Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Similar documents
General Data Privacy Regulation: It s Coming Are You Ready?

EU GENERAL DATA PROTECTION REGULATION

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

General Personal Data Protection Policy

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

The (Scheme) Actuary as a Data Controller

GDPR. Guidance on Employee Personal Data

The Sage quick start guide for businesses

Preparing for the General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation

EU General Data Protection Regulation (GDPR)

EU-GDPR and the cloud. Heike Fiedler-Phelps January 13, 2018

Guidance on the General Data Protection Regulation: (1) Getting started

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

ARTICLE 29 DATA PROTECTION WORKING PARTY

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

GDPR Webinar : Overview & practical compliance steps. 23 October 2017

How employers should comply with GDPR

The General Data Protection Regulation: What does it mean for you?

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry

Data Privacy Bootcamp: GDPR

Contents. Introduction 1. Territorial scope 3. Supervisory authority 4. Data governance and accountability 5. Export of personal data 14

GDPR Compliance Checklist

What is GDPR and Should You Care?

TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION

New General Data Protection Regulation - an introduction

The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner,

Accelerate Your Response to the EU General Data Protection Regulation (GDPR) with Oracle Cloud Applications

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only.

EU General Data Protection Regulation (GDPR) Point of View for ERP and HRMS Operations. For private circulation only.

Preparing for GDPR 27th September, Reykjavik

THE EU GENERAL DATA PROTECTION REGULATION AND INTERNATIONAL AIRLINES SPECIAL UPDATE

WSGR Getting Ready for the GDPR Series

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

EU data protection reform

Lisbon, 17 May Agustín Puente Escobar State Counsel Head of the Legal Cabinet. Agencia Española de Protección de Datos

The General Data Protection Regulation An Overview

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Mind the Gap: GDPR Ahead. Rakesh Sancheti. Author. July Vice President and Business Head - Analytics, Europe and Nordic

GDPR Webinar 4: Data Protection Impact Assessments

Organisational Readiness for the European Union General Data Protection Regulation (GDPR)

ARTICLE 29 Data Protection Working Party

The EU General Data Protection Regulation

The Top 10 Operational Impacts of the EU s General Data Protection Regulation

General Data Protection Regulation. The changes in data protection law and what this means for your church.

Data protection in light of the GDPR

New EU-GDPR: Challenges for Universities and Research Organisations

General Data Protection Regulation

Data Flow Mapping and the EU GDPR

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

GDPR. The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council 27 April

Getting Ready for the. General Data Protection Regulation GDPR. A Guide by Mason Hayes & Curran. Dublin, London, New York & San Francisco. MHC.

GDPR - HOW IS INDUSTRY ADDRESSING THE LEGISLATION

Getting Ready for the GDPR

AmCham s HR Committee s

COMPLIANCE WITH THE EU S GENERAL DATA PROTECTION REGULATION AND US DISCOVERY LAW. By: Miriam C. Beezy and Stephanie A. Lucas

Privacy governance survey. The state of privacy management in Belgian organisations

CANDIDATE DATA PROTECTION STANDARDS

GDPR A Catalyst to Drive Real Action around Privacy and Security

GDPR: keeping data processing records

Parliament of Romania Chamber of Deputies Committee for information technologies and communications

General Optical Council. Data Protection Policy

The New EU General Data Protection Regulation and its Consequences for IT Operations and Governance

General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance.

The EU General Data Protection Regulation. allenovery.com

GDPR, What s in it for you?

The Proposed Digital Content Directive and its Implications for the Data Economy

GDPR: Is it just another strict regulation or a great opportunity for operational excellence?

WORLD MEDIA GROUP THE IMPLICATIONS OF GDPR FOR THE ADVERTISING INDUSTRY

The new EU data protection Regulation: The business opportunity beyond legal compliance. Kalliopi Spyridaki Chief Privacy Strategist, Europe

The Data Protection Regulation for Europe

A questionnaire for senior management

QuickLaunch University Webinar Series Data Privacy and GDPR Is Your Startup Ready?

AUDITING AND ENFORCEMENT AT THE SPANISH DPA. EXPERIENCE WITH OUTSOURCING TO COUNTRIES WITH A NON ADEQUATE LEVEL OF PROTECTION

ECDPO 1: Preparing for the EU General Data Protection Regulation

In partnership with. GDPR for marketers: The essentials

Project Agreements, Risk Management and Litigation Risk Sean Ralph, General Counsel, Sasol Canada Phil Scheibel, Partner, Rose LLP

PERSONAL DATA SECURITY GUIDANCE FOR MICROENTERPRISES UNDER THE GDPR

Rexel Shredding. Why a paper security policy is integral to GDPR compliance.

General Data Protection Regulation (GDPR) Meeting the new requirements

A Parish Guide to the General Data Protection Regulation (GDPR)

DATA PROTECTION AUTHORITY IN POLAND

The draft General Data Protection Regulation

GDPR Best Practices Implementation Guide. Transforming GDPR Requirements into Compliant Operational Behaviours

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER

Committee on Civil Liberties, Justice and Home Affairs WORKING DOCUMENT. Committee on Civil Liberties, Justice and Home Affairs

General Data Protection Regulation (GDPR) Strategy

The operational consequences of new EU data protection regulation In a SAP user access management context

2 nd Quarter, 2017 Q Zachodniopomorskie Province

Achieving GDPR Compliance with Avature

Quality Assurance Agreement

CENTRE FOR INFORMATION POLICY LEADERSHIP RESPONSE

Webinar: Deep Dive into the Role of the DPO under the GDPR

Preparing for GDPR. Frequently Asked Questions & Answers. July July Clearswift 2016

SIGBI DATA PROTECTION PROTOCOLS 2018

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

KRONOS WORLDWIDE, INC. SAFE HARBOR PRIVACY POLICY Effective December 1, 2009 Amended and Restated as of July 20, 2012

General Data Protection Regulation Key News

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER

Working toward GDPR compliance. Insights from a SAS survey and an end-to-end approach

Transcription:

Dealing with the EU Data Protection Regulation in Practice William Long, Partner Sidley Austin LLP February 11, 2016

Do you need to comply? The Regulation will apply to a business processing personal data: (1) in the context of establishments in the EU; or (2) outside the EU where it carries out activities aimed at offering goods or services to individuals in the EU or that monitor individuals. So Regulation will apply to US companies that have personal data on European citizens even if not European business Determine which of your business units will be subject to the Regulation

What are the potential consequences of not complying? Fines of up to the greater of 4% of the annual worldwide turnover (gross revenue) or 20 million for failing to comply with the proposed Regulation Claims by individuals or representative organisations Damages will now be permitted for non-financial loss e.g. for distress One Stop Shop - businesses will be accountable to one single Lead DPA in the EU country where the data controller has its main establishment Determine applicable Lead DPA Carry out gap analysis between existing privacy requirements and those in the Regulation Implement or update privacy program to deal with requirements under the Regulation and to mitigate risk

1. Update privacy notices, consents and policies The Regulation introduces new requirements as to the information that should be provided in notices AND new consent requirements The Regulation also sets out limited legal grounds for which personal data may be processed Review and amend existing employee and customer data privacy notices, consents and policies Determine legal grounds that can be used for processing of personal data and if consent, how it will be obtained in line with Regulation

2. Keep detailed data records The Regulation requires businesses to have clear and accessible policies and maintain a detailed record of processing activities The records must be provided to the DPA upon request Carry out data flow analysis and document the internal use of personal data by the business to meet accountability principles under the Regulation

3. Assess compliance with accountability principles A business must appoint a data protection officer where: the processing involves large amounts of sensitive personal data (e.g. health data) the processing involves regular monitoring of individuals it is required by Member State law Privacy impact assessments must be carried out where data processing uses new technologies and is likely to result in a high risk to individuals (e.g. Profiling or the processing of health data on a large scale) Determine if required to appoint a DPO single or multiple DPO(s)? internal or external? Develop a procedure to ensure accountability measures including carrying out privacy impact assessments where required under the Regulation

4. Review IT systems and procedures The Regulation introduces the concept of privacy by design and by default Requirement to implement technical and organisational measures to ensure data protection requirements are met AND to ensure that by default only the minimum amount of personal data are processed Carry out a review of IT Systems and procedures to consider impact of privacy by design and data minimization requirements

5. Information security and reporting security breaches Requirement to implement appropriate technical and organisational measures, to ensure a level of security appropriate to the risk including, e.g., pseudonymization and encryption of data and regular assessments as to the efficacy of the measures Security breaches must be reported to the DPA without undue delay and where feasible within 72 hours after becoming aware of breach Security breaches that involve high risk must also be reported to affected individuals without undue delay unless measures taken to minimize risk, e.g. the data is encrypted Review and update information security standards and implement a process for regular information security audits Develop a data breach response plan and reporting procedures

6. Review arrangements with vendors The Regulation introduces new requirements and liabilities for data processors (e.g. vendors) New obligations to be included in the processing agreement Prior specific consent must be given by controller where vendor appoints subcontractor and subcontractor must comply with the same data privacy obligations as vendor Conduct a review of vendor agreements to ensure appropriate data privacy provisions are included as well as provisions dealing with liability and security breach reporting Consider implementing a vendor management program with vendor questionnaire, minimum security requirements and regular vendor audits

7. Dealing with individuals new privacy rights Right to erasure a business is obligated to erase an individual s personal data where, for example, the data is no longer necessary for the purpose for which it was obtained or consent is withdrawn Right to object to processing an individual has a right to object to the use of their personal data including in relation to direct marketing Right to data portability an individual has a right to request the transfer of their personal data from one service provider to another where the data is processed in a machine-readable, structured and commonly-used format and the processing is based on consent or on the performance of a contract with the individual Determine how the new data privacy rights apply to your business and develop policies and procedures, and if necessary system changes, to deal with these new rights

8. Review profiling activities The Regulation introduces new restrictions on businesses carrying out profiling which produces legal effects or significantly affects an individual subject to exceptions such as, where: this is necessary for the performance of a contract it is authorized by national Member State law it is conducted with the explicit consent of the individual Review current profiling activities and determine whether profiling is covered by an exception Where appropriate amend profiling activities to ensure compliance with the Regulation Review consents and notices to deal with profiling

9. Review international data transfers Restriction on transfers of personal data outside the EEA to jurisdictions that do not provide adequate safeguards. Data transfer solutions include: the recently announced EU-US Privacy Shield (if agreed!) EU Standard Contractual Clauses and Binding Corporate Rules (but currently being evaluated by Article 29 Working Party) approved Codes of Conduct or Certification Mechanisms Determine international data flows based on reviews of processing activities Consider international transfer solutions and review whether current solutions are adequate particularly in light of recent developments on EU-US Privacy Shield

William Long wlong@sidley.com http://www.sidley.com/services/infolaw