GDPR: keeping data processing records

Similar documents
CNPD Training: Data Protection Basics

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law.

EU General Data Protection Regulation (GDPR)

ARTICLE 29 Data Protection Working Party

What do companies need to do?

GDPR is coming in 108 days: Are you ready?

Whitepaper. What are the changes regarding data protection. in the future. General Data Protection Regulation? eprivacy GmbH, Hamburg, April 2017

December 28, 2018, New Delhi, INDIA

Preparing Your Vendor Agreements for the General Data Protection Regulation

Preparing for the GDPR

Top 10 Data Protection Do s & Don ts in M&A

Call-Off Contract. Legal Consultancy Services Framework Call-Off Number DCCT0012 Legal consultancy on GDPR. Version: V1.0

General Data Protection Regulation (GDPR)

GENERAL DATA PROTECTION REGULATION Guidance Notes

briefing GDPR: cross-border perspectives Overview

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

NEWSFLASH GDPR N 10 - New Data Protection Obligations

One unified law that applies directly to all EEA member states. Text of the Regulation -

GENERAL DATA PROTECTION REGULATION

GDPR: AN OVERVIEW.

PRIVACY STATEMENT Date: 25 May 2018

ARTICLE 29 DATA PROTECTION WORKING PARTY

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

European Data Privacy Notice Applicants. Effective date: 14 th February Information that we use

Data Flow Mapping and the EU GDPR

Paul Jordan Thursday 12 October,

Data Protection, Privacy & Cyber Security Compliance

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

PRIVACY STATEMENT Date: 25 May 2018

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1

EU General Data Protection Regulation in the digital age: Are you ready?

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities

Preparing for the General Data Protection Regulation (GDPR)

New EU General Data Protection Regulation: we can help you get ready!

GDPR factsheet Key provisions and steps for compliance

What is GDPR and Should You Care?

General Data Protection Regulation Guide

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR General Data Protection Regulation

General Personal Data Protection Policy

General Data Protection Regulation

GDPR journey: from ready to compliant GDPR survey results

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

General Data Protection Regulation. Jim Sneddon GDPR-P, CISSP

How employers should comply with GDPR

Tourettes Action Data Protection Policy

GDPR Readiness: Role of the DPO

ARTICLE 29 DATA PROTECTION WORKING PARTY

The General Data Protection Regulation: What does it mean for you?

DATA PROTECTION OFFICER (DPO) Maria Maxim Partner Bucharest October 25, 2017

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR)

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily.

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond

More information at cventconnect.com/europe/mobileapp

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018

The General Data Protection Regulation (GDPR)

Preparing for the GDPR Orla O Hannaidh - Womble Bond Dickinson

New Data Protection & Privacy Regulations in the EU. March 7, 2018

European Union General Data Protection Regulation 25 th May 2018

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

GDPR & SMART PIA. Wageningen University Feb 2017

The Sage quick start guide for businesses

Genera Data Protection Regulation and the Public Sector

Privacy Policy 2018 VERSION 1.0

DATA PROTECTION POLICY

GDPR Compliance Checklist

Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd

Data Breach Prevention & Response

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk

ARTICLE 29 Data Protection Working Party

Webinar: Deep Dive into the Role of the DPO under the GDPR

GDPR SMART. The Neopost Guide to Managing GDPR. ermissions Personal Data Right of Access. nal Data Right of Access Consent Permissi

Summary of General Data Regulation & Actions. Nationwide Coverage.

DATA PROTECTION POLICY

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY

Summary of General Data Regulation & Actions. Nationwide Coverage.

The Privacy Battlefield What does the GDPR Require?

What in the World is GDPR? Imran Ahmad, Partner Miller Thomson LLP

Agenda. What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance

The General Data Protection Regulation (GDPR)

What does the GDPR mean for recruitment?

Technical factsheet: General Data Protection Regulation (GDPR) April 2018

Data Protection Policy. UK Policy May 2018

Firm Creobis, Berchem, results 7 March 2017

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

EU General Data Protection Regulation: Are you ready?

GDPR Compliance Services. Data Privacy and Security Management Services

General Data Protection Regulation

Committee on Civil Liberties, Justice and Home Affairs WORKING DOCUMENT. Committee on Civil Liberties, Justice and Home Affairs

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

PREPARING FOR THE GENERAL DATA PROTECTION REGULATION. SELF-ASSESSMENT QUESTIONNAIRE Data Controllers

Transcription:

GDPR: keeping data processing records Fit4DataProtection

Keeping data processing records under the GDPR 1. Why? 2. Who? 5. 3. 4. What? How? Sanctions? 6. What can we recommend?

1. Why? new data quality principle of accountability : not sufficient to be compliant, compliance must be proven records must be kept and made available to competent data protection authority on request prior notification/authorisation requirements : replaced by records in order to demonstrate the compliance of a processing afterwards ~ registers of DPOs under the Lux 2002 Data Protection Act

2. Who? (virtually all) data controllers and processors exception for enterprises/organisations < 250 employees, BUT not if: processing with a risk to the rights and freedoms of data subjects the processing is not occasional (e.g., CRM, HR, supplier management), the processing includes special categories of data (health data, political preference, ) or personal data relating to criminal convictions and offences.

3. What? Lux 2002 Act GDPR Controller (notification / DPO register) Processor Controller Processor name and contact details legitimate basis of processing purposes of the processing categories of data / persons concerned categories of recipients transfer to non-eu/eea countries general description of security measures time limits for erasure categories of processing (except for DPO register)

4. How? written / including in electronic format no other requirement implicitly: per type/category of processing per business stream + further subdivisions if needed existing CNPD notification forms can help inventory of past processing activities relevant categories of processing, purposes and data but a more comprehensive prior data mapping ( as is + future projects) gap analysis and remediation are needed from simple over more developed excel sheets to more developed software based tools integrating the previous phases of data mapping and gap analysis and remediation

5. Sanctions? administrative fine up to 10.000.000 EUR or, in the case of an undertaking, up to 2% of the global annual turnover worldwide, whichever amount is the highest

6. What can we recommend? do not see the record as just another obligation it is the cornerstone of each organisation s GDPR compliance it is the logical end point of a GDPR gap analysis and remediation any other privacy relevant documents (privacy notice, contracts, ) should be checked against the content of the record therefore do not hesitate to include in the record other types of useful information (e.g., legitimate basis for processing) do not forget that the record is basically a summary of all relevant processing activities to the attention of the competent authorities and that the accountability principle potentially requires to demonstrate compliance with the GDPR in a greater detail!

How can NautaDutilh help? GDPR awareness trainings audit / impact assessment legal assessment compliance gap DPO external DPO servicing data record lawful basis / consent data subjects rights data breaches legal advice (e.g. definition of scope re personal data, adequacy of purpose description) legal assessment invoked legal basis / draft consent language draft privacy notices / legal assessment scope other rights draft notifications / assistance in contacts with authorities

transfers outside EU / EEA How can NautaDutilh help? processing agreements assessment legality transfer / legal assistance in implementing safeguards (SCC / BCR) draft / amend / negotiate processing relevant agreements authorities / courts increasing number of contentious cases to be expected! assisting clients in administrative proceedings before the authority before the competent courts

Questions? At your disposal! Vincent Wellens Partner, Technology law & data protection T. + 352 26 12 29 34 E. Vincent.Wellens@nautadutilh.com Faustine Cachera Associate, Technology law & data protection T. +352 26 12 29 74 12 E. Faustine.Cachera@nautadutilh.com Carmen Schellekens Senior Associate, Technology law & data protection T. +352 26 12 29 74 06 E. Carmen.Schellekens@nautadutilh.com Anne-Sophie Morvan Associate, Technology law & data protection T. +352 26 12 29 74 15 E. Anne-Sophie.Morvan@nautadutilh.com Barbara Giroud Associate, Technology law & data protection T. +352 26 12 29 74 27 E. Barbara.Giroud@nautadutilh.com 11

A brief presentation of our firm Firm profile Number of partners, associates and other legal staff. An international law firm practising Dutch, Belgian, Luxembourg and Dutch Caribbean law, founded in 1724. One of the largest law firms in the Benelux region: o 388 lawyers including 72 partners, including 14 female partners. o 10 of our lawyers are also university professors. Spread across 6 offices and 5 country desks: Offices in Amsterdam, Brussels, London, Luxembourg, New York and Rotterdam. Our country desks focus on: Germany, France, India, China and Japan. We also monitor growth markets such as Brazil, Mexico, Indonesia, South Korea and Turkey. An independent firm with non-exclusive relations with the top law firms in more than 80 countries. Office locations NautaDutilh The Netherlands Belgium Luxembourg United Kingdom (rep. office) United States of America (rep. office) Beethovenstraat 400 1082 PR Amsterdam T +31 20 717 10 00 F +31 20 717 11 11 Weena 800 3014 DA Rotterdam T +31 10 224 00 00 F +31 10 414 84 44 Chaussée de la Hulpe 120 B-1000 Brussels T +32 2 566 80 00 F +32 2 566 80 01 2, rue Jean Bertholet L-1233 Luxembourg T +352 26 12 291 F +352 26 68 43 31 2 Copthall Avenue London EC2R 7DA T +44 20 7786 9100 F +44 20 7588 6888 One Rockefeller Plaza NY 10020 New York T +1 212 218 2990 F +1 212 218 2999 12