Preparing for the General Data Protection Regulation - inside an organisation

Size: px
Start display at page:

Download "Preparing for the General Data Protection Regulation - inside an organisation"

Transcription

1 Preparing for the General Data Protection Regulation - inside an organisation Version: V2.0 Date: 25/05/2017 Jackie Megahey GfK UK Director, Information Security &Data Protection GfK Regional Research & Quality Director, UK, Nordics & Baltics 1

2 12 Steps to take now In today s session I will be taking you through the ICOs guidance Preparing for the General Data Protection Regulation (GDPR) and the 12 steps to take now I will also show some examples of how this is being managed / implemented within GfK All other suggestions / examples welcome! 2

3 Step 1. Awareness ICO Identify decision makers and key people and make sure they are aware of the law change They need to appreciate impact and identify areas that could cause compliance problems Start by looking at your organisation s risk register Consider any significant resource implications Take time to lead in with a clear awareness campaign Last minute compliance will be difficult! 3

4 Resources / workstreams Complexity and Volume Project Workstreams Intelligence Service Audit & Governance Application Changes >2mio Panelists 15K Staff <200K Clients/Others 50K Databases unstructured/analog data ~200 Global BA/EA ~800 Local apps Product Impact >100 products 4

5 Awareness at GfK Started in the UK in 2016 with Compliance Training and Awareness for all staff Tailored training specific to each audience Researchers Shared services HR, IT, Finance, etc Point of Sales Mystery Shopping Legal Operational, etc Introduced GDPR into induction training for all new staff GfK Group Privacy module soon to be available on our online training platform Security training module developed alongside privacy Ongoing. 5

6 Making the message accessible SHOW SECURITY VIDEO 6

7 Making the message accessible Multiple channels to get the message across and raise awareness Intranet, Videos, e-news. Appointment of GDPR Project Manager 7

8 Step 2. Information you hold ICO Document what personal data you hold, where it came from and who you share it with Organise an information audit across the organisation Take into account employee, participant, panellist, client and supplier data The GDPR updates rights for a networked world If you have inaccurate personal data and have shared this with another organisation, you will have to tell the other organisation that the data is inaccurate What, where, who Document it Helps to comply with accountability principle Demonstrates that you have effective policies and procedures in place 8

9 Data flow diagrams may help.. 9

10 .. Or be quite scary!! 10

11 Information gathering questionnaire Started assessment of some 700+ Applications holding personal data by way of an Online Questionnaire sent out to application owners / users Location of App PII categories / Sensitive PII Other data leading to identity Data Subject Details Ownership, Access, Transfer No of people in data set Storage, back-up, Access Deletion Correction Export Consent Reporting Privacy notices Privacy by design Interaction with other apps 11

12 Step 3. Communicating privacy information ICO Review current privacy notices and put a plan in place to implement changes (if necessary) Survey invitation Online privacy notices T&Cs with your panel Thank you leaflets Information for qualitative groups Review what additional information you need to give in these notices. For example, explaining your legal basis for processing the data, your retention periods, and individual s right to complain to the ICO A challenge for telephone surveys! 12

13 Use concise, easy to understand and clear language Always a challenge when collecting information in a very complicated way some examples 13

14 Step 4. Individual s rights ICO Check, where necessary, procedures cover all rights: Subject access To have inaccuracies corrected To have information erased To prevent direct marketing To prevent automated decision-making and profiling Data portability Would your systems help you to locate and delete data? Who will make the decisions about deletion? Data portability provide the data electronically and in a commonly used format, can you do this? 14

15 Updating policies and publishing them Document policies, to meet the requirement of accountability 15

16 Step 5. Subject access request ICO Do your procedures meet the new timescales for providing information Respond within 1 month, rather than 40 days In most cases there can be no charges Manifestly unfounded or excessive requests can be charged or refused If you want to refuse a request, have policies and procedures in place to demonstrate why the request meets these criteria Additional information to provide: Data retention periods The right to have inaccurate data corrected What are the logistical impacts for your organisation of a large volume of requests? Do a cost/benefit analysis to providing online access for individuals to their data 16

17 Ways of publishing the data - all sources to be updated Published policy statements Interactive pdf with links to policy statements Direct links to statements on website 17

18 Step 6. Legal basis for processing personal data ICO Look at all types of data processing you carry out, identify the legal basis of doing so and document it Not just participant data, but employee, client and supplier personal data Have you thought of the practical implications of stronger rights of individuals to have their data deleted, when you use consent as your legal basis for processing Explain your legal basis in privacy notices and subject access requests, alongside information on data retention; confirm that individuals have a right to complain to the ICO Information to be provided in a concise, easy to understand and clear language 18

19 At GfK we are. Reviewing T&Cs and MSA s to ensure the data protection clauses reflect the requirements of the GDPR Consider both new T&Cs/MSAs and adding a variation to existing T&Cs/MSAs Working with Procurement to implement additional schedule in Standard Agency Terms to include an Information Security Schedule 19

20 Step 7. Consent ICO Review how you are seeking, obtaining and recording consent Prominent, concise, separate from other terms and conditions, and easy to understand Confirm the name of your organisation and any third parties, why you want the data, what you will do with it, and the right to withdraw consent Keep records to evidence consent who consented, when, how, and what they were told. Keep consents under review and refresh them if anything changes. Build regular consent reviews into your business processes 20

21 EXAMPLES What methods can you use to obtain consent? ICO signing a consent statement on a paper form ticking an opt-in box on paper or electronically clicking an opt-in button or link online selecting from equally prominent yes/no options choosing technical settings or preference dashboard settings responding to an requesting consent answering yes to a clear oral consent request volunteering optional information for a specific purpose eg filling optional fields in a form (combined with just-in-time notices) or dropping a business card into a box 21

22 Explicit consent ICO You cannot rely on silence, inactivity, pre-ticked boxes, opt-out boxes, default settings or a blanket acceptance of your terms and conditions All consent must involve a specific, informed and unambiguous indication of the individual s wishes. The key difference is likely to be that explicit consent must be affirmed in a clear statement (whether oral or written). 22

23 Step 8. Children ICO Put in place systems to verify individuals ages and gather parental or guardian consent Special protection for children s personal data, particularly for commercial internet services such as social networking Consent has to be verifiable Privacy notice written in a language that children can understand Consider connecting to CEOPS They offer advise in age appropriate language to children on how to stay safe online 23

24 Step 9. Data breaches ICO Have the right procedures in place to detect, report and investigate a personal data breach Reporting to the ICO those breaches where an individual is likely to suffer some form of damage, such as identity theft or confidentiality breach Reporting to the individual, for instance, if it might lead to financial loss for them Failure to report could result in a fine, as well as a fine for the breach itself 24

25 Incident Reporting External / internal theft; Misappropriation of company property / intellectual property Inadvertent, accidental or intended illegal disclosure of information Breach of confidentiality Information Security / Data Protection Director Quality Associate Director IT, Finance, HR, Legal, Police, Client, ICO, Data Subject Confidential whistleblowing 25

26 Step 10. Data protection by design and privacy impact assessment ICO Familiarize yourself with the guidance form the ICO on Privacy Impact Assessments (PIAs) Can link to other organisational processes such as risk management and project management Who will do it Who else needs to be involved Run centrally or locally? Privacy by design and data minimisation an express legal requirement Always consider a PIA for high risk situation, e.g., new technology/application 26

27 11. Data Protection Officers ICO Designate a data protection officer Where does this sit within your organisation s structure and governance Can be an internal or external advisor Takes proper responsibility for your organisation s data protection compliance and has the knowledge, support and authority to do so effectively 27

28 Legal and compliance team Identifying the right person in each country / region to act as the Data Protection Officer 28

29 Step 12. International ICO For international organisations, you should determine which data protection supervisory authority you come under Traditional headquarters (branches model), this is easy to determine More complex if multi-site companies where decisions about different processing activities are taken in different place Helpful to map out where you organisation makes it most significant decisions about data processing May help to determine your main establishment and therefore your lead supervisory authority 29

30 A final BIG step to take around the GfK World 30

31 GDPR time boxing schedule needs to be validated 5. Schedule with Milestones Define key milestones and develop the project schedule further from the Project Charter to determine timing, effort and duration required to complete the project. Milestones Risk Mitigation Target Setting delivered 2017 Risk Mitigation Plan delivered Audit completed External Reality Check GDPR is Law Project Ramp Up Intelligence Audit Service Legal/Economic Risks Master GFK Duties Develop standard contracts Data Landscape Definition Risk Assessment Global Applications Organization Roles & Responsibilities Master IT Architecture Framework Definition Risk Assessment for Regional Application/Data Roll out Changes Contracts Roll out Changes Organization Domain Specific Implementation Streams Application Changes Early Starters Definition +Changes in applications 31

32 Thank you Visit the ICO website for further guidance and the 12 steps to take now 32

Getting ready for GDPR. A guide to General Data Protection Regulations

Getting ready for GDPR. A guide to General Data Protection Regulations Getting ready for GDPR A guide to General Data Protection Regulations The General Data Protection Regulation (GDPR) Wherever information is stored, individuals and organisations need to be mindful of the

More information

12 STEPS TO PREPARE FOR THE GDPR

12 STEPS TO PREPARE FOR THE GDPR 12 STEPS TO PREPARE FOR THE GDPR Presented by Henshalls Insurance Brokers On 25 May 2018, the General Data Protection Regulation (GDPR) comes into effect in the EU and across the United Kingdom. The GDPR

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

Preparing for the General Data Protection Regulation (GDPR)

Preparing for the General Data Protection Regulation (GDPR) Preparing for the General Data Protection Regulation (GDPR) 10 Steps For Schools... Introduction The new EU General Data Protection Regulation (GDPR) comes into force in the UK on 25th May 2018. This regulation

More information

GDPR Service Information Sheet

GDPR Service Information Sheet GDPR Service Information Sheet What is GDPR? General Data Protection Regulation (GDPR) - is a policy that comes into effect from the 25th May 2018. Any business that processes the personal data of EU individuals,

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

GDPR factsheet Key provisions and steps for compliance

GDPR factsheet Key provisions and steps for compliance GDPR factsheet Key provisions and steps for compliance Organisations hold vast amounts of personal data relating to customers, employees, and suppliers as well as within marketing databases. Compliance

More information

TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION

TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION Awareness Data Stream Map Communication Rights of the subject Legal basis Consent Data Breaches Privacy by design and PIA

More information

A Parish Guide to the General Data Protection Regulation (GDPR)

A Parish Guide to the General Data Protection Regulation (GDPR) A Parish Guide to the General Data Protection Regulation (GDPR) What s happening and why is it important? The law is changing. Currently, the Data Protection Act 1998 governs how you process personal data

More information

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR Factsheet - Key Provisions and steps for Compliance GDPR Factsheet - Key Provisions and steps for Compliance Organisations in the Leisure & Hospitality industry hold vast amounts of personal data relating to customers, employees, and suppliers as well as

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

Getting ready for the new UK data protection law Eight practical steps for micro business owners and sole traders

Getting ready for the new UK data protection law Eight practical steps for micro business owners and sole traders Getting ready for the new UK data protection law Eight practical steps for micro business owners and sole traders 1 Know the law is changing which you now do, so that s one thing you ve done already! 5

More information

Minutes of a meeting of the Website and Information Committee held on the 29 th March 2018.

Minutes of a meeting of the Website and Information Committee held on the 29 th March 2018. Minutes of a meeting of the Website and Information Committee held on the 29 th March 2018. PRESENT: Cllr Gareth Rowlands (Chair), Cllr Gareth Smith, Cllr Andy Smith, Mike Kermode, Town Clerk 1. APOLOGIES:

More information

The GDPR: What does it mean for executive search?

The GDPR: What does it mean for executive search? The GDPR: What does it mean for executive search? At Invenias, we are committed to working in partnership with our customers to ensure a streamlined journey to compliance. Our customers benefit from data

More information

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey www.nascenta.com GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey Introduction GDPR Key Points GDPR/DPA Differences Start Up, Tech Business Professional Practice?

More information

WSGR Getting Ready for the GDPR Series

WSGR Getting Ready for the GDPR Series WSGR Getting Ready for the GDPR Series Overview, main concepts, principles and obligations Cédric Burton Of Counsel Laura De Boel Senior Associate Christopher Kuner Senior Privacy Counsel WSGR Webinar,

More information

Getting Ready for the GDPR

Getting Ready for the GDPR Getting Ready for the GDPR Ann Cartwright Information Governance Lead Sefton Council for Voluntary Service (CVS) Registered Charity No. 1024546. Company Limited by Guarantee No. 2832920. Suite 3B, 3rd

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 This document is a broad overview of the GDPR and does not provide legal advice. We urge you to consult with your own

More information

The General Data Protection Regulation An Overview

The General Data Protection Regulation An Overview The General Data Protection Regulation An Overview Published: May 2017 Brunel House, Old Street, St.Helier, Jersey, JE2 3RG Tel: (+44) 1534 716530 Guernsey Information Centre, North Esplanade, St Peter

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information

General Data Protection Regulation. The changes in data protection law and what this means for your church.

General Data Protection Regulation. The changes in data protection law and what this means for your church. General Data Protection Regulation The changes in data protection law and what this means for your church. 1 Contents Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 18 Page 20 Page 23

More information

EU General Data Protection Regulation

EU General Data Protection Regulation Guidance note EU General Data Protection Contents Introduction Guidance note aims and structure Summary Data basics Dealing with individuals Governance and risk management Concluding remarks Appendix 1

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

DATA PROTECTION POLICY 2016

DATA PROTECTION POLICY 2016 DATA PROTECTION POLICY 2016 ADOPTED FROM BRADFORD METROPOLITAIN COUNCIL MODEL POLICY AUTUMN 2016 To be agreed by Governors on; 17/10/16 Signed by Chair of Governors: Statutory policy: Yes Frequency of

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

Auditing data protection

Auditing data protection Data protection Auditing data protection a guide to ICO data protection audits 1 Contents Executive summary 3 1. Audit programme development 5 Audit planning and risk assessment 2. Audit approach 6 Gathering

More information

Guide to the GDPR. Contents. dbsdata.co.uk

Guide to the GDPR. Contents. dbsdata.co.uk Guide to the GDPR Guide to the GDPR Contents 03 What does the new GDPR say? 04 The GDPR Principles 04 Organisational & Technical Measures 05 GDPR at a glance 06 From May 2018 each of us have some new awesome

More information

Our Privacy Principles

Our Privacy Principles SAXON HALL/SOUTHEND MASONIC CENTRE - PRIVACY POLICY Our Privacy Principles We will look after any personal information you share with us. This is central to our values as a company. We want everyone to

More information

UK SCHOOL TRIPS PRIVACY POLICY

UK SCHOOL TRIPS PRIVACY POLICY UK SCHOOL TRIPS PRIVACY POLICY Introduction Welcome to the UK School Trips privacy notice. UK School Trips respects your privacy and is committed to protecting your personal data. This privacy notice will

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1.

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1. Company Name: Document DP3 Topic: Skills Direct Ltd ( the Company ) Data Protection Policy Data protection Date: 21 st May 2018 Version: Version 1 Contents Introduction Definitions Data processing under

More information

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you: Ignata Group Data Protection / Privacy Notice What is the purpose of this document? Ignata is committed to protecting the privacy and security of your personal information. This privacy notice describes

More information

EU GENERAL DATA PROTECTION REGULATION

EU GENERAL DATA PROTECTION REGULATION EU GENERAL DATA PROTECTION REGULATION GENERAL INFORMATION DOCUMENT This resource aims to provide a general factsheet to Asia Pacific Privacy Authorities (APPA) members, in order to understand the basic

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

Privacy notices, transparency and control

Privacy notices, transparency and control Data protection Privacy notices, transparency and control A code of practice on communicating privacy information to individuals About the code Who should use this code? Why should you provide effective

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

ACCENTURE BINDING CORPORATE RULES ( BCR )

ACCENTURE BINDING CORPORATE RULES ( BCR ) ACCENTURE BINDING CORPORATE RULES ( BCR ) EXECUTIVE SUMMARY INTRODUCTION Complying with data privacy laws is part of Accenture s Code of Business Ethics (COBE). In line with our COBE, we implement recognized

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY APRIL 2018 Attendance Policy and Procedures (Pupils) (P3/Policies) Updated January 2018 Page 1 of 11 Title Summary Purpose Operational Date April 2018 Next Review Date April 2019

More information

Air Mauritius Limited (Business Registration Number C ) PRIVACY NOTICE

Air Mauritius Limited (Business Registration Number C ) PRIVACY NOTICE Air Mauritius Limited (Business Registration Number C07001600) Introduction PRIVACY NOTICE Welcome to the Air Mauritius privacy notice, which applies to all our customers. Although we are a company established

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Presenting a live 90-minute webinar with interactive Q&A Compliance With New EU GDPR: Steps Investment Funds, Banks, Advisers and Financial Intermediaries Should Take Now Revising Service Agreements and

More information

What you need to know. about GDPR. as a Financial Broker. Sponsored by

What you need to know. about GDPR. as a Financial Broker. Sponsored by What you need to know about GDPR as a Financial Broker Dear Partner The regulatory and compliance environment is ever changing and the burden and requirements on financial services professionals continues

More information

GDPR & Charitable Fundraising: Spotlight on corporate fundraising

GDPR & Charitable Fundraising: Spotlight on corporate fundraising 4 GDPR & Charitable Fundraising: Spotlight on corporate fundraising Produced by: Reviewed by: Introduction The General Data Protection Regulation (GDPR) comes into effect on 25th May 2018 to update the

More information

Find out about the General Data Protection Regulation (GDPR) and what your club will need to do to comply with the Law.

Find out about the General Data Protection Regulation (GDPR) and what your club will need to do to comply with the Law. Find out about the General Data Protection Regulation (GDPR) and what your club will need to do to comply with the Law. This short guide will give you an introduction to the General Data Protection Regulation

More information

Foundation trust membership and GDPR

Foundation trust membership and GDPR 05 April 2018 Foundation trust membership and GDPR In the last few weeks, we have received a number of enquiries from foundation trusts concerned about the implications of the new General Data Protection

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS What is the purpose of this document? FS1 Recruitment UK Ltd is committed to protecting the privacy and security of your

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?...

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?... Data Protection Guidance for Volunteers Last update 26/11/17 Contents Introduction... 2 1. Why is data protection important?... 2 2. How does it apply to volunteers?... 2 3. What volunteers need to do?...

More information

General Data Protection Regulation. What should community energy organisations be doing to prepare?

General Data Protection Regulation. What should community energy organisations be doing to prepare? General Data Protection Regulation What should community energy organisations be doing to prepare? The implementation date of 25 May 2018 for the General Data Protection Regulation (GDPR) is fast approaching.

More information

A guide to GDPR the effect on all UK organisations

A guide to GDPR the effect on all UK organisations A guide to GDPR the effect on all UK organisations Personal Data Penalties Consent Data Breach Notification GDPR Right to Object Data Portability Right to be Forgotten A white paper from Eazipay Ltd October

More information

Vendor Agreements and the New EU GDPR Steps to Take Now

Vendor Agreements and the New EU GDPR Steps to Take Now Presenting a live 90-minute webinar with interactive Q&A Vendor Agreements and the New EU GDPR Steps to Take Now Complying With the EU General Data Protection and Privacy Regulation TUESDAY, JANUARY 30,

More information

New General Data Protection Regulation - an introduction

New General Data Protection Regulation - an introduction New General Data Protection Regulation - an introduction Netnod spring meeting 2017 Johan Hübner, Partner, Advokat Erika Hammar, Associate Agenda Background Why you need to care about the new data privacy

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

What is GDPR and Should You Care?

What is GDPR and Should You Care? What is GDPR and Should You Care? Ingram Micro Inc. 1 Overview of Privacy Climate & Concerns 2 2 Today We Live In A World Where Advertisers read key words in your Facebook posts and emails and decide what

More information

Consulting Champions

Consulting Champions Consulting Champions Get GDPR Ready with SOLA Consulting A bespoke GDPR compliance offering covering people, process, technology and data www.solagroup.com SOLA Consulting is part of SOLA Group Ltd Contents

More information

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR General Data Protection Regulation Philippe Roggeband Business Development, Manager, GSSO EMEAR Why should you care? Data Protection, and compliance with the General Data Protection regulation, is NOT

More information

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector TABLE OF CONTENTS INTRODUCTION... 2 Accountable privacy management 2 Getting started 3 A.

More information

Information Asset Management Policy

Information Asset Management Policy Information Asset Management Policy 1.0 Purpose 1.1 The purpose of this policy is to outline the management of the Fund s information asset register and the actions that will be taken to provide sufficient

More information

The data protection rules require that personal information we hold about you must be:-

The data protection rules require that personal information we hold about you must be:- JOB APPLICANT DATA PROTECTION POLICY Ryanair is committed to complying with applicable data protection and privacy standards at all times and takes its responsibility regarding information security very

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

GDPR GENERAL GUIDANCE FOR CONGREGATIONS Contents

GDPR GENERAL GUIDANCE FOR CONGREGATIONS Contents 1 GDPR GENERAL GUIDANCE FOR CONGREGATIONS Contents 1. Key definitions pages 1-4 2. Special category data page 5 3. Data Protection Principles pages 5-15 4. Rights of individuals pages 11-13 5. Data security

More information

The new EU data protection Regulation: The business opportunity beyond legal compliance. Kalliopi Spyridaki Chief Privacy Strategist, Europe

The new EU data protection Regulation: The business opportunity beyond legal compliance. Kalliopi Spyridaki Chief Privacy Strategist, Europe The new EU data protection Regulation: The business opportunity beyond legal compliance Kalliopi Spyridaki Chief Privacy Strategist, Europe Content The GDPR: background, content & principles What does

More information

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) The first IBM Personal Computer was introduced just over 35 years ago, on August 12, 1981. The first-generation iphone was introduced in the

More information

PERSPECTIVE. GDPR - An industry and geography agnostic regulation. Abstract

PERSPECTIVE. GDPR - An industry and geography agnostic regulation. Abstract PERSPECTIVE GDPR - An industry and geography agnostic regulation Abstract As the deadline to comply with the General Data Protection Regulation (GDPR) draws near, many organizations are unaware of what

More information

Conducting privacy impact assessments code of practice

Conducting privacy impact assessments code of practice ICO lo Conducting privacy impact assessments code of practice Data Protection Act Contents Data Protection Act... 1 About this code... 3 Chapter 1 - Introduction to PIAs... 5 What the ICO means by PIA...

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY LEEDS BECKETT U NIVERSI T Y DATA PROTECTION POLICY 1. INTRODUCTION 1.1 This policy document explains the framework through which the University ensures compliance with the Data Protection Act 1998 (DPA).

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

If you have queries about this privacy notice or wish to exercise any of the rights mentioned in it please contact

If you have queries about this privacy notice or wish to exercise any of the rights mentioned in it please contact Privacy Notice Grace Personnel Ltd takes its Data Protection responsibilities seriously and we are committed to using the data we hold in accordance with the law. The following explains how and why we

More information

Breaking the myth How your marketing activities can benefit from the GDPR December 2017

Breaking the myth How your marketing activities can benefit from the GDPR December 2017 www.pwc.be Breaking the myth How your marketing activities can benefit from the GDPR December 2017 1. Introduction As opposed to a widespread belief, the GDPR aims to reinforce customers rights, whilst

More information

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016 Dealing with the EU Data Protection Regulation in Practice William Long, Partner Sidley Austin LLP February 11, 2016 Do you need to comply? The Regulation will apply to a business processing personal data:

More information

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation EU General Data Protection Regulation (GDPR) Tieto s approach and implementation GDPR roles and positions Data subjects Information on processing Consent or other basis for processing Right requests High

More information

Mind the Gap: GDPR Ahead. Rakesh Sancheti. Author. July Vice President and Business Head - Analytics, Europe and Nordic

Mind the Gap: GDPR Ahead. Rakesh Sancheti. Author. July Vice President and Business Head - Analytics, Europe and Nordic Author Rakesh Sancheti Vice President and Business Head - Analytics, Europe and Nordic July 2017 The regulatory environment has become increasingly complex, with new regulations being introduced across

More information

RESEARCH ETHICS POLICY

RESEARCH ETHICS POLICY RESEARCH ETHICS POLICY ODSc agreed document August 09 Date approved at Board of Trustees October 09 Board of Trustees Number BOT091005e Date Policy/Procedure to be implemented October 09 Date to be reviewed

More information

Introduction. Ignoring the impact of the GDPR on your recruitment team is opening up your business to substantial risk.

Introduction. Ignoring the impact of the GDPR on your recruitment team is opening up your business to substantial risk. THE GDPR PLAYBOOK Introduction The GDPR requires you to do a number of things and with our GDPR Playbook, you can become a beacon of trust with an approach that is in line with the spirit of GDPR that

More information

European Union General Data Protection Regulation 2016 (Effective 25 May 2018)

European Union General Data Protection Regulation 2016 (Effective 25 May 2018) European Union General Data Protection Regulation 2016 (Effective 25 May 2018) European Union General Data Protection Regulation 2016 (Effective 25 May 2018) CONTENTS Why is the GDPR relevant to Hong

More information

Data Management and Protection Policy

Data Management and Protection Policy Data Management and Protection Policy Approved by Governor committee: Finance and Audit Date to be reviewed: June 2018 Responsibility of : Director of Finance and Operations Date ratified by Governing

More information

GDPR Compliance Checklist

GDPR Compliance Checklist GDPR Compliance Checklist GDPR Compliance Checklist This GDPR Compliance Checklist sets out the key requirements that the General Data Protection Regulation will introduce into EU Privacy law on 25 May

More information

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR) Customer Data Protection Temenos module for the General Data Protection Regulation (GDPR) Contents Glossary 03 GDPR Geographical Scope 03 GDPR implementation status 03 Overview of GDPR 03 Financial Institutions

More information

SIGBI DATA PROTECTION PROTOCOLS 2018

SIGBI DATA PROTECTION PROTOCOLS 2018 SIGBI DATA PROTECTION PROTOCOLS 2018 For the purpose of this document, references to Soroptimist International Great Britain and Ireland (SIGBI) Limited and Soroptimist International may be written as

More information

Privacy Statement for ING customers. Americas - May 2018

Privacy Statement for ING customers. Americas - May 2018 Privacy Statement for ING customers Americas - May 2018 Contents 1. About this Privacy Statement 3 2. The types of data we collect about you 3 3. What we do with your personal data 3 4. Who we share your

More information

Linking establishment and worker records. May 2017 Version 2

Linking establishment and worker records. May 2017 Version 2 Linking establishment and worker records May 2017 Version 2 Contents Introduction... 3 How will I know if my data matches?... 3 How do I correct the mismatched data?... 3 What happens when I have corrected

More information

Unit: CPC 420 De-commission services (Commissioning, Procurement and Contracting)

Unit: CPC 420 De-commission services (Commissioning, Procurement and Contracting) Unit: CPC 420 De-commission services (Commissioning, Procurement and Contracting) Key Purpose The key purpose identified for those working in commissioning, procurement and contracting is to: Specify,

More information

Data Protection Policy

Data Protection Policy Preston and District Data Protection Policy The University of the Third Age Scope of the policy This policy applies to the work of Preston & District U3A (hereafter the U3A ). The policy sets out the requirements

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

A Path to Social Licence

A Path to Social Licence August 2017 A Path to Social Licence Guidelines for Trusted Data Use A Path to Social Licence Guidelines for Trusted Data Use 1 1 2 August 2017 A Path to Social Licence Guidelines Summary for June August

More information

Quick guide to the employment practices code

Quick guide to the employment practices code Data protection Quick guide to the employment practices code Ideal for the small business Contents 3 Contents Section 1 About this guidance 4 Section 2 What is the Data Protection Act? 5 Section 3 Recruitment

More information

TEL: +44 (0)

TEL: +44 (0) EU General Data Protection Regulation FAQs Cordery GDPR Navigator This note is part of the Cordery GDPR Navigator. Technical terms are used in this document which are explained in the glossary. Edition

More information

Reach out to customers and increase your revenue

Reach out to customers and increase your revenue For retail business Contact with the customer is what business is all about. Maintain your contacts with the customers and build your business. Reach out to customers and increase your revenue What is

More information

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT WHAT GDPR MEANS FOR RECORDS MANAGEMENT Presented by: Sabrina Guenther Frigo Overview Background Basic Principles Scope Lawful Processing Data Subjects Rights Accountability & Governance Data Transfers

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 17/EN WP264 rev.01 Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data Adopted on 11

More information