New EU-GDPR: Challenges for Universities and Research Organisations

Size: px
Start display at page:

Download "New EU-GDPR: Challenges for Universities and Research Organisations"

Transcription

1 New EU-GDPR: Challenges for Universities and Research Organisations Prof. Dr. Ing. Ramin Yahyapour CIO Georg-August-Universität Göttingen and University Medical Centre Director GWDG EUNIS workshop for Data Protection and IT Security Berlin, 21. April 2017

2 About GWDG Joint compute and research centre by the University of Göttingen and the Max Planck Society Serving over customers scientists and students external researchers Göttingen Campus University 200 institutes and 13 faculties Number of employees: 14,000 Research scientists: 3,000 Professors: 400 Students: 34,000 Academic Medical Centre (UMG) 1500 beds 7000 staff Göttingen Campus Partners 5 Max Planck Institutes, Leibnitz Institute DPZ, Academy of Science, 2

3 GDPR a relevant topic to science German Council for Scientific Information Infrastructures (RfII) appointed by the Joint Science Conference of the Federal States and the Federal Government of Germany Organized workshops and just issued recommendation for DPR and research data managament March 2017: 3

4 How do the New EU-DGPR affect universities? Roles to be separated: The university as user of external services (third party processor) The university as a data processing entity and in-house service provider (controller and processor in-house) Data-related science Majority of research is data-driven, data is collected, analyzed, and new insights gained The expectations and requirements differ: enabling science/teaching, being compliant, being efficient 4

5 New EU-GDPR as user of external services GDPR will only be one aspect of selecting a business partner or outsourcing a service More often a major mismatch of GDPR rules, the actual privacy statement/terms of use by companies, and the expectations of customer. Universities often not in the situation to impose terms on companies offers. In general, There are many projects/data without minor requirements on DPR There are projects/data with critical requirements on DPR 5

6 Data Privacy at a University In general most universities/research organizations in Germany run best practice standards Data privacy officer in place Established processes to document relevant data processing Maintaining an asset register of relevant data processing Common technical and organizational measures in place All well? Depends 6

7 Challenges before the new EU-GDPR What to do to be legally compliant? Guidelines often not specific and leave room for interpretation Leads to risk assessment whether processes are compliant What rules apply when? Different legal environment; e.g. Germany in its federal structure had different law for states Who is responsible? Universities and research organizations are not homogenous entities Typically no top down structure; leading to incomplete application of guidelines. 7

8 Taxonomy of data processing at an university Central administrative services Not research Centrally funded Run on central infrastructure On data protection Mostly well documented processes Mostly well managed DPO involved, also ethics committee, worker representation, student council etc. Large collaborative projects research Many scientists involved External funding Increasingly considering data management plans, security concepts, sometimes required by funding agency Data privacy sometimes a topic depending on discipline Often run on central infrastructure Normal research projects long-tail of science Often only 1-2 scientists involved Sometimes including use of personal or sensitive data Often no data management plan Infrastructure can be central, decentral or external Limited central insight Often no consideration of data privacy, data management plans, security requirements >

9 New EU-GDPR It provides for a harmonization of the data protection regulations throughout the EU, thereby making it easier for non-european companies to comply with these regulations; however, this comes at the cost of a strict data protection compliance regime with severe penalties of up to 4% of worldwide turnover Reasonable objectives Simplifications but new obligations Consequences to scientific research to be assessed 9

10 Assessment of new EU-GDPR Scope of GDRP: Applies to Universities and Research Organisation Above national law But many aspects up to national interpretation = weakening the objective of harmonizing regulations Science research mentioned as special case details unclear Will only apply to scientific projects and not all data collected at research organizations = Mix of requirements at research organisations 10

11 Assessment of new EU-GDPR Art. 1 - Consent Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. For scientific projects, consent management is getting increasingly complex and practially non maintainable (informing, revoking) Open: Informed versus broad consent. = No real help from EU-GDPR 11

12 Assessment of new EU-GDPR Art. 83 Penalties and Sanctions Infringements shall be subject to administrative fines up to EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: Does it apply to research organizations? Would it be enforced? How is turn-over calculated? = probably universities and research organizations not in focus = however, subject to compliant risk management 12

13 Assessment of new EU-GDPR Art. 33/34 Notification of data breaches the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority personal data breach is likely to result in a high risk to natural persons, the controller shall communicate the personal data breach to the data subject without undue delay. The required notification actions need to be analyzed and established No major problem to be expected But additional effort Requires additional teaching and training of scientists to raise awareness 13

14 Assessment of new EU-GDPR Art. 4 (1) Definition of personal data personal data means any information relating to an identified or identifiable natural person ( data subject ); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; The GDPR gives many aspects and hints on what personal data is. However, there is still plenty of room for interpretation to local authorities. = Different interpretations will lead to varying requirements. No common standard guidelines. 14

15 Assessment of new EU-GDPR Art Processing through a Third Party Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller The regulations towards a third party processor are very similar to prior German regulations. Simplifications in terms of how the contract can be assured (not necessarily written, one-sided etc). No requirement to check compliance of processor. = Easier to use external third parties 15

16 Assessment of new EU-GDPR Art Security of processing implement appropriate technical and organisational measures Recurring term with significant impact on daily work in research organizations What are the appropriate TOM? Who defines them? How are they compared/selected/compliance shown? = Little interest to be innovative in these definitions = Common, acceptable standards needed 16

17 Assessment of new EU-GDPR Art Security of processing (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. There are no clear definitions given. The major work (and cost) lies in adopting and maintaining such measures: ISO2700x, German BSI, Conflicting objectives in cost/effort versus level of security. All strongly dependent on the stance of the supervisory authorities. 17

18 Assessment of new EU-GDPR Art 40 - Code of Conduct Associations and other bodies representing categories of controllers or processors may prepare codes of conduct for the purpose of specifying the application of this Regulation shall contain mechanisms which enable the body referred to in Article 41(1) to carry out the mandatory monitoring of compliance Possibility of Code of Conduct (CoC) for research organizations? One CoC or many? Who should define it? Only reasonable if they are accepted by supervisory authority. Mandatory monitoring of compliance is new. First discussion showed a CoC could be useful but authorities are not yet prepared. Major risk that CoC/TOM are required in a non manageble way. 18

19 Role of authorities The GDPR leaves many aspects still up to national regulatory authorities or the supervising authorities The goal of harmonization seems valid and achieved in some aspects. but in practice, the attitude to data protection by the responsible authorities will remain different and lead to very different procedures. As science is increasingly collaborative beyond borders, this will lead to shopping and selection of friendly jurisdictions. 19

20 Disparity business versus research The GDPR is obviously written with businesses in mind and not universities/research organizations. The processes for public bodies like universities and research organizations seems increasingly more complex. While there are special consideration for science, the real life situation for companies seems more flexible. There is a valid risk that certain research will only take place at companies and not at public research institutions. 20

21 Summary The EU-GDPR simplifies some aspects and makes reasonable steps towards harmonization. It does not yet reach its goals and requires further specification. Many aspects of the GDPR are very similar to existing German national privacy laws. Nevertheless, there are still several new requirements which will take time and effort. Plenty of aspects remain vague or undefined which makes the practical adoption difficult, slow and expensive. The attitude of national supervising authorities will be essential whether the goals can be reached. Requirements of science are not yet well covered. 21

22 Thank you! Questions? Contact Prof. Dr. Ing. Ramin Yahyapour phone: Gesellschaft für wissenschaftliche Datenverarbeitung mbh Göttingen Am Fassberg Göttingen 22

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) The EU General Data Protection Regulation (GDPR) What is the GDPR? The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) was adopted on 27 April,

More information

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 This document is a broad overview of the GDPR and does not provide legal advice. We urge you to consult with your own

More information

GDPR: What Every MSP Needs to Know

GDPR: What Every MSP Needs to Know Robert J. Scott GDPR: What Every MSP Needs to Know Speaker Robert J. Scott Agenda Purpose GDPR Intent & Obligations Applicability Subject-matter and objectives Material scope Territorial scope New Rights

More information

Preparing for the General Data Protection Regulation (GDPR)

Preparing for the General Data Protection Regulation (GDPR) Preparing for the General Data Protection Regulation (GDPR) ServiceNow Governance, Risk, and Compliance Table of Contents What is the GDPR?...3 Key Requirements for the GDPR...4 Accountability, Policies,

More information

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction Introduction On April 2016 the European Parliament approved the General Data Protection Regulation (GDPR). This new regulation, with mandatory implementation by Member States (MS) and businesses that have

More information

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) The first IBM Personal Computer was introduced just over 35 years ago, on August 12, 1981. The first-generation iphone was introduced in the

More information

The General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) Risk Regulation The General Data Protection Regulation (GDPR) Cyber security Preparing your business for the GDPR September 2017 Contents What is the GDPR and what does it change? Section Page What is

More information

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie Get ready A Guide to the General Data Protection Regulation (GDPR) elavon.ie The General Data Protection Regulation (GDPR) will regulate the privacy and handling of the personal data of individuals in

More information

EU General Data Protection Regulation in the digital age: Are you ready?

EU General Data Protection Regulation in the digital age: Are you ready? EU General Data Protection Regulation in the digital age: Are you ready? What do you need to know about the new EU General Data Protection Regulation? Data protection has entered a period of unprecedented

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

GDPR is coming soon. Are you ready. Steven Ringelberg.

GDPR is coming soon. Are you ready. Steven Ringelberg. GDPR is coming soon. Are you ready. Steven Ringelberg steven@ringelberglaw.com 616 227 6403 Agenda Who am I Overview What data do you have that is covered and where is it? What rights do individual data

More information

The General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) Risk Regulation The General Data Protection Regulation (GDPR) Cyber security Preparing your business for the GDPR September 2017 Contents Section Page What is the GDPR and what does it change? 01 Understanding

More information

The New EU General Data Protection Regulation 1

The New EU General Data Protection Regulation 1 The New EU General Data Protection Regulation 1 Dear clients and friends, On 14 April 2016 the EU Parliament formally approved the General Data Protection Regulation ( the Regulation ). The Regulation

More information

New General Data Protection Regulation - an introduction

New General Data Protection Regulation - an introduction New General Data Protection Regulation - an introduction Netnod spring meeting 2017 Johan Hübner, Partner, Advokat Erika Hammar, Associate Agenda Background Why you need to care about the new data privacy

More information

The General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) Risk Regulation The General Data Protection Regulation (GDPR) Cyber security Preparing your business for the GDPR Contents Section Page What is the GDPR and what does it change? 01 Understanding the core

More information

Preparing for the GDPR

Preparing for the GDPR Preparing for the GDPR Note: These slides and the accompanying presentation contain a general summary and are not legal advice. Niall Rooney 03/11/2017 (1) Data Protection The Right to Data Protection

More information

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond InsideNGO's 2017 Annual Conference Washington, DC July 20, 2017 Shannon Yavorsky Partner, Venable LLP David Goodman Global Non-

More information

With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation?

With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation? With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation? The General Data Protection Regulation The GDPR applies to all organizations

More information

The GDPR enforcement deadline is looming are you ready?

The GDPR enforcement deadline is looming are you ready? Link to Article The GDPR enforcement deadline is looming are you ready? 1 Compliance Is this relevant to the Wealth Management community is Asia? It is relevant to your business if you have an establishment

More information

EU GENERAL DATA PROTECTION REGULATION

EU GENERAL DATA PROTECTION REGULATION EU GENERAL DATA PROTECTION REGULATION GENERAL INFORMATION DOCUMENT This resource aims to provide a general factsheet to Asia Pacific Privacy Authorities (APPA) members, in order to understand the basic

More information

Paul Jordan Thursday 12 October,

Paul Jordan Thursday 12 October, GDPR Readiness: Role of the DPO OXS 17 Brussels Paul Jordan Thursday 12 October, 2017 Overview General DPO requirements under the GDPR: legitimacy of the DPO role International Research findings in Data

More information

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law.

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law. Buzescu Ca>Romanian Business Law>Romanian Data Protection Laws 12. ROMANIAN DATA PROTECTION LEGAL REGIME Updated October 2018 The relevant Romanian data protection laws are: European Regulation no. 679

More information

December 28, 2018, New Delhi, INDIA

December 28, 2018, New Delhi, INDIA LexArticle December 28, 2018, New Delhi, INDIA GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW If you have questions or would like additional

More information

SAP and SAP Ariba Solution Support for GDPR Compliance

SAP and SAP Ariba Solution Support for GDPR Compliance Frequently Asked Questions EXTERNAL The General Data Protection Regulation (GDPR) SAP Ariba Source-to-Settle Solutions SAP and SAP Ariba Solution Support for GDPR Compliance The European Union s General

More information

NEWSFLASH GDPR N 10 - New Data Protection Obligations

NEWSFLASH GDPR N 10 - New Data Protection Obligations GDPR N 10 - July 2017 NEWSFLASH GDPR N 10 - New Data Protection Obligations Following the adoption of the new EU General Data Protection Regulation (GDPR) on 27 April 2016, most organisations began to

More information

EU General Data Protection Regulation: are you ready?

EU General Data Protection Regulation: are you ready? EU General Data Protection Regulation: are you ready? Contents What you need to know about the new EU General Data Protection Regulation Is your organization ready for the EU General Data Protection Regulation?

More information

KYC & Data Protection: Friends or Foes?

KYC & Data Protection: Friends or Foes? KYC & Data Protection: Friends or Foes? How To Comply with KYC Requirements CREOBis March 28 th, 2017 0 Overview 1. Relationship between DP & KYC Regulations 2. Using Data Beyond KYC Purposes? 3. Supervisory

More information

Whitepaper. What are the changes regarding data protection. in the future. General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017

Whitepaper. What are the changes regarding data protection. in the future. General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017 Whitepaper What are the changes regarding data protection in the future General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017 Authors: Prof. Dr. Christoph Bauer, Dr Frank Eickmeier, Dr

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1 EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1 The EU General Data Protection Regulation (GDPR), which replaces Directive 95/46/EC

More information

GDPR Readiness: Role of the DPO

GDPR Readiness: Role of the DPO GDPR Readiness: Role of the DPO EDAA Summit 2017 London Paul Jordan Tuesday 28 November, 2017 Overview General DPO requirements under the GDPR: legitimacy of the DPO role International Research findings

More information

GENERAL DATA PROTECTION REGULATION REPORT

GENERAL DATA PROTECTION REGULATION REPORT GENERAL DATA PROTECTION REGULATION REPORT 2016 Report -General Data Protection Regulation BACKGROUND P.4 ECIJA SOLUTIONS P.15 MAIN DEVELOPMENTS P.7 FAQS P.16 MEASURES AND TERMS P.12 Privacy and Data Protection

More information

DATA PROTECTION OFFICER (DPO) Maria Maxim Partner Bucharest October 25, 2017

DATA PROTECTION OFFICER (DPO) Maria Maxim Partner Bucharest October 25, 2017 DATA PROTECTION OFFICER (DPO) Maria Maxim Partner Bucharest October 25, 2017 TOPICS GDPR overview Concept of the DPO Recruitment process Job description Liability Your to do s: GDPR Responsibility and

More information

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT WHAT GDPR MEANS FOR RECORDS MANAGEMENT Presented by: Sabrina Guenther Frigo Overview Background Basic Principles Scope Lawful Processing Data Subjects Rights Accountability & Governance Data Transfers

More information

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR General Data Protection Regulation Philippe Roggeband Business Development, Manager, GSSO EMEAR Why should you care? Data Protection, and compliance with the General Data Protection regulation, is NOT

More information

GENERAL DATA PROTECTION REGULATION Guidance Notes

GENERAL DATA PROTECTION REGULATION Guidance Notes GENERAL DATA PROTECTION REGULATION Guidance Notes What is the GDPR? Currently, the law on data protection requiring the handling of data which identifies people to be done in a fair way, is contained in

More information

What you need to know. about GDPR. as a Financial Broker. Sponsored by

What you need to know. about GDPR. as a Financial Broker. Sponsored by What you need to know about GDPR as a Financial Broker Dear Partner The regulatory and compliance environment is ever changing and the burden and requirements on financial services professionals continues

More information

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016 Dealing with the EU Data Protection Regulation in Practice William Long, Partner Sidley Austin LLP February 11, 2016 Do you need to comply? The Regulation will apply to a business processing personal data:

More information

European Union General Data Protection Regulation 25 th May 2018

European Union General Data Protection Regulation 25 th May 2018 European Union - General Data Protection Regulation External Frequently Asked Questions European Union General Data Protection Regulation 25 th May 2018 European Union General Data Protection Regulation

More information

EU General Data Protection Regulation: Are you ready?

EU General Data Protection Regulation: Are you ready? EU General Data Protection Regulation: Are you ready? Powered by Global Markets EY Knowledge Contents What do you need to know about the new EU General Data Protection Regulation? Are organisations ready

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

CNPD Training: Data Protection Basics

CNPD Training: Data Protection Basics CNPD Training: Data Protection Basics The obligations of controllers and processors Esch-sur-Alzette Mathilde Stenersen 7-8 February 2018 Legal service Outline 1. Introduction 2. Basic elements 3. The

More information

General Data Protection Regulation (GDPR) Business Guide

General Data Protection Regulation (GDPR) Business Guide General Data Protection Regulation (GDPR) Business Guide May 2018 LEGAL DISCLAIMER The information contained in this guide is for general guidance purposes only. It should not be taken for, nor is it intended

More information

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak PROFESSIONAL INDEPENDENT ADVISERS LTD DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Training Manual Data Protection Officer is Mike Bandurak GDPR introduction

More information

WHITE PAPER EU General Data Protection Regulation Compliance

WHITE PAPER EU General Data Protection Regulation Compliance WHITE PAPER EU General Data Protection Regulation Compliance Table of Contents 1. SAP is ready for GDPR 04 1.1. Data Protection Processes 04 1.2. Data Protection Thresholds 05 1.3. Technical & Organizational

More information

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018 GDPR: Are You Ready? Mapping the Road to GDPR Compliance March 2018 Agenda GDPR Overview Should you appoint a DPO? Accountability checklist/documentation required When is consent appropriate and how do

More information

Genera Data Protection Regulation and the Public Sector

Genera Data Protection Regulation and the Public Sector Genera Data Protection Regulation and the Public Sector Tuesday 30 May 2017 @mhclawyers Welcome Edward Gleeson Partner & Head of Public & Administrative Law Mason Hayes & Curran GDPR for Public Bodies

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey www.nascenta.com GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey Introduction GDPR Key Points GDPR/DPA Differences Start Up, Tech Business Professional Practice?

More information

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop.

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop. Webinar 1: Overview of Preparing for the T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop peter.blenkinsop@dbr.com Agenda Introduction (5 mins) Level setting: Brief overview of main provisions

More information

General Data Protection Regulation (GDPR) New regulation for the protection of data

General Data Protection Regulation (GDPR) New regulation for the protection of data General Data Protection Regulation (GDPR) New regulation for the protection of data Executive summary This manual has been developed by Retail Excellence in association with Grant Thornton to provide retailers

More information

General Data Protection Regulation Guide

General Data Protection Regulation Guide General Data Protection Regulation Guide TABLE OF CONTENTS Introduction 1 Scope 2 Legal Bases for Data Processing 3 Rights of Individuals 5 Accountability and Governance Mechanisms 7 Data Processor Obligations

More information

What do companies need to do?

What do companies need to do? Briefing GDPR The General Data Protection Regulation ( GDPR ) will come into effect on 25 May 2018. The GDPR will replace the existing data protection laws in all EU member states and is designed to result

More information

The Data Protection Regulation for Europe

The Data Protection Regulation for Europe The Data Protection Regulation for Europe Magnus Stenbeck, Karolinska Institutet Dept of Clinical Neuroscience and The Research Data Inquiry (U 2016:04) The data protection regulation in the EU Old system

More information

Getting ready for GDPR. A guide to General Data Protection Regulations

Getting ready for GDPR. A guide to General Data Protection Regulations Getting ready for GDPR A guide to General Data Protection Regulations The General Data Protection Regulation (GDPR) Wherever information is stored, individuals and organisations need to be mindful of the

More information

Summary of General Data Regulation & Actions. Nationwide Coverage.

Summary of General Data Regulation & Actions. Nationwide Coverage. Nationwide Coverage M Group Services Head Office Abel Smith House, Gunnels Wood Road, Stevenage, Hertfordshire SG1 2ST Tel: 01438 743 744 Morrison Utility Services Head Office Abel Smith House, Gunnels

More information

Summary of General Data Regulation & Actions. Nationwide Coverage.

Summary of General Data Regulation & Actions. Nationwide Coverage. Nationwide Coverage M Group Services Head Office Abel Smith House, Gunnels Wood Road, Stevenage, Hertfordshire SG1 2ST Tel: 01438 743 744 Morrison Utility Services Head Office Abel Smith House, Gunnels

More information

What is GDPR and Should You Care?

What is GDPR and Should You Care? What is GDPR and Should You Care? Ingram Micro Inc. 1 Overview of Privacy Climate & Concerns 2 2 Today We Live In A World Where Advertisers read key words in your Facebook posts and emails and decide what

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

A COMPANION DOCUMENT TO THE GDPR READINESS DECISION TREE QUESTIONS AND ANALYSIS. April 19, 2017

A COMPANION DOCUMENT TO THE GDPR READINESS DECISION TREE QUESTIONS AND ANALYSIS. April 19, 2017 A COMPANION DOCUMENT TO THE GDPR READINESS DECISION TREE QUESTIONS AND ANALYSIS April 19, 2017 The General Data Protection Regulation (GDPR) represents perhaps the most sweeping changes to the protection

More information

Vendor Agreements and the New EU GDPR Steps to Take Now

Vendor Agreements and the New EU GDPR Steps to Take Now Presenting a live 90-minute webinar with interactive Q&A Vendor Agreements and the New EU GDPR Steps to Take Now Complying With the EU General Data Protection and Privacy Regulation TUESDAY, JANUARY 30,

More information

Briefing No. 2 GDPR. 1 mccann fitzgerald

Briefing No. 2 GDPR. 1 mccann fitzgerald Briefing No. 2 GDPR This briefing was produced by the Institute of Directors in association with McCann FitzGerald for use in Ireland. McCann FitzGerald is one of Ireland s premier law firms, providing

More information

GDPR journey: from ready to compliant GDPR survey results

GDPR journey: from ready to compliant GDPR survey results GDPR journey: from ready to compliant GDPR survey results Readiness at a glance The General Data Protection Regulation (or GDPR ) took full effect on 25 May 2018. As a key data protection regulation,

More information

General Data Privacy Regulation: It s Coming Are You Ready?

General Data Privacy Regulation: It s Coming Are You Ready? General Data Privacy Regulation: It s Coming Are You Ready? Presenters Tristan North Worldwide ERC Government Affairs Adviser, Moderator William R. Tehan General Counsel, Graebel Companies, Inc. Hank A.

More information

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR) Customer Data Protection Temenos module for the General Data Protection Regulation (GDPR) Contents Glossary 03 GDPR Geographical Scope 03 GDPR implementation status 03 Overview of GDPR 03 Financial Institutions

More information

Agenda. What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance

Agenda. What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance Agenda What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance What is the GDPR? The General Data Protection Regulation(GDPR) is a European-wide regulation

More information

GDPR is coming in 108 days: Are you ready?

GDPR is coming in 108 days: Are you ready? Charles-Albert Helleputte Partner, Brussels GDPR is coming in 108 days: Are you ready? Diletta De Cicco Legal Consultant, Brussels 6 February 2018 +32 2 551 5982 chelleputte@mayerbrown.com +32 2 551 5974

More information

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities EU Data Protection Officer: Roles and responsibilities Robert Bond, CCEP Head of Data Protection and Cyber Security Law and DPO charlesrussellspeechlys.com Robert Bond Partner Robert Bond has over 36 years'

More information

A GDPR Primer For U.S.-Based Cos. Handling EU Data: Part 1

A GDPR Primer For U.S.-Based Cos. Handling EU Data: Part 1 Portfolio Media. Inc. 111 West 19 th Street, 5th Floor New York, NY 10011 www.law360.com Phone: +1 646 783 7100 Fax: +1 646 783 7161 customerservice@law360.com A GDPR Primer For U.S.-Based Cos. Handling

More information

GDPR Service Information Sheet

GDPR Service Information Sheet GDPR Service Information Sheet What is GDPR? General Data Protection Regulation (GDPR) - is a policy that comes into effect from the 25th May 2018. Any business that processes the personal data of EU individuals,

More information

GDPR for Charities. Tuesday 17 October 2017

GDPR for Charities. Tuesday 17 October 2017 GDPR for Charities Tuesday 17 October 2017 Welcome Edward Gleeson, Head of Charities GDPR for the Charity Sector Robert Haniver, Senior Associate Data protection reform General Data Protection Regulation

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP265 Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data Adopted on 11 April

More information

Accelerate Your Response to the EU General Data Protection Regulation (GDPR) with Oracle Cloud Applications

Accelerate Your Response to the EU General Data Protection Regulation (GDPR) with Oracle Cloud Applications Accelerate Your Response to the EU General Data Protection Regulation (GDPR) with Oracle Cloud Applications O R A C L E W H I T E P A P E R D E C E M B E R 2 0 1 7 Disclaimer The purpose of this document

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

WHAT DOES THE GDPR MEAN FOR HR PROFESSIONALS?

WHAT DOES THE GDPR MEAN FOR HR PROFESSIONALS? WHAT DOES THE GDPR MEAN FOR HR PROFESSIONALS? The General Data Protection Regualtion An introduction The General Data Protection Regulation comes into effect in mid-2018 and will introduce a number of

More information

The GDPR Are you ready?

The GDPR Are you ready? The GDPR Are you ready? kpmg.ie The GDPR - Overview The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) will come into force from 25th May 2018, replacing the existing data protection

More information

EU data protection reform

EU data protection reform EU data protection reform Background and insight A Whitepaper Executive summary The Irish Data Protection Acts 1988 and 2003 gave effect to the European Data Protection Directive 95/46/EC. The existing

More information

Data Protection (internal) Audit prior to May (In preparation for that date)

Data Protection (internal) Audit prior to May (In preparation for that date) Data Protection (internal) Audit prior to May 2018. (In preparation for that date) For employers without a dedicated data protection or compliance function, a Data Protection Audit can seem like an overwhelming

More information

Preparing Your Vendor Agreements for the General Data Protection Regulation

Preparing Your Vendor Agreements for the General Data Protection Regulation Preparing Your Vendor Agreements for the General Data Protection Regulation Oliver Yaros Partner - London +44 (0)203 130 3698 oyaros@mayerbrown.com Lei Shen Senior Associate - Chicago +1 312 701 8852 lshen@mayerbrown.com

More information

Breaking the myth How your marketing activities can benefit from the GDPR December 2017

Breaking the myth How your marketing activities can benefit from the GDPR December 2017 www.pwc.be Breaking the myth How your marketing activities can benefit from the GDPR December 2017 1. Introduction As opposed to a widespread belief, the GDPR aims to reinforce customers rights, whilst

More information

Achieving GDPR Compliance with Avature

Achieving GDPR Compliance with Avature Achieving GDPR Compliance with Avature What You Need to Know About GDPR The General Data Protection Regulation, or GDPR, is a regulation that was passed by the European Union in 2016 to update and replace

More information

#RSAC TEN PITFALLS TO AVOID IN GDPR

#RSAC TEN PITFALLS TO AVOID IN GDPR SESSION ID: SEM-M01 TEN PITFALLS TO AVOID IN GDPR Next Month 25 May 2018 > Protection of personal data in e-society Single legal basis for all 28 (27) Member States Regulation > no enabling legislation

More information

General Data Protection Regulation

General Data Protection Regulation General Data Protection Regulation Caroline Budde Vice President, Compliance, Global Privacy Officer Walgreens Boots Alliance Agenda Overview of global data protection The General Data Protection Regulation

More information

GDPR. Guidance on Employee Personal Data

GDPR. Guidance on Employee Personal Data GDPR Guidance on Employee Personal Data Introduction The General Data Protection Regulation (GDPR), due to come into force on 25 May 2018, will impose significant new burdens on organisations across Europe

More information

The GDPR: What does it mean for executive search?

The GDPR: What does it mean for executive search? The GDPR: What does it mean for executive search? At Invenias, we are committed to working in partnership with our customers to ensure a streamlined journey to compliance. Our customers benefit from data

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 17/EN WP264 rev.01 Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data Adopted on 11

More information

The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner,

The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner, The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner, Deloitte, Cyber Advisory Table of Contents Introduction

More information

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Legal02#67236978v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Notes: We recommend that any business looking to comply with the

More information

More information at cventconnect.com/europe/mobileapp

More information at cventconnect.com/europe/mobileapp Download and Login to the Cvent CONNECT Europe Mobile Event App Tap On Schedule Find Your Session Access Polls and Live Q&A More information at cventconnect.com/europe/mobileapp Cvent CONNECT Europe General

More information

General Data Protection Regulation - Explained

General Data Protection Regulation - Explained General Data Protection Regulation - Explained Bernard Cogan & Bobby Gould CUNA Mutual Group ACE Conference & AGM 2017 12 th May 13 3h May 2017 Copthorne Hotel (Birmingham) Are you familiar with GDPR Don't

More information

GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO

GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO 1 Consent Things you need to know about consent and the processing of employees data The EU General Data Protection Regulation

More information

IMPACT OF THE NEW GDPR DIRECTIVE ON OUTSOURCING ARRANGEMENTS

IMPACT OF THE NEW GDPR DIRECTIVE ON OUTSOURCING ARRANGEMENTS IMPACT OF THE NEW GDPR DIRECTIVE ON OUTSOURCING ARRANGEMENTS This Insight provides an overview of the changes, and impact the GDPR Directive presents to outsourcing arrangements. Furthermore, it provides

More information

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER ARRIVAL OF GDPR IN 2018 The European Union (EU) General Data Protection Regulation (GDPR), which takes effect in 2018, will bring changes

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Presenting a live 90-minute webinar with interactive Q&A Compliance With New EU GDPR: Steps Investment Funds, Banks, Advisers and Financial Intermediaries Should Take Now Revising Service Agreements and

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

closer look at Definitions The General Data Protection Regulation

closer look at Definitions The General Data Protection Regulation A closer look at Definitions The General Data Protection Regulation September 2017 V1 www.inforights.im Important This document is part of a series, produced purely for guidance, and does not constitute

More information

A guide to GDPR the effect on all UK organisations

A guide to GDPR the effect on all UK organisations A guide to GDPR the effect on all UK organisations Personal Data Penalties Consent Data Breach Notification GDPR Right to Object Data Portability Right to be Forgotten A white paper from Eazipay Ltd October

More information

Brace for Impact: Why the GDPR Should Remain at the Top of Directors Agendas

Brace for Impact: Why the GDPR Should Remain at the Top of Directors Agendas February 13, 2017 Brace for Impact: Why the GDPR Should Remain at the Top of Directors Agendas The ICSA Annual Conference 2017 Stronger Boards, Better Governance ExCel, London, 4 July, 2017, 11:30 AM Our

More information