What you need to know. about GDPR. as a Financial Broker. Sponsored by

Size: px
Start display at page:

Download "What you need to know. about GDPR. as a Financial Broker. Sponsored by"

Transcription

1 What you need to know about GDPR as a Financial Broker

2 Dear Partner The regulatory and compliance environment is ever changing and the burden and requirements on financial services professionals continues to increase. I am sure you ve heard of the General Data Protection Regulation ( GDPR ) which will change the way we all have to handle client data. Given the dramatic rise in the personal data held by companies, used to tailor and market their services and products to their customers, GDPR has been designed to reinforce an individual s right to take control of their own data and ensure companies use it appropriately. As a broker and introducer of financial products, along with all other UK businesses who hold client data, your legal obligations and responsibilities on how you collect, record and administrate customers data is changing and you need to be ready and prepared! Carl D Ammassa Group Managing Director - Business Finance Aldermore Bank PLC The implementation of GDPR is due to come into effect on 25th May 2018, therefore it s critical you understand what this means for your business and the responsibilities you have in working with each of your funders. Ultimately, given the sensitivity and potential fines for non-compliance and data breaches, if you are unable to categorically state to your funding partners that you re GDPR compliant your trading relationships may be suspended! There is a lot of preparation needed, so don t leave this until the last minute! Our guide aims to help you understand what you need to do by setting out the key points of the legislation, while outlining how you can start planning the areas you may need to consider alongside your funding partners. Thank you to the team at Locke Lord and Jo Davies for their help in producing this report. Joanne Davies Head of Asset & Consumer Finance Locke Lord (UK) LLP Carl D Ammassa Group Managing Director - Business Finance Aldermore Bank PLC

3 GDPR, what is it and when is it coming? This briefing is intended to inform you of your new obligations under the General Data Protection Regulation (GDPR) so that you can protect yourselves, but more importantly, so that you can ensure that the rights of individuals under the GDPR legislation are given priority. Data protection has become more important than ever before with the pending implementation in the UK from 25 May 2018 of the General Data Protection Regulation (GDPR). The government has confirmed that the UK s decision to leave the EU will not affect the implementation of the GDPR in this country. The GDPR is designed to reinforce an individual s right to take control of their own data. It lays down rules relating to the protection of natural persons with regard to the processing of personal data and the rules relating to the free movement of personal data. Within this guide, you ll find a number of useful hints to help you to assess the impact GDPR will have on your business. What you should do now plan! Compliance with the GDPR is likely to require organisation-wide changes for you to ensure that an individual s ( data subject s ) personal data is processed in compliance with the GDPR requirements. You need to be aware that these changes may require a significant amount of time to implement. Failure to do so could mean that you are left with new requirements to implement, without having set aside appropriate resources necessary to achieve compliance. Talk with your senior management, partners and team to understand what preparations and projects are in place to ensure that you will be GDPR compliant by the 25th May The new Principal of Accountability The new Principle of Accountability under the GDPR requires that you not only comply with the principles of data protection but that you are also able to actively demonstrate such compliance if asked to do so. The Information Commissioners Office (ICO) is the body responsible in the UK for ensuring compliance with data protection legislation and regulation. However it will work with other regulatory bodies, such as the Financial Conduct Authority (FCA), to ensure such compliance where necessary. If you are unable to print off, or locate your Data Operating Procedures and Processes, you will need to produce them so ensure that you take relevant actions now to rectify this. You must keep therefore keep full records to demonstrate your compliance with the GDPR.

4 Tougher penalties for breaches The GDPR introduces a number of important changes including greater investigative and enforcement powers for the ICO including the power to levy significant fines. A person, who has suffered material or non-material damage as a result of an infringement of the GDPR has a right to receive compensation from the person responsible for the damage they have suffered. It is important to note that failure to comply with the GDPR can also result in damaging adverse publicity. Increasingly, any wrong step in the area of data protection commonly attracts intense media scrutiny, regardless of whether any law has in fact been infringed. This can cause significant damage to the reputation of the business concerned and any connected business. This may prevent funders from wanting to deal with the organisation in the future and they may withdraw from their relationship with you. Customers may also look elsewhere if you have a bad reputation within your market sector. Check what information you currently deal with and whether it could be considered to be personal data. Personal data will not only apply if you are dealing with consumers it also applies to your business customers as well. What data is covered by GDPR? Personal data is covered by the GDPR, The GDPR defines personal data as: any information relating to an identified or identifiable natural person ( data subject ); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Personal Data includes: Personal details; Family and lifestyle details; Education and training; Medical details; Employment details; Financial details; Contractual details (for example, goods and services provided to a data subject) Genetic, biometric and health data; Online identifiers (IP addresses, cookies) Have you got drawn up guidelines with your funding partners that sets out your responsibilities at each stage of the customers journey and when your role could change from processor to controller? What is the difference between Processor and Controller and what are their responsibilities? Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

5 Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. When you first meet with a customer and they use a broker to find finance, at that point the broker will be in control of the personal data and therefore will be considered to be a controller. Where the broker passes that personal data over to a funder, the funder becomes a processor of the personal data when considering whether to accept the customer for finance. At the point the funder has accepted the customer, the funder will become the controller of that personal data. What are the rights of individuals? Individuals have certain rights under the GDPR including the right to: Information (this is the right to receive certain information on their request about the way their personal data is being collected and processed); Access their own personal data (including receiving a copy of any such data held on request); Correct personal data (to correct inaccurate personal data held by the data controller and to complete incomplete personal data held by the data controller); Erase personal data, also known as the right to be forgotten (data subjects have the right to request the erasure of the personal data in certain circumstances such as they are withdrawing their consent to its use) Restrict data processing (in certain circumstances such as the data subject contests the accuracy of such data). Object to data processing (for example for marketing purposes); Receive the transfer of their personal data to another data controller (known as data portability). Not be subject to automated decision-making (including profiling) Be notified of a data security breach (when a personal data breach is likely to result in a high risk to a data subject s rights, a data controller must notify the data subject of the security breach without undue delay). Check your current documentation to assess if you correctly state how you use a customer s personal data and if you can action the above requests e.g. the right to be forgotten. Individuals can also request from you confirmation as to: The purposes of the processing of their personal data; The categories of personal data concerned; The recipients or categories of recipient to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organisations; Where possible, the envisaged period for which the personal data will be stored or, if not possible, the criteria used to determine that period; The right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; The right to lodge a complaint with a supervisory authority; Where the personal data is not collected from the data subject, any available information as to its source; The existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

6 Are there any changes to my responsibilities? Yes, there are a number of changes to your responsibilities, which you will now have to demonstrate. You should carefully review your existing practices to ensure that you obtain proper consents from your individual customers and that you can evidence that the customer has fully understood how you will be using their personal data. This means you should use methods to collect consent which require a proactive activity by the customer (for example, ticking a blank box to indicate their consent rather than allowing for a pre-ticked box). Failing to un-tick a pre-ticked box will not constitute valid consent under the GDPR. 1. Consent The GDPR requires a very high standard of consent as we have set out above. You must be able to demonstrate when you are dealing with personal data that the individual owner of that personal data gave their informed, unambiguous and proactive consent to the processing and you will now bear the burden of proof that consent was validly obtained. The individual shall also have the right to withdraw their consent at any time, known as the right to be forgotten. The execution of a contract or the provision of a service cannot be conditional on consent to processing or use of data that is not necessary for the execution of the contract or the provision of the service. You must ensure that an individual can withdraw their consent at any time. It must be as easy for them to withdraw their consent as it is to give it. You should liaise with your funders or other brokers to ensure that procedures are in place to effect this successfully. Identify where you are handling personal data and keep documented evidence that you have considered the risk connected to the handling of this personal data and then put in place controls to address these risks. For example, use encrypted s to pass personal data to your funder and limit the number of people within your business who can access such data. 2. Risk based approach The GDPR adopts a risk-based approach to compliance, under which you bear responsibility for assessing the degree of risk that your processing activities pose to individuals. You may be asked to prove that you have carried out such assessments and present evidence of this to the ICO. Ensure your policy and procedure documents reflect the fact that you are aware of these requirements and that they are being complied with. 3. Privacy by design and by default and privacy impact assessments When you create new products, or attempt to implement existing products in a different way (i.e. offering them to a new audience) you are required to consider the personal data involved in the transaction from the outset and ensure that the new product effectively protects such personal data by its very design. For example, by only collecting relevant personal data that is needed to complete the task. There are also requirements for you to perform mandatory privacy impact assessments (PIAs) before carrying out any processing that uses new technologies that are likely to result in a high risk to data subjects.

7 Other things that you need to bear in mind 1. Registrations Instead of registering with the ICO, the GDPR requires you to maintain detailed documentation recording your processing activities and specifies the information this record must contain. Have you got records of the processing activities you carry out and the purpose you are doing this for? Do your records contain what the GDPR requires them to contain? 2. Strict data breach notification rules The GDPR requires you to notify the ICO of all data breaches without undue delay and where feasible within 72 hours of the breach unless the breach is unlikely to result in a risk to the individuals. If you cannot notify the ICO within this required period, you will have to justify the delay to them by way of a reasoned justification. If the breach is likely to result in high risk to the individuals, the GDPR, requires you to inform those individuals without undue delay, unless an exception set out in the GDPR applies. 3. The right to erasure ( right be forgotten ) The data subject has a right to ask you to delete their personal data completely. Make sure you have effective procedures in place to comply with these time limits and for assessing and escalating breaches correctly. You should consider what systems your customers details are recorded on, how they have been shared (i.e. ) and whether you can delete all of their records if required (wiping personal data is not always straightforward!). In addition, you will need work with your funding partners, to ensure that they can do the same when the customer makes such a request. 4. The right to data portability Data subjects have a new right to obtain a copy of their personal data from you (if you are the controller) in a commonly used and machine-readable format, They also have the right to require you to transmit their data to another controller (for example, an online service provider) in a commonly used and machine-readable format. In exercising their right, the data subject can request the information be transmitted directly from one controller to another, where technically feasible. You should consider how you will give effect to these rights. You should consider how you can pull off their information and the formats which you can share that information on to create a compliant template for the customer to receive. 5. Data subject access requests You must reply within one month from the date of receipt of the request and provide more information than was required previously. You should plan and establish a process of how you will respond to an individual s data subject access request within the new time scale and how you will provide the information required.

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak PROFESSIONAL INDEPENDENT ADVISERS LTD DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Training Manual Data Protection Officer is Mike Bandurak GDPR introduction

More information

Brasenose College Data Protection Policy Statement v1.2

Brasenose College Data Protection Policy Statement v1.2 Brasenose College Data Protection Policy Statement v1.2 1. Introduction All documents referred to in this policy can be found online at the address below: https://www.bnc.ox.ac.uk/privacypolicies 1.1 Background

More information

WEBSITE PRIVACY POLICY. Park Retail is a subsidiary of Park Group plc. (registered in England with company number ) ( Park Group ).

WEBSITE PRIVACY POLICY. Park Retail is a subsidiary of Park Group plc. (registered in England with company number ) ( Park Group ). WEBSITE PRIVACY POLICY INTRODUCTION This website is owned and operated by Park Retail Ltd (registered in England with company number 402152) ("Park Retail"). Park Retail is a subsidiary of Park Group plc.

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

WEBSITE PRIVACY POLICY. Park Retail is a subsidiary of Park Group plc. (registered in England with company number ) ( Park Group ).

WEBSITE PRIVACY POLICY. Park Retail is a subsidiary of Park Group plc. (registered in England with company number ) ( Park Group ). WEBSITE PRIVACY POLICY INTRODUCTION This website is owned and operated by Park Retail Ltd (registered in England with company number 402152) and whose office in Ireland is at Ground Floor Unit 11, Sandyford

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

GDPR: What Every MSP Needs to Know

GDPR: What Every MSP Needs to Know Robert J. Scott GDPR: What Every MSP Needs to Know Speaker Robert J. Scott Agenda Purpose GDPR Intent & Obligations Applicability Subject-matter and objectives Material scope Territorial scope New Rights

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

Privacy Policy. To invest significant resources in order to respect your rights in connection with Personal Data about you:

Privacy Policy. To invest significant resources in order to respect your rights in connection with Personal Data about you: Privacy Policy Last updated: May 17, 2018 This is the privacy policy (the Policy ) of the website www.experitest.com (the "Website") operated by Experitest Ltd., of 10 HaGavish St, 4250708 Poleg, Israel

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

GDPR factsheet Key provisions and steps for compliance

GDPR factsheet Key provisions and steps for compliance GDPR factsheet Key provisions and steps for compliance Organisations hold vast amounts of personal data relating to customers, employees, and suppliers as well as within marketing databases. Compliance

More information

December 28, 2018, New Delhi, INDIA

December 28, 2018, New Delhi, INDIA LexArticle December 28, 2018, New Delhi, INDIA GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW If you have questions or would like additional

More information

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company )

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company ) RSD Technology Limited - Data protection policy: Introduction Company Name: Document DP3 Topic: RSD Technology Limited ( the Company ) Data Protection Policy Data protection Date: 25 th May 2018 Version:

More information

PERSONAL DATA REQUEST RESPONSE TEMPLATE GUIDANCE

PERSONAL DATA REQUEST RESPONSE TEMPLATE GUIDANCE PERSONAL DATA REQUEST RESPONSE TEMPLATE GUIDANCE PERSONAL DATA REQUEST RESPONSE TEMPLATE GUIDANCE 1. INTRODUCTION This guidance document is designed to accompany the personal data request response template

More information

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR Factsheet - Key Provisions and steps for Compliance GDPR Factsheet - Key Provisions and steps for Compliance Organisations in the Leisure & Hospitality industry hold vast amounts of personal data relating to customers, employees, and suppliers as well as

More information

Privacy Policy 2018 VERSION 1.0

Privacy Policy 2018 VERSION 1.0 Introduction 1.1 We are committed to safeguarding the privacy of our website visitors and service users. 1.2 This policy applies where we are acting as a data controller with respect to the personal data

More information

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop.

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop. Webinar 1: Overview of Preparing for the T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop peter.blenkinsop@dbr.com Agenda Introduction (5 mins) Level setting: Brief overview of main provisions

More information

The Mortgage Broker s Guide to GDPR. The data privacy laws are changing - get prepared!

The Mortgage Broker s Guide to GDPR. The data privacy laws are changing - get prepared! The Mortgage Broker s Guide to GDPR. The data privacy laws are changing - get prepared! An introduction to the GDPR Hopefully by now you have heard of the General Data Protection Regulation (GDPR) which

More information

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT WHAT GDPR MEANS FOR RECORDS MANAGEMENT Presented by: Sabrina Guenther Frigo Overview Background Basic Principles Scope Lawful Processing Data Subjects Rights Accountability & Governance Data Transfers

More information

What does the GDPR mean for recruitment?

What does the GDPR mean for recruitment? What does the GDPR mean for recruitment? www.recruitment.software Contents 04 What is GDPR? In May 2018, Europe s new data protection rules will come into effect. 04 Who is responsible? 05 What are the

More information

Nissa Consultancy Ltd Data Protection Policy

Nissa Consultancy Ltd Data Protection Policy Nissa Consultancy Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments (DPIA)

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Operational Owner: Executive Owner: James Newby Data Protection Officer Sarah Litchfield Senior Information Risk Officer Effective date: 25 th May 2018 Review date: May 2021 Related

More information

DATA PROTECTION NOTICE

DATA PROTECTION NOTICE DATA PROTECTION NOTICE 1. YOUR PERSONAL DATA COLLECTED & OBTAINED This Data Protection Notice ("Notice") sets out the basis on which It Works! Marketing International UC ( It Works!", we or us ) of 45-46

More information

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR General Data Protection Regulation Philippe Roggeband Business Development, Manager, GSSO EMEAR Why should you care? Data Protection, and compliance with the General Data Protection regulation, is NOT

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

Preparing for the GDPR

Preparing for the GDPR Preparing for the GDPR Note: These slides and the accompanying presentation contain a general summary and are not legal advice. Niall Rooney 03/11/2017 (1) Data Protection The Right to Data Protection

More information

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Legal02#67236978v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Notes: We recommend that any business looking to comply with the

More information

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 1 PURPOSE OF THIS DOCUMENT 2 This document is to be used as a guide for advertisers on how they should work with their agencies,

More information

GENERAL DATA PROTECTION REGULATION Guidance Notes

GENERAL DATA PROTECTION REGULATION Guidance Notes GENERAL DATA PROTECTION REGULATION Guidance Notes What is the GDPR? Currently, the law on data protection requiring the handling of data which identifies people to be done in a fair way, is contained in

More information

Xerox Privacy Notice: Rights of data subjects pursuant to the General Data Protection Regulation

Xerox Privacy Notice: Rights of data subjects pursuant to the General Data Protection Regulation Xerox Privacy Notice: Rights of data subjects pursuant to the General Data Protection Regulation EU Regulation 2016/679 (known as the General Data Protection Regulation, hereinafter referred to as GDPR

More information

The Galway Clinic (GC) has implemented this document to demonstrate its commitment to the

The Galway Clinic (GC) has implemented this document to demonstrate its commitment to the Galway Clinic Recruitment Privacy Notice 1. Introduction The Galway Clinic (GC) has implemented this document to demonstrate its commitment to the protection of your personal data. We recognises that protecting

More information

a) Account data is data gathered directly from you or your employer for the purposes of entering into a contract for the services we offer

a) Account data is data gathered directly from you or your employer for the purposes of entering into a contract for the services we offer Care England Privacy Policy Last updated: 23 May 2018 Definitions a) Account data is data gathered directly from you or your employer for the purposes of entering into a contract for the services we offer

More information

The General Data Protection Regulation in health & social care. 6 October 2016 Leeds

The General Data Protection Regulation in health & social care. 6 October 2016 Leeds The General Data Protection Regulation in health & social care 6 October 2016 Leeds Session outline 09.05am: Roadmap of the GDPR 10.15am: Coffee break 10.30: GDPR impact: Streetview Employment Rights of

More information

EU GENERAL DATA PROTECTION REGULATION

EU GENERAL DATA PROTECTION REGULATION EU GENERAL DATA PROTECTION REGULATION GENERAL INFORMATION DOCUMENT This resource aims to provide a general factsheet to Asia Pacific Privacy Authorities (APPA) members, in order to understand the basic

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1.

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1. Company Name: Document DP3 Topic: Skills Direct Ltd ( the Company ) Data Protection Policy Data protection Date: 21 st May 2018 Version: Version 1 Contents Introduction Definitions Data processing under

More information

Nuijamiestentie 7, Helsinki

Nuijamiestentie 7, Helsinki General Name of the registry Controller Data Protection Officer Purpose of processing Legal basis of processing This privacy notice presents the information about this data register to the data subjects

More information

Introduction to the General Data Protection Regulation (GDPR)

Introduction to the General Data Protection Regulation (GDPR) Introduction to the General Data Protection Regulation (GDPR) #CIPR / @CIPR_UK This guide is worth 5 CPD points Introduction to the General Data Protection Regulation (GDPR) / 2 Contents 1 Introduction

More information

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR) Customer Data Protection Temenos module for the General Data Protection Regulation (GDPR) Contents Glossary 03 GDPR Geographical Scope 03 GDPR implementation status 03 Overview of GDPR 03 Financial Institutions

More information

Whitepaper. What are the changes regarding data protection. in the future. General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017

Whitepaper. What are the changes regarding data protection. in the future. General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017 Whitepaper What are the changes regarding data protection in the future General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017 Authors: Prof. Dr. Christoph Bauer, Dr Frank Eickmeier, Dr

More information

VITROLIFE S PRIVACY POLICY

VITROLIFE S PRIVACY POLICY VITROLIFE S PRIVACY POLICY Summary and introduction Vitrolife Sweden AB ( Vitrolife or we ) cares about your privacy. Therefore, Vitrolife always strives to protect your personal data in the best possible

More information

Getting ready for GDPR. A guide to General Data Protection Regulations

Getting ready for GDPR. A guide to General Data Protection Regulations Getting ready for GDPR A guide to General Data Protection Regulations The General Data Protection Regulation (GDPR) Wherever information is stored, individuals and organisations need to be mindful of the

More information

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

THE COMPETITION AND CONSUMER PROTECTION COMMISSION JOB APPLICANT PRIVACY NOTICE 1. INTRODUCTION... 2

THE COMPETITION AND CONSUMER PROTECTION COMMISSION JOB APPLICANT PRIVACY NOTICE 1. INTRODUCTION... 2 THE COMPETITION AND CONSUMER PROTECTION COMMISSION JOB APPLICANT PRIVACY NOTICE CONTENT 1. INTRODUCTION... 2 2. IDENTITY OF THE CONTROLLER OF PERSONAL INFORMATION... 2 3. CONTACT DETAILS OF THE DATA PROTECTION

More information

Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes

Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes 1 INTRODUCTION The General Data Protection Regulation (GDPR) comes into force in all EU Member States on 25.

More information

GDPR General Data Protection Regulation

GDPR General Data Protection Regulation GDPR General Data Protection Regulation Compliance Information Guide - May 2018 About this document Ticket Arena & Event Genius Disclaimer DISCLAIMER: This is a brief presentation for information purposes

More information

The (Scheme) Actuary as a Data Controller

The (Scheme) Actuary as a Data Controller The (Scheme) Actuary as a Data Controller Keith Webster and Ian Stevens Partners, CMS Cameron McKenna LLP June 2014 Discussion Areas New IFOA guidance Data Protection Act refresher Compliance obligations

More information

European Union General Data Protection Regulation 25 th May 2018

European Union General Data Protection Regulation 25 th May 2018 European Union - General Data Protection Regulation External Frequently Asked Questions European Union General Data Protection Regulation 25 th May 2018 European Union General Data Protection Regulation

More information

General Data Privacy Regulation: It s Coming Are You Ready?

General Data Privacy Regulation: It s Coming Are You Ready? General Data Privacy Regulation: It s Coming Are You Ready? Presenters Tristan North Worldwide ERC Government Affairs Adviser, Moderator William R. Tehan General Counsel, Graebel Companies, Inc. Hank A.

More information

Privacy notice Corporate customer

Privacy notice Corporate customer Background The purpose of this information is to provide information in a clear and transparent manner of s processing of Personal Data relating to you in your capacity as contact person or other business

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) The EU General Data Protection Regulation (GDPR) What is the GDPR? The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) was adopted on 27 April,

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk Session 1 Asset Management and Risk Control Forum GDPR Threat or Opportunity? BVRLA Asset Management & Risk Control Forum 19 April 2018 Introduction Personal data is an invaluable asset and many organisations

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

GDPR-CERTIFIED ASSURANCE REPORT BASED PROCESSING ACTIVITIES

GDPR-CERTIFIED ASSURANCE REPORT BASED PROCESSING ACTIVITIES GDPR-CERTIFIED ASSURANCE REPORT BASED PROCESSING ACTIVITIES CERTIFICATION CRITERIA Working draft for public consultation - 29 May 2018 Abstract Document to the attention of organizations that want to obtain

More information

Personal data: By Personal data we understand all information about identified or identifiable natural ( data subject ) according to GDPR

Personal data: By Personal data we understand all information about identified or identifiable natural ( data subject ) according to GDPR PRINCIPLES OF PERSONAL DATA PROTECTION In these Principles of Personal Data Protection we inform the subjects of data whose personal data we process about all our activities regarding processing and principles

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY In Zagreb, 25 May 2018 Contents: 1. DEFINITIONS 2. GENERAL PROVISIONS 3. DATA PROTECTION CONTROLLER 4. PRINCIPLES OF DATA PROCESSING 5. LAWFULNESS OF DATA PROCESSING 6. DATA THAT

More information

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie Get ready A Guide to the General Data Protection Regulation (GDPR) elavon.ie The General Data Protection Regulation (GDPR) will regulate the privacy and handling of the personal data of individuals in

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

GDPR POLICY. This policy complies with the requirements set out in the GDPR, which will come into effect on

GDPR POLICY. This policy complies with the requirements set out in the GDPR, which will come into effect on GDPR POLICY Sponsors Statement All The Bishop of Winchester Academy policies exist to support the Sponsors vision, Christian ethos and values that are embedded in the day-to-day and long term running of

More information

Search Consultancy Limited Privacy Notice

Search Consultancy Limited Privacy Notice Search Consultancy Limited Privacy Notice Search Consultancy Limited and Search Consultancy Group Limited (hereinafter the Company ) is a recruitment business which provides work-finding services to its

More information

Data subject access policy

Data subject access policy Data subject access policy Introduction 1. This is our Data subject access requests policy. 2. We are the professional regulator for nurses and midwives in the UK. Our principal functions include setting

More information

Privacy Notice. Stanton Chase Bucharest

Privacy Notice. Stanton Chase Bucharest Privacy Notice Stanton Chase Bucharest The principles described in this Privacy Notice document are handled in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council

More information

GDPR is coming in 108 days: Are you ready?

GDPR is coming in 108 days: Are you ready? Charles-Albert Helleputte Partner, Brussels GDPR is coming in 108 days: Are you ready? Diletta De Cicco Legal Consultant, Brussels 6 February 2018 +32 2 551 5982 chelleputte@mayerbrown.com +32 2 551 5974

More information

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond InsideNGO's 2017 Annual Conference Washington, DC July 20, 2017 Shannon Yavorsky Partner, Venable LLP David Goodman Global Non-

More information

A summary of the implications of the General Data Protection Regulations (GDPR)

A summary of the implications of the General Data Protection Regulations (GDPR) Introduction A summary of the implications of the General Data Protection Regulations (GDPR) 1. The General Data Protection Regulation (GDPR) will apply in the UK from 25 May 2018. Various implications

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd

Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd At RSL group we are very aware of the importance of managing the personal data that we hold, whether that is from a customer, a supplier

More information

Mature Accountants Limited ( MA ) are committed to protecting and respecting your privacy.

Mature Accountants Limited ( MA ) are committed to protecting and respecting your privacy. Mature Accountants Data Privacy as of May 2018 Mature Accountants Limited ( MA ) are committed to protecting and respecting your privacy. This notice together with our Website Terms of Use and any other

More information

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018 GDPR: Are You Ready? Mapping the Road to GDPR Compliance March 2018 Agenda GDPR Overview Should you appoint a DPO? Accountability checklist/documentation required When is consent appropriate and how do

More information

GENERAL DATA PROTECTION REGULATION.

GENERAL DATA PROTECTION REGULATION. For the use of mortgage intermediaries and other professionals only. GENERAL DATA HALIFAX INTERMEDIARIES KEY CHANGES GUIDE MAY 2018 REGULATION >SELECT A TILE FOR MORE INFORMATION WHAT IS THE GDPR? KEY

More information

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data OPTIN checklist OVERVIEW 1 GDPR Checklist This checklist sets out activities you will need to consider and act on by the compliance deadline of 25th May 2018. Use this to help you identify what support

More information

University for the Creative Arts Application Declaration. Data Protection Privacy Notice

University for the Creative Arts Application Declaration. Data Protection Privacy Notice University for the Creative Arts Application Declaration Data Protection Privacy Notice The University for the Creative Arts takes its obligations with regard to data protection seriously. As such, we

More information

Documenting data processing: The EDPS guide to ensuring accountability

Documenting data processing: The EDPS guide to ensuring accountability Documenting data processing: The EDPS guide to ensuring accountability Accountability on the ground Unlawful data processing can have serious implications for the lives and rights of the individuals whose

More information

The General Data Protection Regulation and the UK Data Protection Act 2018 DATA PROTECTION NOTICE

The General Data Protection Regulation and the UK Data Protection Act 2018 DATA PROTECTION NOTICE The General Data Protection Regulation and the UK Data Protection Act 2018 SCOPE DATA PROTECTION NOTICE This notice is for all candidates for, and Freemasons of, the Province of Gloucestershire (the Province)

More information

CELESTYAL CRUISES LIMITED SUBJECT ACCESS REQUEST POLICY

CELESTYAL CRUISES LIMITED SUBJECT ACCESS REQUEST POLICY CELESTYAL CRUISES LIMITED SUBJECT ACCESS REQUEST POLICY 1 Policy Statement The rights of data subjects to access personal data that Celestyal Cruises Limited ( the Company ) holds about them. This policy

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

Data Protection (internal) Audit prior to May (In preparation for that date)

Data Protection (internal) Audit prior to May (In preparation for that date) Data Protection (internal) Audit prior to May 2018. (In preparation for that date) For employers without a dedicated data protection or compliance function, a Data Protection Audit can seem like an overwhelming

More information

Privacy Policy & Data Protection

Privacy Policy & Data Protection Introduction Hewett Recruitment are committed to protecting the privacy or our clients, candidates and individuals who access our services and website. This policy applies where we are acting as data controller

More information

General Data Protection Regulation. What should community energy organisations be doing to prepare?

General Data Protection Regulation. What should community energy organisations be doing to prepare? General Data Protection Regulation What should community energy organisations be doing to prepare? The implementation date of 25 May 2018 for the General Data Protection Regulation (GDPR) is fast approaching.

More information

Brexit and the Future of Data Protection

Brexit and the Future of Data Protection Brexit and the Future of Data Protection Max Todd Information Compliance Team, Council Secretariat Tuesday 27 September 2016 General Data Protection Regulation (GDPR) Applies throughout EU from 25 May

More information

A guide to GDPR the effect on all UK organisations

A guide to GDPR the effect on all UK organisations A guide to GDPR the effect on all UK organisations Personal Data Penalties Consent Data Breach Notification GDPR Right to Object Data Portability Right to be Forgotten A white paper from Eazipay Ltd October

More information

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make. What is the purpose of this document? NORTHERN IRELAND SCREEN COMMISSION (Company Number NI031997) whose registered office is at 3 rd Floor Alfred House, 21 Alfred Street, Belfast, BT2 8ED is committed

More information

The ICT Service:

The ICT Service: GDPR for schools 1 Intro and aims The ICT Service: support@theictservice.org.uk, 0300 300 00 00 Cambridgeshire County Council: Information and Records Team. Data.protection@cambridgeshire.gov.uk 01223

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information