or local data that will be affected. Recording Consent The module will provide a configurable consent management system, allowing different levels and types of consent to be recorded. Data Erasure The module will enable the logical erasure of personal data which clients can decide is no longer legitimately required to be held from the Temenos system(s). Reporting Customisable reports will be available, their output able to be exported into machine readable formats to satisfy Subject Access Requests, and allow data portability. GDPR Processing Additional functionality will be available to assist regulatory compliant processing; such as exercising objections or restrictions. A data request management tool will be provided to log and track rights requests made by data subjects. 8

9 Customer Data Protection module Recording data? What data do we store, where and why? What actions do we need to take if a subject right is exercised? How is that carried out in each Product? Data Capture Identify Personal Data Define Action Implement The purpose and basis of processing; consent or otherwise. A metadata model that defines personal data within Temenos systems. A set of processing rules for when data subject s rights are invoked. Provision of specific tools that implement the requirements within each product. Temenos Customer Data Protection module The Temenos Customer Data Protection module will provide the tools and functionality to assist a financial institution s compliancy to the General Data Protection Regulation. It is the responsibility of the Financial Institution itself to ensure internal policies and procedures are in place across all systems to ensure compliancy. 9

10 Contacts For any further queries and interest in getting the Customer Data Protection Solution in Temenos Core Banking, please get in touch with: Peter Ryan Product Manager Temenos UK Ltd 5th Floor, 71 Fenchurch Street, London EC3M 4TD, UK T: D: E: Rachel Vardon Business Analyst Temenos UK Ltd 5th Floor, 71 Fenchurch Street, London EC3M 4TD, UK T: D: E: 10

11 TEMENOS is a registered trademarks of Temenos Headquarters SA 2017 Temenos Headquarters SA - all rights reserved. Warning: This document is protected by copyright law and international treaties. Unauthorised reproduction of this document, or any portion of it, may result in severe and criminal penalties, and will be prosecuted to the maximum extent possible under law.

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie Get ready A Guide to the General Data Protection Regulation (GDPR) elavon.ie The General Data Protection Regulation (GDPR) will regulate the privacy and handling of the personal data of individuals in

More information

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT WHAT GDPR MEANS FOR RECORDS MANAGEMENT Presented by: Sabrina Guenther Frigo Overview Background Basic Principles Scope Lawful Processing Data Subjects Rights Accountability & Governance Data Transfers

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

Preparing for the GDPR

Preparing for the GDPR Preparing for the GDPR Note: These slides and the accompanying presentation contain a general summary and are not legal advice. Niall Rooney 03/11/2017 (1) Data Protection The Right to Data Protection

More information

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 This document is a broad overview of the GDPR and does not provide legal advice. We urge you to consult with your own

More information

Introduction to the General Data Protection Regulation (GDPR)

Introduction to the General Data Protection Regulation (GDPR) Introduction to the General Data Protection Regulation (GDPR) #CIPR / @CIPR_UK This guide is worth 5 CPD points Introduction to the General Data Protection Regulation (GDPR) / 2 Contents 1 Introduction

More information

More information at cventconnect.com/europe/mobileapp

More information at cventconnect.com/europe/mobileapp Download and Login to the Cvent CONNECT Europe Mobile Event App Tap On Schedule Find Your Session Access Polls and Live Q&A More information at cventconnect.com/europe/mobileapp Cvent CONNECT Europe General

More information

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) The first IBM Personal Computer was introduced just over 35 years ago, on August 12, 1981. The first-generation iphone was introduced in the

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

What you need to know. about GDPR. as a Financial Broker. Sponsored by

What you need to know. about GDPR. as a Financial Broker. Sponsored by What you need to know about GDPR as a Financial Broker Dear Partner The regulatory and compliance environment is ever changing and the burden and requirements on financial services professionals continues

More information

EU General Data Protection Regulation in the digital age: Are you ready?

EU General Data Protection Regulation in the digital age: Are you ready? EU General Data Protection Regulation in the digital age: Are you ready? What do you need to know about the new EU General Data Protection Regulation? Data protection has entered a period of unprecedented

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

GDPR a legal overview

GDPR a legal overview GDPR a legal overview Andrew Gilchrist and Noirin McFadden, K&L Gates LLP Copyright 2017 by K&L Gates LLP. All rights reserved. Background to reform WHY WAS REFORM REQUIRED? We ve had data protection laws

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) The EU General Data Protection Regulation (GDPR) What is the GDPR? The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) was adopted on 27 April,

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

A guide to GDPR the effect on all UK organisations

A guide to GDPR the effect on all UK organisations A guide to GDPR the effect on all UK organisations Personal Data Penalties Consent Data Breach Notification GDPR Right to Object Data Portability Right to be Forgotten A white paper from Eazipay Ltd October

More information

WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT

WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT WHAT IS GDPR? The EU General Data Protection Regulation (GDPR) comes into force on 25 May 2018. Within this document we ll explore what

More information

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR Factsheet - Key Provisions and steps for Compliance GDPR Factsheet - Key Provisions and steps for Compliance Organisations in the Leisure & Hospitality industry hold vast amounts of personal data relating to customers, employees, and suppliers as well as

More information

December 28, 2018, New Delhi, INDIA

December 28, 2018, New Delhi, INDIA LexArticle December 28, 2018, New Delhi, INDIA GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW If you have questions or would like additional

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes

Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes 1 INTRODUCTION The General Data Protection Regulation (GDPR) comes into force in all EU Member States on 25.

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

GDPR factsheet Key provisions and steps for compliance

GDPR factsheet Key provisions and steps for compliance GDPR factsheet Key provisions and steps for compliance Organisations hold vast amounts of personal data relating to customers, employees, and suppliers as well as within marketing databases. Compliance

More information

GDPR: What Every MSP Needs to Know

GDPR: What Every MSP Needs to Know Robert J. Scott GDPR: What Every MSP Needs to Know Speaker Robert J. Scott Agenda Purpose GDPR Intent & Obligations Applicability Subject-matter and objectives Material scope Territorial scope New Rights

More information

GDPR - Salon Guide Contents

GDPR - Salon Guide Contents GDPR for salons INTRODUCTION 1 GDPR - Salon Guide Contents GDPR - Salon Guide 1. INTRODUCTION 1 a. Already comply with Data Protection? 1 b. What is personal data? 4 c. Who controls the data? 4 d. What

More information

GDPR SMART. The Neopost Guide to Managing GDPR. ermissions Personal Data Right of Access. nal Data Right of Access Consent Permissi

GDPR SMART. The Neopost Guide to Managing GDPR. ermissions Personal Data Right of Access. nal Data Right of Access Consent Permissi s Personal Data Right of Access l Data Right of Access Consent P f Access Consent Permissions Pe sent Permissions Personal Data Rig ions Personal Data Right of Access nal Data Right of Access Consent P

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

General Data Protection Regulation (GDPR) Business Guide

General Data Protection Regulation (GDPR) Business Guide General Data Protection Regulation (GDPR) Business Guide May 2018 LEGAL DISCLAIMER The information contained in this guide is for general guidance purposes only. It should not be taken for, nor is it intended

More information

PERSPECTIVE. GDPR - An industry and geography agnostic regulation. Abstract

PERSPECTIVE. GDPR - An industry and geography agnostic regulation. Abstract PERSPECTIVE GDPR - An industry and geography agnostic regulation Abstract As the deadline to comply with the General Data Protection Regulation (GDPR) draws near, many organizations are unaware of what

More information

Preparing for the General Data Protection Regulation (GDPR)

Preparing for the General Data Protection Regulation (GDPR) Preparing for the General Data Protection Regulation (GDPR) ServiceNow Governance, Risk, and Compliance Table of Contents What is the GDPR?...3 Key Requirements for the GDPR...4 Accountability, Policies,

More information

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 1 PURPOSE OF THIS DOCUMENT 2 This document is to be used as a guide for advertisers on how they should work with their agencies,

More information

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016 Dealing with the EU Data Protection Regulation in Practice William Long, Partner Sidley Austin LLP February 11, 2016 Do you need to comply? The Regulation will apply to a business processing personal data:

More information

EU General Data Protection Regulation: are you ready?

EU General Data Protection Regulation: are you ready? EU General Data Protection Regulation: are you ready? Contents What you need to know about the new EU General Data Protection Regulation Is your organization ready for the EU General Data Protection Regulation?

More information

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak PROFESSIONAL INDEPENDENT ADVISERS LTD DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Training Manual Data Protection Officer is Mike Bandurak GDPR introduction

More information

The GDPR: What does it mean for executive search?

The GDPR: What does it mean for executive search? The GDPR: What does it mean for executive search? At Invenias, we are committed to working in partnership with our customers to ensure a streamlined journey to compliance. Our customers benefit from data

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

EU General Data Protection Regulation: Are you ready?

EU General Data Protection Regulation: Are you ready? EU General Data Protection Regulation: Are you ready? Powered by Global Markets EY Knowledge Contents What do you need to know about the new EU General Data Protection Regulation? Are organisations ready

More information

EU GENERAL DATA PROTECTION REGULATION

EU GENERAL DATA PROTECTION REGULATION EU GENERAL DATA PROTECTION REGULATION GENERAL INFORMATION DOCUMENT This resource aims to provide a general factsheet to Asia Pacific Privacy Authorities (APPA) members, in order to understand the basic

More information

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company )

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company ) RSD Technology Limited - Data protection policy: Introduction Company Name: Document DP3 Topic: RSD Technology Limited ( the Company ) Data Protection Policy Data protection Date: 25 th May 2018 Version:

More information

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction Introduction On April 2016 the European Parliament approved the General Data Protection Regulation (GDPR). This new regulation, with mandatory implementation by Member States (MS) and businesses that have

More information

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Legal02#67236978v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Notes: We recommend that any business looking to comply with the

More information

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data OPTIN checklist OVERVIEW 1 GDPR Checklist This checklist sets out activities you will need to consider and act on by the compliance deadline of 25th May 2018. Use this to help you identify what support

More information

GDPR Webinar : Overview & practical compliance steps. 23 October 2017

GDPR Webinar : Overview & practical compliance steps. 23 October 2017 GDPR Webinar : Overview & practical compliance steps 23 October 2017 1 Dr Michelle Goddard Director Policy & Communication, EFAMRO Mattias Strandberg Skribent, dagensanalys.se copyright efamro 2010 2 About

More information

The GDPR enforcement deadline is looming are you ready?

The GDPR enforcement deadline is looming are you ready? Link to Article The GDPR enforcement deadline is looming are you ready? 1 Compliance Is this relevant to the Wealth Management community is Asia? It is relevant to your business if you have an establishment

More information

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry 1 Contents Introduction 5 Brexit: GDPR or New UK Law? 8 The eprivacy Directive 10 The GDPR: 10 Key Areas

More information

Technical factsheet: General Data Protection Regulation (GDPR) April 2018

Technical factsheet: General Data Protection Regulation (GDPR) April 2018 Technical factsheet: General Data Protection Regulation (GDPR) April 2018 1 1 CONTENTS 1. What is GDPR? 2. How is GDPR different to the old Data Protection Act? 3. Why does it apply to members? 4. What

More information

Getting Ready for the. General Data Protection Regulation GDPR. A Guide by Mason Hayes & Curran. Dublin, London, New York & San Francisco. MHC.

Getting Ready for the. General Data Protection Regulation GDPR. A Guide by Mason Hayes & Curran. Dublin, London, New York & San Francisco. MHC. Getting Ready for the General Data Protection Regulation GDPR 2018 Dublin, London, New York & San Francisco A Guide by Mason Hayes & Curran MHC.ie The contents of this publication are to assist access

More information

GDPR - 10 THINGS YOU NEED TO KNOW (US PERSPECTIVE) 1. Privacy and data protection are fundamental rights

GDPR - 10 THINGS YOU NEED TO KNOW (US PERSPECTIVE) 1. Privacy and data protection are fundamental rights GDPR - 10 THINGS YOU NEED TO KNOW (US PERSPECTIVE) 1. Privacy and data protection are fundamental rights Privacy is internationally recognised as a fundamental human right, like the right to free speech

More information

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond InsideNGO's 2017 Annual Conference Washington, DC July 20, 2017 Shannon Yavorsky Partner, Venable LLP David Goodman Global Non-

More information

GDPR journey: from ready to compliant GDPR survey results

GDPR journey: from ready to compliant GDPR survey results GDPR journey: from ready to compliant GDPR survey results Readiness at a glance The General Data Protection Regulation (or GDPR ) took full effect on 25 May 2018. As a key data protection regulation,

More information

GDPR Compliance Checklist

GDPR Compliance Checklist GDPR Compliance Checklist GDPR Compliance Checklist This GDPR Compliance Checklist sets out the key requirements that the General Data Protection Regulation will introduce into EU Privacy law on 25 May

More information

What do companies need to do?

What do companies need to do? Briefing GDPR The General Data Protection Regulation ( GDPR ) will come into effect on 25 May 2018. The GDPR will replace the existing data protection laws in all EU member states and is designed to result

More information

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

GENERAL DATA PROTECTION REGULATION Guidance Notes

GENERAL DATA PROTECTION REGULATION Guidance Notes GENERAL DATA PROTECTION REGULATION Guidance Notes What is the GDPR? Currently, the law on data protection requiring the handling of data which identifies people to be done in a fair way, is contained in

More information

What does the GDPR mean for recruitment?

What does the GDPR mean for recruitment? What does the GDPR mean for recruitment? www.recruitment.software Contents 04 What is GDPR? In May 2018, Europe s new data protection rules will come into effect. 04 Who is responsible? 05 What are the

More information

Preparing Your Vendor Agreements for the General Data Protection Regulation

Preparing Your Vendor Agreements for the General Data Protection Regulation Preparing Your Vendor Agreements for the General Data Protection Regulation Oliver Yaros Partner - London +44 (0)203 130 3698 oyaros@mayerbrown.com Lei Shen Senior Associate - Chicago +1 312 701 8852 lshen@mayerbrown.com

More information

General Data Protection Regulation - Explained

General Data Protection Regulation - Explained General Data Protection Regulation - Explained Bernard Cogan & Bobby Gould CUNA Mutual Group ACE Conference & AGM 2017 12 th May 13 3h May 2017 Copthorne Hotel (Birmingham) Are you familiar with GDPR Don't

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

GDPR A guide to key articles for security & privacy professionals

GDPR A guide to key articles for security & privacy professionals GDPR A guide to key articles for security & privacy professionals SPONSORED BY TABLE OF CONTENTS 1 5. Introduction 6. Data Protection Principles (Article 5) 7. Transparency and Notice (Article 12) 8. Security

More information

A summary of the implications of the General Data Protection Regulations (GDPR)

A summary of the implications of the General Data Protection Regulations (GDPR) Introduction A summary of the implications of the General Data Protection Regulations (GDPR) 1. The General Data Protection Regulation (GDPR) will apply in the UK from 25 May 2018. Various implications

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

EU-GDPR and the cloud. Heike Fiedler-Phelps January 13, 2018

EU-GDPR and the cloud. Heike Fiedler-Phelps January 13, 2018 . EU-GDPR and the cloud Heike Fiedler-Phelps January 13, 2018 Disclaimer SAP does not provide legal advice The following presentation is only about a high level discussion about GDPR. 2 EU-GDPR Summary

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information

Privacy Policy 2018 VERSION 1.0

Privacy Policy 2018 VERSION 1.0 Introduction 1.1 We are committed to safeguarding the privacy of our website visitors and service users. 1.2 This policy applies where we are acting as a data controller with respect to the personal data

More information

GDPR POLICY. This policy complies with the requirements set out in the GDPR, which will come into effect on

GDPR POLICY. This policy complies with the requirements set out in the GDPR, which will come into effect on GDPR POLICY Sponsors Statement All The Bishop of Winchester Academy policies exist to support the Sponsors vision, Christian ethos and values that are embedded in the day-to-day and long term running of

More information

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR General Data Protection Regulation Philippe Roggeband Business Development, Manager, GSSO EMEAR Why should you care? Data Protection, and compliance with the General Data Protection regulation, is NOT

More information

SAP and SAP Ariba Solution Support for GDPR Compliance

SAP and SAP Ariba Solution Support for GDPR Compliance Frequently Asked Questions EXTERNAL The General Data Protection Regulation (GDPR) SAP Ariba Source-to-Settle Solutions SAP and SAP Ariba Solution Support for GDPR Compliance The European Union s General

More information

Data Flow Mapping and the EU GDPR

Data Flow Mapping and the EU GDPR Data Flow Mapping and the EU GDPR Adrian Ross LLB (Hons), MBA GRC Consultant IT Governance Ltd 29 September 2016 www.itgovernance.co.uk Introduction Adrian Ross GRC Consultant Infrastructure services Business

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) EU General Data Protection Regulation (GDPR) May 23, 2018 Dixie B. Baker, Ph.D. Agenda GDPR Basics Key Changes from Data Protection Directive Special Categories Consent Conditions and Elements HIPAA and

More information

The General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) Risk Regulation The General Data Protection Regulation (GDPR) Cyber security Preparing your business for the GDPR September 2017 Contents What is the GDPR and what does it change? Section Page What is

More information

GDPR is coming in 108 days: Are you ready?

GDPR is coming in 108 days: Are you ready? Charles-Albert Helleputte Partner, Brussels GDPR is coming in 108 days: Are you ready? Diletta De Cicco Legal Consultant, Brussels 6 February 2018 +32 2 551 5982 chelleputte@mayerbrown.com +32 2 551 5974

More information

GDPR The role of the Internal Audit Function

GDPR The role of the Internal Audit Function www.pwc.com/mt GDPR The role of the Internal Audit Function What should the Internal Auditor do? 24 MAY 2017 it s not your problem yet 2 How does GDPR feature in your 2017 audit plan? much of 2017 will

More information

The General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) Risk Regulation The General Data Protection Regulation (GDPR) Cyber security Preparing your business for the GDPR Contents Section Page What is the GDPR and what does it change? 01 Understanding the core

More information

With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation?

With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation? With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation? The General Data Protection Regulation The GDPR applies to all organizations

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

General Data Protection Regulation

General Data Protection Regulation General Data Protection Regulation Caroline Budde Vice President, Compliance, Global Privacy Officer Walgreens Boots Alliance Agenda Overview of global data protection The General Data Protection Regulation

More information

GENERAL DATA PROTECTION REGULATION.

GENERAL DATA PROTECTION REGULATION. For the use of mortgage intermediaries and other professionals only. GENERAL DATA HALIFAX INTERMEDIARIES KEY CHANGES GUIDE MAY 2018 REGULATION >SELECT A TILE FOR MORE INFORMATION WHAT IS THE GDPR? KEY

More information

The ecommerce Guide to GDPR. How to Ensure Compliance and a Competitive Edge

The ecommerce Guide to GDPR. How to Ensure Compliance and a Competitive Edge The ecommerce Guide to GDPR How to Ensure Compliance and a Competitive Edge 03 Table of Contents Executive Summary 03 What is the GDPR? 04 What Does the GDPR Mean to ecommerce? 06 Challenges to Overcome

More information

Nissa Consultancy Ltd Data Protection Policy

Nissa Consultancy Ltd Data Protection Policy Nissa Consultancy Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments (DPIA)

More information

A Practical Guide to Data Protection for Information Professionals

A Practical Guide to Data Protection for Information Professionals A Practical Guide to Data Protection for Information Professionals Naomi Korn and Carol Tullo on behalf of NKCC NKCC 2018. All Rights Reserved. www.naomikorn.com The information contained within this document

More information

GDPR. https://www.eugdpr.org/eugdpr.org.html

GDPR. https://www.eugdpr.org/eugdpr.org.html GDPR https://www.eugdpr.org/eugdpr.org.html GDPR FAQs When is the GDPR coming into effect? Frequently Asked Questions about the incoming GDPR. The GDPR was approved and adopted by the EU Parliament in

More information

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only.

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only. EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations For private circulation only Risk Advisory Preface Does the EU GDPR impact organisations in India? Yes!

More information

GENERAL DATA PROTECTION REGULATION

GENERAL DATA PROTECTION REGULATION GENERAL DATA PROTECTION REGULATION A survey of the readiness of Irish business towards gdpr implementation PART II November About Mazars Mazars is an integrated and independent professional service firm

More information

GDPR: what you need to know

GDPR: what you need to know GDPR: what you need to know Getting to grips with the EU General Data Protection Regulation (GDPR) Introduction In May 2018, the European Union s (EU) GDPR ushers in unprecedented data protection for EU

More information

The GDPR Are you ready?

The GDPR Are you ready? The GDPR Are you ready? kpmg.ie The GDPR - Overview The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) will come into force from 25th May 2018, replacing the existing data protection

More information

Preparation Guide to the New European General Data Protection Regulation

Preparation Guide to the New European General Data Protection Regulation Preparation Guide to the New European General Data Protection Regulation 1. Introduction 2. The Application of the Regulation to Businesses The General Data Protection Regulation (GDPR) is to protect citizens

More information

Brexit and the Future of Data Protection

Brexit and the Future of Data Protection Brexit and the Future of Data Protection Max Todd Information Compliance Team, Council Secretariat Tuesday 27 September 2016 General Data Protection Regulation (GDPR) Applies throughout EU from 25 May

More information

Data protection COLLECT STORE USE/RE USE DATA? What is personal data? Better rules for small business. January 2017 EN. You have to abide by the rules

Data protection COLLECT STORE USE/RE USE DATA? What is personal data? Better rules for small business. January 2017 EN. You have to abide by the rules Data protection 0100101000011010100010001010110101101111000101000 00101000011010100010001010110101101111000101 01001001010000110101000100010101101011011110001 Better rules for small business Stronger rules

More information

Preparing for the GDPR Orla O Hannaidh - Womble Bond Dickinson

Preparing for the GDPR Orla O Hannaidh - Womble Bond Dickinson womblebonddickinson.com Preparing for the GDPR Orla O Hannaidh - Womble Bond Dickinson Agenda What is the GDPR? How Could it Apply to US companies? What are a Few Key Requirements? Share common challenges

More information

Getting Ready for the GDPR

Getting Ready for the GDPR Getting Ready for the GDPR Ann Cartwright Information Governance Lead Sefton Council for Voluntary Service (CVS) Registered Charity No. 1024546. Company Limited by Guarantee No. 2832920. Suite 3B, 3rd

More information

EU General Data Protection Regulation (GDPR) A Point of View. For private circulation only. Risk Advisory

EU General Data Protection Regulation (GDPR) A Point of View. For private circulation only. Risk Advisory EU General Data Protection Regulation (GDPR) A Point of View For private circulation only Risk Advisory Preface Does the EU GDPR impact organisations in India? Yes! This new law will have a profound impact

More information

General Data Protection Regulation

General Data Protection Regulation October 2017 Whitepaper General Data Protection Regulation What does it mean for you and your organization? Page 1 General Data Protection Regulation (GDPR) From May 2018, the General Data Protection Regulation,

More information

New General Data Protection Regulation - an introduction

New General Data Protection Regulation - an introduction New General Data Protection Regulation - an introduction Netnod spring meeting 2017 Johan Hübner, Partner, Advokat Erika Hammar, Associate Agenda Background Why you need to care about the new data privacy

More information

The General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) Risk Regulation The General Data Protection Regulation (GDPR) Cyber security Preparing your business for the GDPR September 2017 Contents Section Page What is the GDPR and what does it change? 01 Understanding

More information

GDPR & SMART PIA. Wageningen University Feb 2017

GDPR & SMART PIA. Wageningen University Feb 2017 GDPR & SMART PIA Wageningen University Feb 2017 Tips for Action: Anticipate on the new EU General Data Protection Regulation (GDPR) to determine the privacy standards GDPR has been adopted by EU Parliament

More information