GDPR is just around the corner. What does it mean for you?

Size: px
Start display at page:

Download "GDPR is just around the corner. What does it mean for you?"

Transcription

1 GDPR is just around the corner What does it mean for you?

2 Your guide to the GDPR The General Data Protection Regulation (or the GDPR for short) is a piece of EU regulation that comes into force on 25 May 2018 which intends to bring data protection regulation up to date. Since the launch of the Data Protection Act 1998, the technology landscape has changed dramatically and data is being used now in many more ways than it has been previously. You ve probably heard a lot about the GDPR in the news, the trade press, and from your suppliers. Here at Close Brothers Motor Finance, we re keen to let you know what it means for you, your relationship with us, and our relationship with our customers. Contents The GDPR an overview What does the GDPR mean for you? Privacy notices Customer consent FAQs Key terms glossary Close Brothers Motor Finance

3 Summary What do you need to do? Training You should make sure that decision makers and key people in your organisation are aware that the law is changing to the GDPR. They need to appreciate the impact this is likely to have. Data collection and storage You should document what personal data you hold, where it came from and who you share it with. You may need to organise an information audit. You can keep customer data for a period of time that is deemed relevant to the relationship you have. It will be important to tell the customer how long you will keep it and have a process to remove after these defined points. Think about how you store customer data. Check that you are keeping it secure, whether electronically or in hard copy. This also gives you an opportunity to reduce duplicate or old data you no longer need to hold. We (Close Brothers Motor Finance) collect data to make a credit decision and to provide finance, the customer needs to know what this entails and what we will do with their data this is all in our updated privacy notice. Customer privacy and consent You should review your current privacy notices and put a plan in place for making any necessary changes in time for the GDPR implementation. Make sure your privacy notice tells the customer why you re capturing their data and what you intend to do with it. After 25 May, we will only accept manual proposals on our own manual proposal forms. The GDPR is just around the corner: What does it mean for you? 3

4 The GDPR An overview What is the GDPR? The General Data Protection Regulation (or GDPR for short) is a piece of EU regulation that comes into force on 25 May 2018 which intends to update data protection law. It will apply to the UK even after we leave the EU through Brexit. Since the launch of the Data Protection Act 1998, the technology landscape has changed dramatically and data is now being used in new and innovative ways that the existing law did not account for, so it s important that the rules around data are brought up to date. The GDPR is designed to protect and strengthen an individual s personal data rights and reshape how we approach data privacy. Who does it apply to? Who are the ICO? What does it mean for us? They have produced lots of information about the GDPR, all of which can be found on their website: The GDPR affects any organisation or individual which holds or processes personal data. It also gives new rights and more control over how an individual s information is used and shared. Close Brothers Motor Finance as a finance provider and you as a dealer partner or broker are both Data Controllers. That means that we are both responsible for ensuring we comply with the new legislation in our own businesses. We each have our own responsibilities to ensure we are doing the right thing for our customers and there are certain changes we must make. The ICO (Information Commissioner s Office) are an independent body set up to uphold information rights in the UK and ensure that organisations abide by Data Protection laws. 25 May 4 Close Brothers Motor Finance These changes come into effect on 25 May 2018; you might notice that our agreements and consent requirements will change just before this date.

5 What does the GDPR mean for you? Training First of all, it s important that you and your team understand what the GDPR is. To promote best practice, you should train all of your staff about the principles of the GDPR so that they understand the importance of protecting individuals data. Training is also one of the first things that the ICO might ask about if they were to investigate your business, so make sure you keep a record of any training you provide to your team. Data collection and storage The GDPR sets out how we keep personal data and what we can and can t do with it. For example, data must be collected for specified, explicit and legitimate purposes. It is important to ensure that information is not captured without reason and that the individual knows how and where their data will be used. Under the GDPR, you can still retain customer data, however you cannot retain personal data for any longer than is necessary, so if you do want to hold on to it, you need to have a valid reason for doing so. If for example, someone buys a vehicle from you, together with a service plan, then you have a legitimate reason to keep their data as they will be returning to you on a regular basis for their services. However, if someone fills in a web enquiry form, but doesn t visit the dealership or convert into a sale, you should only retain this for a shorter period of time before deleting. You need to maintain a log of the types of personal information you store, and why you maintain it. This may be for purposes such as marketing to prospects, marketing services to existing customers, or providing warranty coverage. Data security The GDPR requires personal data to be processed in a manner that ensures its security. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. You should think about who has access to your systems and paper files, and put controls in place where necessary to ensure that only individuals who have a need to access the data can do so. You should not allow people from outside of your business to have access to any personal information that you hold, unless you have a contract in place with them, and the individual has been made aware of and agreed to their data being shared in such a way. You collect customer data for a number of reasons and it can take place well in advance of submitting a finance application to us, right back to the enquiry stage. You should think about the different ways you capture personal data: it could be online, over the phone, on , or face to face. The GDPR is just around the corner: What does it mean for you? 5

6 Privacy Notices Being transparent and providing accessible information to individuals about how you will use their personal data is a key element of the GDPR. The most common way to provide information about how you will use an individual s personal data is in the form of a privacy notice. Most companies already have a privacy notice, but there may be some changes required under the GDPR. One of the first principles of data protection is that personal data must be processed fairly and lawfully. In order for processing to be fair, the data controller (you regarding the sale of a car, and separately us regarding finance for the vehicle) must make certain information available to the data subjects (customers). That information is: w ho the data controller is; t he purpose or purposes for which the information will be processed; who the data is shared with; and t he data retention period; a ny further information which is necessary for the specific circumstances to enable the processing to be fair. This applies whether the personal data was obtained directly from the individuals or from other sources. Information you provide to people about how you process their data must be: c oncise, transparent, intelligible and easily accessible; w ritten in clear and plain language and f ree of charge. You must provide privacy information to the individuals at the time you collect their personal data from them. 6 Close Brothers Motor Finance So, what should you do? If you don t have a privacy notice already, then you should create one. It should be easy to understand, and explain what you do with their data and why. If you do have one already, make sure you check through it to ensure that it s easy to understand and covers any activity that you ll be using the customers data in. If you do not yet have a privacy notice, or want to confirm it is fit for purpose going forward, take a look at the guidance available on the For Organisations link on What are we doing? In keeping with the above, we re making some changes to our own privacy notice to ensure we re following the guidelines that have been published. You ll probably be familiar with our privacy notice which appears when you process an application and submit it to us if you ve used the Ask Close/Showroom proposal system. It also appears on our manual proposal forms.

7 Our privacy notices How it appears on the manual proposal form How it appears in Showroom We have updated our privacy notice which now goes into much more detail about how we process customer data and why. Before 25 May, you ll see our privacy notice change. The updated manual proposal form pads will be available through your Account Manager. 25 May From 25 May, we will no longer accept proposals on the old proposal form containing our old privacy notice. It is imperative that the customer has an opportunity to read our privacy notice before you submit the application to us. Please destroy any of the old manual proposal forms, and make sure you order the new ones in plenty of time before 25 May. We also will no longer accept any manual proposals on anything other than the approved Close Brothers Motor Finance proposal forms. What should you do if the customer isn t present? If arranging an application over the phone, or a customer is making a remote purchase, then you need to explain the key points from the privacy notice to the customer. These are as follows: Purposes for which Close Brothers Motor Finance use the customer s personal data: To conduct a credit check via a Credit Reference Agency; To verify the customer s identity, assess their suitability for the products and services that they have requested, and decide whether to enter into an agreement with them; To manage, administer and take decisions regarding their agreement; Where necessary for our legitimate business interests (improving customer service, market research, quality assurance etc.) and; To meet our legal and regulatory obligations. Exchange of information with credit reference agencies (CRAIN) If the customer would like to read more about how their information will be used by our credit reference agency, they can do so at What is CRAIN? CRAIN stands for Credit Reference Agency Information Notice. It is the joint privacy notice for the credit reference agencies (Experian, Call Credit etc.). It s something that we need to make the customer aware of and advise them on how they can access it. We ve got the URL in our privacy notices (as above), and you should make sure the customers are aware of their right to access this. The GDPR is just around the corner: What does it mean for you? 7

8 Consent What is consent? Consent means offering individuals real choice and control over their personal data and how it is used. If consent is done properly, it should put individuals in charge, build customer trust and engagement and enhance reputation. The GDPR sets a high standard for how individuals can consent to their data being used. It must be unambiguous and involve a clear and affirmative action. It specifically bans pre-ticked opt-in boxes. Consent is one of the six lawful reasons (or bases) for processing personal data that you can use under the GDPR. The requirement to have a lawful basis is not new; it just replaces the conditions for processing from the Data Protection Act. You can find more information about lawful basis here: Consent doesn t last forever, but there aren t any set limits so provided you have a valid reason for maintaining that customer information (i.e. they re a current customer), then you can class that information as active and continue to use it. What do you need to do? The key here is to make sure that you understand what personal data you collect and what for, or why you use it. You might not always need to gain consent if you have other lawful bases for collecting the data. For example, we re not asking customers to consent to us using their data for the purposes of a finance application, because we re covered by contract and legitimate interest bases we must process that data in order to fulfil a contract. Direct marketing to individuals who are not your customers generally requires the individuals to have consented to hearing from you in the channel used (i.e., , SMS, phone, post) and about the type of product or service you are marketing. This means any web enquiry forms on your website and other ways of identifying leads will need to be reviewed to confirm appropriate consent language is in place. Check the ICO website for further guidance on consent language. You may be able to market to existing customers without explicit consent, if you are marketing related products or services to those already purchased, the individuals have an opportunity to opt out of future communications, and you stop marketing to anyone who does opt out. You can no longer use customer data from Showroom/Ask Close for your own marketing activities or to contact customers 8 Close Brothers Motor Finance

9 What are Close Brothers Motor Finance doing? We want to be transparent with the customer about what they re providing their consent for and when, and so we ve made some changes to our processes. Electronic Signature eclick We re introducing two new tick boxes as part of the customer signature journey that looks like this: Wet signature We ve added the same consent boxes to our wet signature agreement documents too. This is going to allow our customers to decide what information they receive from us. Neither of the boxes will be populated, so the customer has the option to tick either box, both or none, as they prefer. The GDPR is just around the corner: What does it mean for you? 9

10 FAQs What about your ICO registration? Most data controllers are required to register annually with the ICO. For further information on ICO registration and to understand if you should be registered, you can visit their website. self-assessment/ Where can you find out more information about the GDPR in general? The best place to start is the Information Commissioner s Office (ICO) website. They have produced a guide to the 12 things you need to think about right now, and a Getting Ready for the GDPR checklist, along with plenty of background information about the new regulation. Can you still use your customers data to market to them? Yes provided you have a lawful basis according to the GDPR. You can find more information about lawful bases here; What does the GDPR say about what your privacy notice should contain? Who the data controller is; The purpose or purposes for which the information will be processed; The data retention period; Who the data is shared with; and Any further information which is necessary for the specific circumstances to enable the processing to be fair. This applies whether the personal data was obtained directly from the customer, or from other sources. Information you provide to people about how you process their data must be: concise, transparent, intelligible and easily accessible; written in clear and plain language and free of charge. What about business customers? If an individual can be identified by the data you hold, regardless of whether they are associated with a Limited Company or not, this data is classed as PII under the GDPR, and the processing principles in this document apply. One change you need to be aware of is that from 25 May you will no longer be able to use data from our systems (Showroom/Ask Close) to market to your customers. 10 Close Brothers Motor Finance

11 Glossary Consent Consent is any freely-given, specific and informed indication of wishes by which the Data Subject agrees to their personal data being processed. This can be achieved by a customer opting-in to receiving marketing material from you or associated third parties. CRAIN The CRAIN is the Credit Reference Agency Information Notice the privacy notice for our credit reference agency/agencies. Customers must have access to this if requested before sending their personal information on to the credit reference agency. Data controller A controller determines how and why personal data is collected and processed. Data controllers will usually be organisations, but can be individuals. If you or your business are a controller, you are not relieved of your obligations where a processor is involved the GDPR places further obligations on you to ensure your contracts with processors comply with the GDPR. Data processor A processor is responsible for processing personal data on behalf of a controller. If you are a processor, the GDPR places specific legal obligations on you; for example, you are required to maintain records of personal data and processing activities. You will have legal liability if you are responsible for a breach. Data subject A data subject is a living individual to whom personal data relates. The Act does not count as a data subject an individual who has died or who cannot be identified or distinguished from others. DPA The Data Protection Act (DPA) controls how your personal information is used by organisations, businesses or the government. The GDPR will replace the Data Protection Act. ICO Stands for Information Commissioner s Office. The UK s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. PII PII is Personally Identifiable Information. As described in the regulation, it is any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly by something such as a name, ID number, location data or online identifier. Essentially this means that PII is anything like customer name, address, address, vehicle registration, credit card number, VIN/VRN etc. It s any piece of information that exclusively or when used in conjunction with other information, could allow you to identify a unique individual Privacy policy A privacy policy is a publicly available document that outlines a company s intentions concerning personal data storage and use. DPO A DPO (Data Protection Officer) is someone appointed to a business to monitor internal compliance with the GDPR and provide advice regarding Data Protection Impact Assessments. To understand whether you need to appoint a DPO, visit the ICO website. The GDPR is just around the corner: What does it mean for you? 11

12 Call us on Call your local branch Visit closemotorfinance.co.uk/dealer Visit closemotorfinance.co.uk/dealer/gdpr Close Brothers Motor Finance Close Brothers Motor Finance Roman House, Roman Road, Doncaster, DN4 5EZ Roman House, Roman Road, Doncaster, DN4 5EZ Showroom User Guide - February 2018 The information contained in this guide is for general information purposes only. The information is provided by Close Brothers Motor Finance, and while we endeavour to keep the information up to date and correct, we make no representations or warranties of any kind, express or implied about the completeness, accuracy, reliability, suitability or availability with respect to the guide or the information, products, services, or related graphics contained in the guide for any purpose. Any reliance you place on such information is therefore strictly at your own risk. You should seek independent legal advice if you are in any doubt as to your own legal obligations. In no event will we be liable for any loss or damage including without limitation, indirect or consequential loss or damage or any loss or damage whatsoever arising from loss of data or profits arising out of, or in connection with, the use of this guide. Please make sure you are using the most up to date version of this guide if you are in any doubt; please speak to your Account Manager. Please make sure you destroy any previous version of this guidance whether in hard copy or stored electronically. You should not copy, share or reproduce the contents of this guide other than for your own use. Close Brothers Limited does not accept any responsibility to any unconnected third party in the event that its contents are reproduced or relied upon as legal advice in any way. Close Brothers Motor Finance is a trading style of Close Brothers Limited ( CBL ), a subsidiary of Close Brothers Group plc. CBL is registered in England and Wales with company number and registered office at 10 Crown Place, London EC2A 4FT. Close Brothers Limited is authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and Prudential Regulation Authority. Firm reference number

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

GENERAL DATA PROTECTION REGULATION.

GENERAL DATA PROTECTION REGULATION. For the use of mortgage intermediaries and other professionals only. GENERAL DATA HALIFAX INTERMEDIARIES KEY CHANGES GUIDE MAY 2018 REGULATION >SELECT A TILE FOR MORE INFORMATION WHAT IS THE GDPR? KEY

More information

GDPR in Early Years and Childcare settings. What s the connection? Data Protection

GDPR in Early Years and Childcare settings. What s the connection? Data Protection GDPR in Early Years and Childcare settings What s the connection? Data Protection What is GDPR? Test your knowledge 10 minute quiz Think of GDPR as evolutionary, not revolutionary Why? GDPR legislation

More information

GDPR General Data Protection Regulation

GDPR General Data Protection Regulation GDPR General Data Protection Regulation Compliance Information Guide - May 2018 About this document Ticket Arena & Event Genius Disclaimer DISCLAIMER: This is a brief presentation for information purposes

More information

Open Badge in partnership with SSSC: GDPR Aware

Open Badge in partnership with SSSC: GDPR Aware Open Badge in partnership with SSSC: GDPR Aware This Open Badge is informed by guidance available from the Information Commissioner's Office. This resource will raise your awareness of ensuring compliance

More information

Foundation trust membership and GDPR

Foundation trust membership and GDPR 05 April 2018 Foundation trust membership and GDPR In the last few weeks, we have received a number of enquiries from foundation trusts concerned about the implications of the new General Data Protection

More information

General Data Protection Regulation. Jim Sneddon GDPR-P, CISSP

General Data Protection Regulation. Jim Sneddon GDPR-P, CISSP General Data Protection Regulation Jim Sneddon GDPR-P, CISSP "The GDPR is actually already in force, it is just that Member States are not obligated to apply it until 25 May 2018. It s your job, it s your

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

12 STEPS TO PREPARE FOR THE GDPR

12 STEPS TO PREPARE FOR THE GDPR 12 STEPS TO PREPARE FOR THE GDPR Presented by Henshalls Insurance Brokers On 25 May 2018, the General Data Protection Regulation (GDPR) comes into effect in the EU and across the United Kingdom. The GDPR

More information

As members will be aware new General Data Protection Regulations (GDPR) come into effect on May 25 th this year.

As members will be aware new General Data Protection Regulations (GDPR) come into effect on May 25 th this year. GDPR As members will be aware new General Data Protection Regulations (GDPR) come into effect on May 25 th this year. These new regulations apply to all businesses and organisations. Controller vs Processor

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

GDPR & Charitable Fundraising: Spotlight on community fundraising

GDPR & Charitable Fundraising: Spotlight on community fundraising 3 GDPR & Charitable Fundraising: Spotlight on community fundraising Produced by: Reviewed by: Introduction The General Data Protection Regulation (GDPR) comes into effect on 25th May 2018 to update the

More information

General Data Protection Regulation. The changes in data protection law and what this means for your church.

General Data Protection Regulation. The changes in data protection law and what this means for your church. General Data Protection Regulation The changes in data protection law and what this means for your church. 1 Contents Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 18 Page 20 Page 23

More information

Functional area. F Hallinan, C Abad, W Andrews Approver (s) Version 001 Effective date 25 May Privacy Notice for Emergency Contacts

Functional area. F Hallinan, C Abad, W Andrews Approver (s) Version 001 Effective date 25 May Privacy Notice for Emergency Contacts The Charter Schools Educational Trust Privacy Notice for Emergency contacts GDPR compliant (Article 14 contact details given by someone other than the data subject) Contents: The personal data we hold

More information

CHANNING SCHOOL DATA PROTECTION POLICY

CHANNING SCHOOL DATA PROTECTION POLICY CHANNING SCHOOL DATA PROTECTION POLICY The School may amend/change/update this Policy from time to time. 1. Background Data protection is an important legal compliance issue for Channing School. During

More information

GDPR & Charitable Fundraising: Spotlight on corporate fundraising

GDPR & Charitable Fundraising: Spotlight on corporate fundraising 4 GDPR & Charitable Fundraising: Spotlight on corporate fundraising Produced by: Reviewed by: Introduction The General Data Protection Regulation (GDPR) comes into effect on 25th May 2018 to update the

More information

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie Get ready A Guide to the General Data Protection Regulation (GDPR) elavon.ie The General Data Protection Regulation (GDPR) will regulate the privacy and handling of the personal data of individuals in

More information

GDPR UNIQUEULOGY. Hello. If you re working in the funeral sector, this is what you need to know about the General Data Protection Regulations

GDPR UNIQUEULOGY. Hello. If you re working in the funeral sector, this is what you need to know about the General Data Protection Regulations UNIQUEULOGY GDPR If you re working in the funeral sector, this is what you need to know about the General Data Protection Regulations Hello. Celebrants, funeral directors, florists, coffin-makers, caterers...

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

Sample Data Management Policy Structure

Sample Data Management Policy Structure Sample Data Management Policy Structure This document has been produced by The Audience Agency. You are free to edit and use this document in your business. You may not use this document for commercial

More information

What does the GDPR mean for recruitment?

What does the GDPR mean for recruitment? What does the GDPR mean for recruitment? www.recruitment.software Contents 04 What is GDPR? In May 2018, Europe s new data protection rules will come into effect. 04 Who is responsible? 05 What are the

More information

DATA PROTECTION POLICY 2018

DATA PROTECTION POLICY 2018 DATA PROTECTION POLICY 2018 Amesbury Baptist Church is committed to protecting all information that we handle about people we support and work with, and to respecting people s rights around how their information

More information

GDPR & Charitable Fundraising: Spotlight on Charitable Trust fundraising

GDPR & Charitable Fundraising: Spotlight on Charitable Trust fundraising 6 GDPR & Charitable Fundraising: Spotlight on Charitable Trust fundraising Produced by: Reviewed by: Introduction The General Data Protection Regulation (GDPR) comes into effect on 25th May 2018 to update

More information

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY LEICESTER HIGH SCHOOL DATA PROTECTION POLICY 1. Background Data protection is an important legal compliance issue for Leicester High School. During the course of the School's activities it collects, stores

More information

Data Protection Policy. UK Policy May 2018

Data Protection Policy. UK Policy May 2018 UK Policy May 2018 5 & 7 Diamond Court, Opal Drive, Eastlake Park, Fox Milne, Milton Keynes MK15 0DU, T: 01908 396250, F: 01908 396251 www.cognitaschools.co.uk Registered in England Cognita Limited No

More information

General Data Protection Regulation - Explained

General Data Protection Regulation - Explained General Data Protection Regulation - Explained Bernard Cogan & Bobby Gould CUNA Mutual Group ACE Conference & AGM 2017 12 th May 13 3h May 2017 Copthorne Hotel (Birmingham) Are you familiar with GDPR Don't

More information

Preparing for the GDPR

Preparing for the GDPR Preparing for the GDPR Note: These slides and the accompanying presentation contain a general summary and are not legal advice. Niall Rooney 03/11/2017 (1) Data Protection The Right to Data Protection

More information

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General Data Protection Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) General Index reference number Approved 26/04/18 Approved by Trust

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

GDPR factsheet Key provisions and steps for compliance

GDPR factsheet Key provisions and steps for compliance GDPR factsheet Key provisions and steps for compliance Organisations hold vast amounts of personal data relating to customers, employees, and suppliers as well as within marketing databases. Compliance

More information

An Introduction to GDPR and How To Prepare

An Introduction to GDPR and How To Prepare An Introduction to GDPR and How To Prepare Vincenzo Ardilio IRIS Data Protection Officer What We Will Highlight What you need to know first about GDPR Privacy notices Data subject rights The data controller/processor

More information

B2B telemarketing in a GDPR world

B2B telemarketing in a GDPR world B2B telemarketing in a GDPR world Written by: Jason Waldock & Anita Turner OUR BUSINESS IS NEW BUSINESS 1 Foreword Given the right advice and expertise, telemarketing in the GDPR world should be more effective.

More information

Find out about the General Data Protection Regulation (GDPR) and what your club will need to do to comply with the Law.

Find out about the General Data Protection Regulation (GDPR) and what your club will need to do to comply with the Law. Find out about the General Data Protection Regulation (GDPR) and what your club will need to do to comply with the Law. This short guide will give you an introduction to the General Data Protection Regulation

More information

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3 Norwich Central Baptist Church DATA PROTECTION POLICY Adopted: May.2018 Norwich Central Baptist Church (NCBC) is committed to protecting all information that we handle about people we support and work

More information

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey www.nascenta.com GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey Introduction GDPR Key Points GDPR/DPA Differences Start Up, Tech Business Professional Practice?

More information

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY Dingwall Baptist Church DATA PROTECTION POLICY Adopted: By Trustees Dingwall Baptist Church May 2018 1 Dingwall Baptist Church is committed to protecting all information that we handle about people we

More information

GDPR AN OVERVIEW OF THE REGULATIONS AND THEIR LIKELY IMPACT ON APPRENTICESHIPS

GDPR AN OVERVIEW OF THE REGULATIONS AND THEIR LIKELY IMPACT ON APPRENTICESHIPS GDPR AN OVERVIEW OF THE REGULATIONS AND THEIR LIKELY IMPACT ON APPRENTICESHIPS March 2018 Rebecca Rhodes, Senior Associate, UVAC r.rhodes@bolton.ac.uk Agenda Aim and purpose Scope & implications for non-compliance

More information

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy DATA PROTECTION POLICY WINCHESTER CITY COUNCIL Document Title: Author: Fiona Sutherland Revision History Version Revision Date Summary of Change Distribution 1.0 08/03/16 Internet Intranet WINCHESTER CITY

More information

Baptist Union of Scotland DATA PROTECTION POLICY

Baptist Union of Scotland DATA PROTECTION POLICY Baptist Union of Scotland DATA PROTECTION POLICY Adopted: May 2018 1 1.The Baptist Union of Scotland 48, Speirs Wharf, Glasgow G4 9TH (Charity Registration SC004960) is committed to protecting all information

More information

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY Adopted: 5 June 2018 1 Earls Hall Baptist Church is committed to protecting all information that we handle about people we support and work with, and to

More information

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak PROFESSIONAL INDEPENDENT ADVISERS LTD DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Training Manual Data Protection Officer is Mike Bandurak GDPR introduction

More information

GDPR Impacts on Digital Transformation

GDPR Impacts on Digital Transformation GDPR Impacts on Digital Transformation @leanandagile @engage_process @leanandagile @engage_process Is this another millennium bug? GDPR compliance will be an ongoing journey Unlike planning for the Y2K

More information

UNITED BANK FOR AFRICA (UK) LIMITED PRIVACY NOTICE

UNITED BANK FOR AFRICA (UK) LIMITED PRIVACY NOTICE UNITED BANK FOR AFRICA (UK) LIMITED PRIVACY NOTICE United Bank for Africa (UK) Limited is authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and Prudential

More information

A Practical Guide to Data Protection for Information Professionals

A Practical Guide to Data Protection for Information Professionals A Practical Guide to Data Protection for Information Professionals Naomi Korn and Carol Tullo on behalf of NKCC NKCC 2018. All Rights Reserved. www.naomikorn.com The information contained within this document

More information

The ICT Service:

The ICT Service: GDPR for schools 1 Intro and aims The ICT Service: support@theictservice.org.uk, 0300 300 00 00 Cambridgeshire County Council: Information and Records Team. Data.protection@cambridgeshire.gov.uk 01223

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

Data Protection Policy

Data Protection Policy Data Protection Policy This policy will be reviewed by the Trust Board three yearly or amended if there are any changes in legislation before that time. Date of last review: Autumn 2018 Date of next review:

More information

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR Factsheet - Key Provisions and steps for Compliance GDPR Factsheet - Key Provisions and steps for Compliance Organisations in the Leisure & Hospitality industry hold vast amounts of personal data relating to customers, employees, and suppliers as well as

More information

While every organisation is different, we believe the following guidance will help you understand what GDPR is and how you can start to comply.

While every organisation is different, we believe the following guidance will help you understand what GDPR is and how you can start to comply. Introduction While every organisation is different, we believe the following guidance will help you understand what GDPR is and how you can start to comply. This guidance is split into two main parts Part

More information

WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT

WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT WHAT IS GDPR? The EU General Data Protection Regulation (GDPR) comes into force on 25 May 2018. Within this document we ll explore what

More information

BROOKS PERSONAL TRAINING

BROOKS PERSONAL TRAINING BROOKS PERSONAL TRAINING Data Protection Policy Data Protection Policy Lent 2017 0 DATA PROTECTION POLICY Table of Contents: 1. Document Control... 2 2. Introduction... 3 3. General Statement of Scope...

More information

Introduction to the General Data Protection Regulation (GDPR)

Introduction to the General Data Protection Regulation (GDPR) Introduction to the General Data Protection Regulation (GDPR) #CIPR / @CIPR_UK This guide is worth 5 CPD points Introduction to the General Data Protection Regulation (GDPR) / 2 Contents 1 Introduction

More information

GDPR. Applying the General Data Protection Regulation to your business

GDPR. Applying the General Data Protection Regulation to your business GDPR Applying the General Data Protection Regulation to your business Mediaburst SMS Guide Contents 1 Introduction 3 12 steps to take now 7 Who does it apply to? 8 What information does it apply to? 9

More information

GENERAL DATA PROTECTION REGULATION Guidance Notes

GENERAL DATA PROTECTION REGULATION Guidance Notes GENERAL DATA PROTECTION REGULATION Guidance Notes What is the GDPR? Currently, the law on data protection requiring the handling of data which identifies people to be done in a fair way, is contained in

More information

Current Account Credit Card. Privacy Notice

Current Account Credit Card. Privacy Notice Current Account Credit Card Privacy Notice Contents Introduction 3 What sort of data do we hold about you? 3 What about joint applications and additional cardholders? 4 How does Tesco Bank use your personal

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ] SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY Adopted: [17-04-2018] 1 SAFFRON WALDEN COMMUNITY CHURCH is committed to protecting all information that we handle about people we support and work

More information

Getting Ready for the GDPR

Getting Ready for the GDPR Getting Ready for the GDPR Ann Cartwright Information Governance Lead Sefton Council for Voluntary Service (CVS) Registered Charity No. 1024546. Company Limited by Guarantee No. 2832920. Suite 3B, 3rd

More information

St Michael s CE Primary School Data Protection Policy

St Michael s CE Primary School Data Protection Policy St Michael s CE Primary School Data Protection Policy We will prepare the children at St. Michael's school for life, by giving them the opportunity to fulfil their potential within a happy caring Christian

More information

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 1 PURPOSE OF THIS DOCUMENT 2 This document is to be used as a guide for advertisers on how they should work with their agencies,

More information

GDPR is coming in 108 days: Are you ready?

GDPR is coming in 108 days: Are you ready? Charles-Albert Helleputte Partner, Brussels GDPR is coming in 108 days: Are you ready? Diletta De Cicco Legal Consultant, Brussels 6 February 2018 +32 2 551 5982 chelleputte@mayerbrown.com +32 2 551 5974

More information

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data OPTIN checklist OVERVIEW 1 GDPR Checklist This checklist sets out activities you will need to consider and act on by the compliance deadline of 25th May 2018. Use this to help you identify what support

More information

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018 LIFE STYLE CARE PLC Privacy Statement for Employees August 2018 Key points Why we use your personal data: We typically use your personal information for purposes related to your employment relationship

More information

Representative Church Body of the Church of Ireland General Data Protection Regulation Overview

Representative Church Body of the Church of Ireland General Data Protection Regulation Overview Representative Church Body of the Church of Ireland General Data Protection Regulation Overview Rebekah Fozzard Representative Church Body Spring 2018 Introduction Data Protection Coordinator for the Representative

More information

Moulsham Junior School

Moulsham Junior School Moulsham Junior School Advice to Parents - Your Data Protection Rights 1. Introduction The new General Data Protection Regulations provide you with legal rights over the personal data our school holds

More information

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH, NORTHALLERTON (referred to in this policy as NLBC) is committed to

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

GDPR in schools and academies. Dai Durbridge, Partner Browne Jacobson LLP

GDPR in schools and academies. Dai Durbridge, Partner Browne Jacobson LLP GDPR in schools and academies Dai Durbridge, Partner Browne Jacobson LLP Welcome Partner in the Education team at Browne Jacobson Lead the Manchester Education team Expert information management lawyers

More information

Privacy Notice for Clients of RISDON HOSEGOOD Solicitors

Privacy Notice for Clients of RISDON HOSEGOOD Solicitors Privacy Notice for Clients of RISDON HOSEGOOD Solicitors What does this document do? This Privacy Notice describes how personal data we collect from our clients will be collected, stored and processed.

More information

GDPR digest ARE YOU GDPR READY? {More than a MORTGAGE CLUB}

GDPR digest ARE YOU GDPR READY? {More than a MORTGAGE CLUB} GDPR digest ARE YOU GDPR READY? {More than a MORTGAGE CLUB} contents. at a glance ICO Helpline Principles Privacy by design Lawful basis for processing Privacy Electronic Communications Regulations - PECR

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Mission Statement WeST holds a deep seated belief in education and lifelong learning. Effective collaboration, mutual support and professional challenge will underpin our quest to

More information

Standard Advisory London Limited Third Party Privacy Statement

Standard Advisory London Limited Third Party Privacy Statement Standard Advisory London Limited Third Party Privacy Statement Purpose of this Privacy Notice Standard Advisory London Limited ("SALL" or "we") recognises its obligations to process personal data in accordance

More information

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make. What is the purpose of this document? NORTHERN IRELAND SCREEN COMMISSION (Company Number NI031997) whose registered office is at 3 rd Floor Alfred House, 21 Alfred Street, Belfast, BT2 8ED is committed

More information

The GDPR: What does it mean for executive search?

The GDPR: What does it mean for executive search? The GDPR: What does it mean for executive search? At Invenias, we are committed to working in partnership with our customers to ensure a streamlined journey to compliance. Our customers benefit from data

More information

We have prepared a general privacy notice covering all subject data and including use of our website at

We have prepared a general privacy notice covering all subject data and including use of our website at Privacy Notice Elliott Scott HR Recruitment is aware of its obligations in Europe to comply with General Data Protection Regulation (GDPR) and is committed to processing personal data securely and transparently.

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: 4 1. Statement of Intent 1.1 Radian 1 must collect, store and process information about its customers,

More information

Data Protection Policy

Data Protection Policy Policy Current Status Operational Last Review: May 2018 Responsibility for Review: Director of Administration, Contracts and Health Next Review: September 2019 Internal Approval: & Safety SLT Originated:

More information

GDPR Privacy notice for Students

GDPR Privacy notice for Students GDPR Privacy notice for Students What is the purpose of this document? Solent Students Union is committed to protecting the privacy and security of your personal information. Solent Students Union is a

More information

Regulates the way data controllers process personal data

Regulates the way data controllers process personal data GUIDANCE NOTE ON THE DATA PROTECTION ACT 1998 This guidance note gives an overview of how the Data Protection Act 1998 (the Act ) applies to clubs (including class associations) and recognised training

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

Breaking the myth How your marketing activities can benefit from the GDPR December 2017

Breaking the myth How your marketing activities can benefit from the GDPR December 2017 www.pwc.be Breaking the myth How your marketing activities can benefit from the GDPR December 2017 1. Introduction As opposed to a widespread belief, the GDPR aims to reinforce customers rights, whilst

More information

The template uses the terms students / pupils to refer to the children or young people at the institution.

The template uses the terms students / pupils to refer to the children or young people at the institution. This document is for advice and guidance purposes only. It is anticipated that schools / colleges will use this advice alongside their own data protection policy. This document is not intended to provide

More information

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY Member of staff responsible Head teacher Governor responsible Chair of LGB & DPO Date

More information

W h i t t l e s C h a r t e r e d A c c o u n t a n t s

W h i t t l e s C h a r t e r e d A c c o u n t a n t s PRIVACY NOTICE 1. PURPOSE OF THIS NOTICE This notice describes how we collect and use personal data about you, in accordance with the General Data Protection Regulation (GDPR), the Data Protection Act

More information

Thrive under the GDPR

Thrive under the GDPR Unlock greater opportunity with your data Contents Introduction...03 Why can Experian help?...03 Experian s GDPR package...04 Data Cataloguing Sensitive data landscape...05 Data Integrity Quality and integrity

More information

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk Session 1 Asset Management and Risk Control Forum GDPR Threat or Opportunity? BVRLA Asset Management & Risk Control Forum 19 April 2018 Introduction Personal data is an invaluable asset and many organisations

More information

Nissa Consultancy Ltd Data Protection Policy

Nissa Consultancy Ltd Data Protection Policy Nissa Consultancy Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments (DPIA)

More information

General Data Protection Regulation ( GDPR ) National Care Forum How Boards Manage GDPR Compliance & Risks. By Meena Lekhi, Associate

General Data Protection Regulation ( GDPR ) National Care Forum How Boards Manage GDPR Compliance & Risks. By Meena Lekhi, Associate General Data Protection Regulation ( GDPR ) National Care Forum How Boards Manage GDPR Compliance & Risks By Meena Lekhi, Associate Agenda Background What are the risks? GDPR checklist Steps for trustees

More information

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER Contents 1 Introduction 2 2 Key messages 3 3 The requirement to appoint a Data Protection Officer 4 3.1 Public

More information

The Growth Company Group Privacy Notice

The Growth Company Group Privacy Notice The Growth Company Group Privacy Notice Version May 2018 INTRODUCTION Welcome to The Growth Company s privacy notice. We recognise the importance of the privacy and the security of your personal information

More information

TradeTracker: Preparing for GDPR

TradeTracker: Preparing for GDPR TradeTracker: Preparing for GDPR At TradeTracker, privacy and data protection is important to us. The new General Data Protection Regulation (GDPR) is set to significantly change the data protection landscape

More information

DriveTech (UK) Limited, trading as DriveTech and DriveTech International

DriveTech (UK) Limited, trading as DriveTech and DriveTech International Page 1 DriveTech (UK) Limited, trading as DriveTech and DriveTech International Privacy Notice This privacy notice lets you know what happens to any personal data that you give to us, or any that we may

More information

Complete Funding Solutions Limited Privacy Notice

Complete Funding Solutions Limited Privacy Notice Complete Funding Solutions Limited Privacy Notice Who we are Complete Funding Solutions Limited (company number: 10619210) which is an independent Finance Broker based at Windle Hall Farm, Crank Road,

More information

Data Protection Policy

Data Protection Policy Data Protection Policy General Data Protection Regulations (GDPR) Document control Version control / history Note: This policy requires to be reviewed at least annually from the publication of the last

More information

Recruitment Privacy Notice

Recruitment Privacy Notice Recruitment Privacy Notice Core Notice... 1 Our commitment to your privacy... 1 How we use your information?... 1 Personal data what we hold and why we process it... 1 Legal grounds for processing personal

More information

General Data Protection Regulation. What should community energy organisations be doing to prepare?

General Data Protection Regulation. What should community energy organisations be doing to prepare? General Data Protection Regulation What should community energy organisations be doing to prepare? The implementation date of 25 May 2018 for the General Data Protection Regulation (GDPR) is fast approaching.

More information

Hendre Infants School DATA PROTECTION POLICY. Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris

Hendre Infants School DATA PROTECTION POLICY. Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris Hendre Infants School DATA PROTECTION POLICY Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris Data Protection Policy OBJECTIVES Administration and delivery of quality services involves processing

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information