The General Data Protection Legislation: a challenge for the Internal Auditor

Similar documents
COSO Framework: A Practical Application

2 nd Joint Conference. Date Friday, 29 January 2016 Time 13:00 to 16:30 Venue Corinthia Palace Hotel, Attard CPE 2.5 hours Fee EUR45.

EU General Data Protection Regulation (GDPR)

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction

December 28, 2018, New Delhi, INDIA

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law.

The GDPR enforcement deadline is looming are you ready?

The ICT Service:

NOT PROTECTIVELY MARKED

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

The GDPR: What does it mean for executive search?

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1

ARTICLE 29 DATA PROTECTION WORKING PARTY

Committee on Civil Liberties, Justice and Home Affairs WORKING DOCUMENT

GENERAL DATA PROTECTION REGULATION.

Preparation Guide to the New European General Data Protection Regulation

CNPD Training: Data Protection Basics

New General Data Protection Regulation - an introduction

GDPR in Early Years and Childcare settings. What s the connection? Data Protection

WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR)

Shop Floor Retail Bootcamp

Boral Limited Audit & Risk Committee Charter

CPD at CPD (CLASSROOM & ONLINE) ACCA CIMA ACA CPA DIP IFR (CLASSROOM & ONLINE)

More information at cventconnect.com/europe/mobileapp

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

A PRACTICAL APPROACH TO AUDIT PLANNING AND RISK ASSESSMENT. COURSE FEE: 100 inc. VAT LECTURE DATES: 27TH APRIL &11TH MAY 2018 TIME:

GDPR: What Every MSP Needs to Know

GDPR - 10 THINGS YOU NEED TO KNOW (US PERSPECTIVE) 1. Privacy and data protection are fundamental rights

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation?

Data Protection Policy

OFFICE OF THE DATA PROTECTION COMMISSIONER. Official Languages Act Language Scheme

EU General Data Protection Regulation (GDPR) A Point of View. For private circulation only. Risk Advisory

D M K L a w y e r s C e n t r a l L a w

***I REPORT. EN United in diversity EN. European Parliament A8-0226/

ECDPO 1: Preparing for the EU General Data Protection Regulation

PwC s Annual IFRS Update 2018

Continuing Professional Education CPE Regulations

NEWSFLASH GDPR N 10 - New Data Protection Obligations

The General Data Protection Regulation (GDPR)

A guide to GDPR the effect on all UK organisations

The implications of the EU General Data Protection Regulation 2016 for ICT Disposal

ICO s DP Regulatory Action Policy details the guiding principles supporting decisions on enforcement.

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

Professional Standards Authority for Health and Social Care. A guide to the information available under the Freedom of Information Publication Scheme

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY

General Data Protection Regulation - Explained

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only.

How employers should comply with GDPR

Regulates the way data controllers process personal data

Accountability under the GDPR: What does it mean for Boards & Senior Management?

ARTICLE 29 Data Protection Working Party

Employment Equity Committee Master Conference 2018

Introduction. Key points of the recent ODPC guidance, and the Article 29 working group guidance

Call for tender for translation services for the Translation Centre Frequently asked questions (FAQs) FL/LEG17

ECDPO 1: Preparing for the EU General Data Protection Regulation

The General Data Protection Regulation (GDPR)

GDPR factsheet Key provisions and steps for compliance

EU General Data Protection Regulation (GDPR) Point of View for ERP and HRMS Operations. For private circulation only.

Advanced Compliance & AML Seminar

COMPREHENSIVE LEGAL, TAX, ACCOUNTING AND AUDIT SERVICES

Summary of General Data Regulation & Actions. Nationwide Coverage.

WORLD REPORT >>> DATA PROTECTION

Committee on Civil Liberties, Justice and Home Affairs. of the Committee on Civil Liberties, Justice and Home Affairs

Summary of General Data Regulation & Actions. Nationwide Coverage.

GDPR Factsheet - Key Provisions and steps for Compliance

General Data Protection Regulation (GDPR) New regulation for the protection of data

Data Flow Mapping and the EU GDPR

IBM Collaboration Solutions Readiness for GDPR IBM Corporation

GDPR 5 things HR Must Do! YEARN2LEARN TRAINING, GILLIAN ACHESON, DEIRDRE ALLISON

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

Effective Quality Oversight of Pharmaceutical Contract Manufacturing Organizations (CMOs)

European Union Recruitment Privacy Policy

Breaking the myth How your marketing activities can benefit from the GDPR December 2017

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

Re: Implementation of the General Data Protection Regulation (GDPR)

Municipal Administration

JOB TITLE: Head of Risk and Governance and Data Protection Officer. REPORTS TO: Director of Corporate Affairs and Governance

GDPR Compliance Services. Data Privacy and Security Management Services

DECISION No on the

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data

EU General Data Protection Regulation (GDPR)

Discussion Paper on innovative uses of consumer data by financial institutions

What do companies need to do?

Data protection (GDPR) policy

GDPR - Salon Guide Contents

Effective Quality Oversight of Pharmaceutical Contract Manufacturing Organizations (COM) COURSE DESCRIPTION

What does the GDPR mean for recruitment?

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients

GDPR Service Information Sheet

Pursuant to Convention No. 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data;

Continuing Professional Education

c) to consider at a meeting of Council in early 2015 a LLP Partnership Agreement to include the following governance arrangements:

Risk Based Approach ISO 9001:2015 Internal Auditor Training

Introduction to the General Data Protection Regulation (GDPR)

Achieving GDPR Compliance with Avature

9 Ways Accountants Can Prepare for GDPR

INFORMATION TO BE GIVEN 2

Transcription:

The General Data Protection Legislation: a challenge for the Internal Auditor Date: 24 May 2017 Time: 13:30 (registration) till 16:30. Venue: Radisson Blu Sea Resort, St Julian s Price: EUR30 (Students EUR15) CPE: 2.0 hours CPE (Professional Competency)

About MFIA The Malta Forum for Internal Auditors is a not-for-profit organisation, set up by local professionals in the field to promote awareness about the role of internal auditing in the local business and non-business community, to support education about the profession and to provide appropriate networking opportunities for both peers and professionals in the field, students and executives. For more information visit the MFIA website: http://www.fiamalta.org

EU General Data Protection Regulation The Subject. The EU s General Data Protection Regulation ( GDPR ), which took 4 years of preparation and debate, is being touted as the most important change in data privacy regulation in 20 years (www.eugdpr.org). The GDPR was approved by the EU Parliament on 14 April 2016 and will come into force on 25 May 2018. The key changes to the legal requirements around data privacy arising from the coming into effect of this Regulation are: Increased Territorial Scope: applies to all companies processing the personal data of data subject residing within the European Union, regardless of the companies location; Penalties: organisations in breach of the Regulation can be fined a maximum of 20 million or 4% of global turnover (whichever is higher); Consent: consent must be clear and distinguishable from other matters and provided in an intelligible and easily accessible form, using clear and plain language. It must be as easy to withdraw consent as it is to give it. The Seminar. As internal auditors we should be ensuring that our organisations are prepared for the changes that will be brought about by this Regulation. Mr Ian Deguara will delve into the requirements emanating from the Regulation. After a networking break, Mr George Sammut will go through the steps that organisations need to take to adhere to the GDPR as well as set out the Internal Audit function s role in ensuring adherence to this regulation.

A biographical note on the Speakers Ian Deguara. Ian is Director Technical Affairs, within the office of the Information and Data Protection Commissioner. He was one of the first employees to join the Office of the Commissioner in December 2002 after successfully completing his studies at the University of Malta, where he obtained a degree in computing and in management. His first tasks were to assist the Commissioner on capacity building and on the implementation of the new set of rules which introduced fundamental rights to data subjects and imposed obligations on data controllers. At the time, the careful implementation of structured efforts was indeed necessary to bring along a smooth culture change in the manner personal data were processed by both the public and private sectors. During the years, Ian has acquired a level of expertise in data protection. Currently, he holds the position of Director where his main areas of responsibility include the taking care of general administrative matters, investigating complaints relating to both data protection and freedom of information, advising the Commissioner on various local and European data protection issues, conducting on-site inspections and investigations, actively participating in European working groups on data protection and devising the necessary strategies to implement the new data protection legal framework (GDPR) which shall apply as from 25 May 2018. George Sammut. George is a partner at PwC leading Governance Risk and Compliance advisory services. He has many years experience in Data Protection legislation and practical implementation, handling assignments for clients in various business sectors and involving multiple territories. He presented a series of seminars to over 300 delegates since the year when the Data Protection Act was introduced in Malta and more recently to over 100 Data Protection Officers anticipating the obligations of the General Data Protection Regulation. For almost 9 years, George was one of the three members of the Data Protection Appeals Tribunal that heard and adjudicated appeals against judgements by the Commissioner and others. He has a BSc (Honours) degree in Data Processing, is a Qualified Accountant, a Chartered Engineer, a member of the British Computer Society, a member of the Institute of Financial Accountants, Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Controls (CRISC). He sits on the executive board of the Malta IT Law Association.

Registration Form Name: Company: Job Position: Email: Mobile No.: I am enclosing a payment of EUR30 (Students EUR15) to attend the Malta Forum for Internal Auditors training session The General Data Protection Legislation: a challenge for the Internal Auditor Signature Date Ideally payments are made by bank transfer to IBAN no. MT67VALL22013000000040019433628, indicating your name and organisation in the payment details. Cheque payments may also be made and are to be addressed to MFIA, PO Box 10, Birkirkara. Payment is to reach MFIA by 19 May 2017. Email: info@fiamalta.org