SlideShare a Scribd company logo
Preparing for the GDPR
How to comply
Introduction to GDPR
UK privacy history
What is GDPR?
1995
1998
2009
2012
2018
First EU
Data
Protection
Directive
Data
Protection Act
First public consultation
with view to revise
European data
protection framework
First draft of
the GDPR
GDPR
comes into
force
• Trust
• Consumer control
• Transparency
Why is GDPR being enforced?
GDPR fines & penalties
Not complying can cost your business up to
€20million or 4% of the company’s annual
worldwide turnover (whichever is higher).
Fines & penalties
hello
Fines & penalties
• Sent 3.3 million emails under the title ‘Are your
details correct?’ to people who didn’t sign up to
marketing material.
• Fined £70,000 in March 2017.
hello
Fines & penalties
• Sent 289,790 emails clarifying whether
customers who hadn’t signed up
wanted to receive marketing
• Fined £13,000 in March 2017
GDPR consumer statistics
Trust in Personal Data: A UK Review
• 96% of respondents claim to understand the
term ‘personal data’ but less than 64% picked
the correct definition
• 79% of consumers believe the primary use of
personal data is for an organisations financial
gain
• 65% of consumers are unsure if data is being
shared without their consent
Trust in Personal Data: A UK Review
Trust in Personal Data: A UK Review
6 key updates
1. Lawfulness, fairness & transparency
2. Purpose limitation
3. Data minimisation
4. Accuracy
5. Storage limitation
6. Security
6 key updated principles from the
Data Protection Act
Individual’s rights & special
categories of data
The GDPR provides the following
rights for individuals:
1. The right to be informed
2. The right of access
3. The right to erasure
4. The right to object
5. Rights in relation to automated
decision making and profiling
6. The right to rectification
7. The right to restrict
processing
8. The right to data portability
The right to erasure: case study
• hi
Mario Costeja
González
Warning: Special categories of data
l
1. Racial or ethnic origin
2. Political opinions
3. Religious / philosophical beliefs
4.Trade union membership
5. Genetic data
6. Biometric data
7. Data containing health or sex life
8. Sexual orientation
9. Criminal data
Consent
Every submission of personal data must be:
• Freely given
• Specific
• Informed
• Unambiguous
Consent
Consent shouldn’t include:
• Pre-ticked boxes
• Assumptions
• Conditional consent
Consent
How do you persuade consumers to share
their data?
• Offer incentives
• Be completely clear on what
the consumer will receive
• Be completely clear on storage details
and who the information will be shared with
The consent challenge
The GDPR defines valid consent as
unambiguous, affirmative consent.
Consent
The consent challenge: Incentives
The consent challenge
Come up with an incentive to
encourage sign ups to
your mailing list
Can we still use a pre-ticked
box as consent?
Consent Q&A
No, GDPR doesn’t class a pre-ticked
box or any form of inactivity as valid
consent. The data subject must make
an affirmative action for
their consent to be valid.
What is the best way to gain valid consent
if purchasing a product or service?
Consent Q&A
The best way to ensure that you’re fully
compliant with the GDPR is to include a
separate opt-in option at the point a
consumer joins/purchases by
encouraging them to sign up to
receive updates via email.
We’ve got historic lists –
will they still be valid?
Consent Q&A
If your current data hasn’t specifically
been collected using affirmative consent
for all activities, or you don’t have a record
of the details required, then
you’ll have to gain fresh consent.
New database requirements
Database requirements
Organisations must be able to demonstrate that an
individual consented to the processing of
their personal data.
If consent is given
over the phone, you’ll
need a recording
If you collect consent
online, you’ll need to
record consent wording,
time & source
True or false
True or false
GDPR will stop dentists ringing patients
to remind them about appointments
True or false
All personal data breaches will need to
be reported to the ICO.
Existing data
Existing data
Existing data
Credit: Getty
Review your strategy
Data controller vs data processor
Are you a data controller
or data processor?
Data controller - the organisation that collects
personal data and decides how it will be used.
Data processor - the organisation that processes
personal data on behalf of the data controller.
Data controller obligations
• Collects data
• Which items of personal data to collect
• How the data will be used
• Whether to disclose the data, and if so,
who to
• Arranging access
• Storage
Data processor obligations
• To process data fairly
and lawfully
• Data is kept accurate
and up to date
• Data is only kept for
as long as necessary
• Adhere to all agreements in your
contract with the data controller
Data controller or data processor?
A local authority uses a cloud provider to store
data about its housing stock and residents, rather
than holding the data on its own IT system.
The cloud provider is also contracted to delete
certain data after a particular period and to grant
members of the public access to their own
records via a secure online portal.
Data controller or data processor?
An online retailer work in co-operation with a
third-party payment company to process
customers’ transactions.
Data protection officer
The data protection officer (DPO)
A data protection officer is responsible for
overseeing your data protection strategy and
implementation to ensure compliance
with GDPR.
• Inform
• Monitor
• Contact
Who needs a DPO?
x
• Public authorities
• Large scale systematic monitoring of individuals
• Large scale processing of special categories
Any questions?
Thank you
http://cobb.agency/digital | 01273 208 913

More Related Content

PDF
VMTN6642E - GDPR Slide Deck
PPTX
EU General Data Protection Regulation - Update 2017
PPTX
General Data Protection Regulation
PDF
GDPR for Dummies
PDF
What about GDPR?
PPTX
The Practical Impact of the General Data Protection Regulation
PDF
GDPR Basics - General Data Protection Regulation
PPTX
GDPR Presentation slides
VMTN6642E - GDPR Slide Deck
EU General Data Protection Regulation - Update 2017
General Data Protection Regulation
GDPR for Dummies
What about GDPR?
The Practical Impact of the General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
GDPR Presentation slides

What's hot (20)

PPTX
Gdpr action plan
PDF
GDPR Awareness for YOU
PPTX
Gdpr action plan - ISSA
PPTX
The Meaning and Impact of the General Data Protection Regulation
PPTX
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
PPTX
Do You Have a Roadmap for EU GDPR Compliance?
PDF
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
PDF
GDPR Demystified
PPTX
GDPR From Implementation to Opportunity
PPTX
General Data Protection Regulations (GDPR): Do you understand it and are you ...
PPTX
GDPR - Fail to Prepare, Prepare to Fail!
PPTX
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
PPTX
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
PDF
DAMA Ireland - GDPR
PDF
GDPR-Overview
PPTX
Understanding the EU's new General Data Protection Regulation (GDPR)
PDF
The Essential Guide to GDPR
PDF
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
PDF
Modelling the General Data Protection Regulation
PDF
GDPR Cyber Insurance 11/1/2017
Gdpr action plan
GDPR Awareness for YOU
Gdpr action plan - ISSA
The Meaning and Impact of the General Data Protection Regulation
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
Do You Have a Roadmap for EU GDPR Compliance?
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
GDPR Demystified
GDPR From Implementation to Opportunity
General Data Protection Regulations (GDPR): Do you understand it and are you ...
GDPR - Fail to Prepare, Prepare to Fail!
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
DAMA Ireland - GDPR
GDPR-Overview
Understanding the EU's new General Data Protection Regulation (GDPR)
The Essential Guide to GDPR
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
Modelling the General Data Protection Regulation
GDPR Cyber Insurance 11/1/2017
Ad

Viewers also liked (9)

PPTX
Privacy Pitfalls in Transactions
PDF
Managing Personally Identifiable Information (PII)
PPTX
What is identity
PDF
Halt & Catch Fire: Is PII No Longer the Third-Rail of Digital Privacy?
PDF
Identity and Access Management 101
PPTX
Identity and Representation
PPTX
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
PPTX
GDPR: Your Journey to Compliance
Privacy Pitfalls in Transactions
Managing Personally Identifiable Information (PII)
What is identity
Halt & Catch Fire: Is PII No Longer the Third-Rail of Digital Privacy?
Identity and Access Management 101
Identity and Representation
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
GDPR: Your Journey to Compliance
Ad

Similar to Cobb Digital Bitesize workshop - GDPR, are you compliant? (20)

PDF
GDPR changes affect direct marketing
PDF
GDPR - Sink or Swim
PPTX
Reddico GDPR Presentation
PPTX
How will GDPR affect your business - Marketing Fox & Birkett Long
PPTX
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
PDF
Scotland legal update 25 sept
PPTX
SMS and GDPR - what you need to know to be compliant
PPTX
Gdpr zilla
PDF
Opportunity or burden
PPTX
B2: Fundraising in an age of GDPR
PDF
Public sector breakfast club - October 2017, Exeter
PDF
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
PDF
GDPR for your Payroll Bureau
PPTX
GDPR Practicalities - The Data Shed
PPTX
Key marketing impacts of the GDPR - Rosemary Smith, Director, Opt-4
PDF
Gdpr for business full
PDF
GDPR is Coming, Five Things You Can Do Now To Prepare
PDF
What's Next - General Data Protection Regulation (GDPR) Changes
PDF
GDPR Ready Presentation - Marc Michaels
PDF
DMA - DPC Workshop - 23 October 2013
GDPR changes affect direct marketing
GDPR - Sink or Swim
Reddico GDPR Presentation
How will GDPR affect your business - Marketing Fox & Birkett Long
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
Scotland legal update 25 sept
SMS and GDPR - what you need to know to be compliant
Gdpr zilla
Opportunity or burden
B2: Fundraising in an age of GDPR
Public sector breakfast club - October 2017, Exeter
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
GDPR for your Payroll Bureau
GDPR Practicalities - The Data Shed
Key marketing impacts of the GDPR - Rosemary Smith, Director, Opt-4
Gdpr for business full
GDPR is Coming, Five Things You Can Do Now To Prepare
What's Next - General Data Protection Regulation (GDPR) Changes
GDPR Ready Presentation - Marc Michaels
DMA - DPC Workshop - 23 October 2013

Recently uploaded (20)

PDF
5 free to use google tools to understand your customers online behavior in 20...
PPTX
Presentation - MindfulHeal Digital Ayurveda GTM & Marketing Plan.pptx
PDF
Mastering Content Strategy in 2025 ss.pdf
PPTX
Tea and different types of tea in India
PDF
How a Travel Company Can Implement Content Marketing
PDF
Mastering Bulk Email Campaign Optimization for 2025
PPTX
PRINCIPLES OF MANAGEMENT and functions (1).pptx
PPTX
Sumit Saxena IIM J Project Market segmentation.pptx
PPTX
Best Digital marketing service provider in Chandigarh.pptx
PPTX
Your score increases as you pick a category, fill out a long description and ...
PDF
Pay-Per-Click Marketing: Strategies That Actually Work in 2025
PDF
UNIT 1 -4 Profile of Rural Consumers (1).pdf
PDF
How to Break Into AI Search with Andrew Holland
PPTX
Captain Morgan x FOS_Revised_8.8.25.pptx
PDF
UNIT 2 - 5 DISTRIBUTION IN RURAL MARKETS.pdf
DOCX
procubiz_modern digital marketingblog.docx
PDF
Building a strong social media presence.
PDF
SEO vs. AEO: Optimizing for Google vs AI-Powered Search Assistants
PPTX
Kimberly Crossland Storytelling Marketing Class 5stars.pptx
PDF
You Need SEO for Your Business. Here’s Why..pdf
5 free to use google tools to understand your customers online behavior in 20...
Presentation - MindfulHeal Digital Ayurveda GTM & Marketing Plan.pptx
Mastering Content Strategy in 2025 ss.pdf
Tea and different types of tea in India
How a Travel Company Can Implement Content Marketing
Mastering Bulk Email Campaign Optimization for 2025
PRINCIPLES OF MANAGEMENT and functions (1).pptx
Sumit Saxena IIM J Project Market segmentation.pptx
Best Digital marketing service provider in Chandigarh.pptx
Your score increases as you pick a category, fill out a long description and ...
Pay-Per-Click Marketing: Strategies That Actually Work in 2025
UNIT 1 -4 Profile of Rural Consumers (1).pdf
How to Break Into AI Search with Andrew Holland
Captain Morgan x FOS_Revised_8.8.25.pptx
UNIT 2 - 5 DISTRIBUTION IN RURAL MARKETS.pdf
procubiz_modern digital marketingblog.docx
Building a strong social media presence.
SEO vs. AEO: Optimizing for Google vs AI-Powered Search Assistants
Kimberly Crossland Storytelling Marketing Class 5stars.pptx
You Need SEO for Your Business. Here’s Why..pdf

Cobb Digital Bitesize workshop - GDPR, are you compliant?

  • 1. Preparing for the GDPR How to comply
  • 3. UK privacy history What is GDPR? 1995 1998 2009 2012 2018 First EU Data Protection Directive Data Protection Act First public consultation with view to revise European data protection framework First draft of the GDPR GDPR comes into force
  • 4. • Trust • Consumer control • Transparency Why is GDPR being enforced?
  • 5. GDPR fines & penalties
  • 6. Not complying can cost your business up to €20million or 4% of the company’s annual worldwide turnover (whichever is higher). Fines & penalties
  • 7. hello Fines & penalties • Sent 3.3 million emails under the title ‘Are your details correct?’ to people who didn’t sign up to marketing material. • Fined £70,000 in March 2017.
  • 8. hello Fines & penalties • Sent 289,790 emails clarifying whether customers who hadn’t signed up wanted to receive marketing • Fined £13,000 in March 2017
  • 10. Trust in Personal Data: A UK Review
  • 11. • 96% of respondents claim to understand the term ‘personal data’ but less than 64% picked the correct definition • 79% of consumers believe the primary use of personal data is for an organisations financial gain • 65% of consumers are unsure if data is being shared without their consent Trust in Personal Data: A UK Review
  • 12. Trust in Personal Data: A UK Review
  • 14. 1. Lawfulness, fairness & transparency 2. Purpose limitation 3. Data minimisation 4. Accuracy 5. Storage limitation 6. Security 6 key updated principles from the Data Protection Act
  • 15. Individual’s rights & special categories of data
  • 16. The GDPR provides the following rights for individuals: 1. The right to be informed 2. The right of access 3. The right to erasure 4. The right to object 5. Rights in relation to automated decision making and profiling 6. The right to rectification 7. The right to restrict processing 8. The right to data portability
  • 17. The right to erasure: case study • hi Mario Costeja González
  • 18. Warning: Special categories of data l 1. Racial or ethnic origin 2. Political opinions 3. Religious / philosophical beliefs 4.Trade union membership 5. Genetic data 6. Biometric data 7. Data containing health or sex life 8. Sexual orientation 9. Criminal data
  • 20. Every submission of personal data must be: • Freely given • Specific • Informed • Unambiguous Consent
  • 21. Consent shouldn’t include: • Pre-ticked boxes • Assumptions • Conditional consent Consent
  • 22. How do you persuade consumers to share their data? • Offer incentives • Be completely clear on what the consumer will receive • Be completely clear on storage details and who the information will be shared with The consent challenge
  • 23. The GDPR defines valid consent as unambiguous, affirmative consent. Consent
  • 25. The consent challenge Come up with an incentive to encourage sign ups to your mailing list
  • 26. Can we still use a pre-ticked box as consent? Consent Q&A No, GDPR doesn’t class a pre-ticked box or any form of inactivity as valid consent. The data subject must make an affirmative action for their consent to be valid.
  • 27. What is the best way to gain valid consent if purchasing a product or service? Consent Q&A The best way to ensure that you’re fully compliant with the GDPR is to include a separate opt-in option at the point a consumer joins/purchases by encouraging them to sign up to receive updates via email.
  • 28. We’ve got historic lists – will they still be valid? Consent Q&A If your current data hasn’t specifically been collected using affirmative consent for all activities, or you don’t have a record of the details required, then you’ll have to gain fresh consent.
  • 30. Database requirements Organisations must be able to demonstrate that an individual consented to the processing of their personal data. If consent is given over the phone, you’ll need a recording If you collect consent online, you’ll need to record consent wording, time & source
  • 32. True or false GDPR will stop dentists ringing patients to remind them about appointments
  • 33. True or false All personal data breaches will need to be reported to the ICO.
  • 38. Data controller vs data processor
  • 39. Are you a data controller or data processor? Data controller - the organisation that collects personal data and decides how it will be used. Data processor - the organisation that processes personal data on behalf of the data controller.
  • 40. Data controller obligations • Collects data • Which items of personal data to collect • How the data will be used • Whether to disclose the data, and if so, who to • Arranging access • Storage
  • 41. Data processor obligations • To process data fairly and lawfully • Data is kept accurate and up to date • Data is only kept for as long as necessary • Adhere to all agreements in your contract with the data controller
  • 42. Data controller or data processor? A local authority uses a cloud provider to store data about its housing stock and residents, rather than holding the data on its own IT system. The cloud provider is also contracted to delete certain data after a particular period and to grant members of the public access to their own records via a secure online portal.
  • 43. Data controller or data processor? An online retailer work in co-operation with a third-party payment company to process customers’ transactions.
  • 45. The data protection officer (DPO) A data protection officer is responsible for overseeing your data protection strategy and implementation to ensure compliance with GDPR. • Inform • Monitor • Contact
  • 46. Who needs a DPO? x • Public authorities • Large scale systematic monitoring of individuals • Large scale processing of special categories

Editor's Notes

  • #30: Database requirements – this is one of the areas that will take some time to set up and get ready. You’ll have to make sure that software / database that you use has the capability to record what you need (like sign up wording).