SlideShare a Scribd company logo
1
ROTARY AND THE GENERAL DATA PROTECTION
REGULATION (GDPR)
Whatis GDPR?
GDPR is a new European Union law that strengthens data protection rules for EU residents.The law
applies to all companies that process data within the EU but also to foreign organizations, like Rotary
International, that offer goods and services to EU residents. The law takes effect 25 May and replaces the
EU’s 1995 Data Protection Directive.
Whatdoes Rotary International do to protect personaldata?
Long before GDPR, Rotary’s policies took care to protect your information. Rotary’s Website Privacy
Policy explains what information we collect, how we collect it, and how we use it. We also striveto give
you control over your data so you can decide what personal information to share,as well as review it
whenever you want.
The measures we take to safeguardyour personal data includeusing password-protected databases on
secure servers behind firewalls and requiring all staffto attend information security awareness training
each year.
How has Rotary International prepared forGDPR?
First, we completed a readiness assessment and risk analysis. These helped us understand how the new
regulation would affect ourprocesses and what we needed to change to comply with GDPR. Our analysis
led us to focus on these areas:
 Process inventory. We inventoried all ofour personal data processing activities in order to
comply with GDPR’s Article30.
 Lawful basis. We reviewed all data processing to ensure that we have a documented legal basis, or
reason, for every process,according to GDPR.
 Policy and notices. We’re updating our Website PrivacyPolicy to meet GDPR expectations. And
we’re making our notices about how yourpersonal data is used morespecific.
 Records management. We updated our schedules for retaining records that contain personal
data to make sure we’re keeping records only as long as necessary.
 Data breach procedures.We revised our guidelines for responding to a breach,according to
GDPR expectations for notifying constituents ofa breach.
2
Whatdoes GDPR mean for me?
Rotary is applying thesenew standards globally, not just for our European constituents. So no matter
where you live,ifRotary processes your personal data, you will have the following rights:
 Right to be informed: Rotary will regularly disclose to you what personal data we collectand for
what purpose.
 Right to object: You can tell us ifyou no longer want your personal data to be processed in a
certain way, such as for direct marketing.
 Right to rectification: Y ou can write us at data@rotary.org to correct errors in yourpersonal
data.
Do I need to give Rotary International consentto use my personaldata?
In general, no. Under GDPR, consent is just one ofsix legal bases used to determinethat processing
someone’s data is lawful. Rotary will generally rely on “legitimate interest” as the lawful basis for
processing personal data, because doing so is necessary to effectively manage and operateRotary and
won’t unduly infringe yourlegal rights.
We will ask for your consentonly when it’s truly appropriate,for example, when we are processing special
categories ofpersonal data, like health information.
My club or district is in the EU. Do I need to do anything?
Y es. Ifyour clubor districtis in the EU and is processing the personal data ofyour members or other
program participants, you areobligated to follow GDPR requirements. This may mean:
 Providing notice to yourmembers abouthow their personal data is used
 Minimizing the personal data that you have and keeping it secure
 Getting consent when it’s appropriate(for example, for personal data ofyouths under the age of16)
Further information can be found at EUGDPR.org or on one ofthe many EU country data protection
authorities’ websites.Y ou may also want to consult with local privacyexperts to better understand your
responsibilities underthe law.
3
I’m notin the EU. Do I need to do anything?
Possibly.Even ifyour club or district is not in the EU, you are required to follow GDPR rules if you
process the personal data ofEU residents. Youmay also need to comply with GDPR if you welcome
European attendees at events, hostexchangestudents from Europe, or partnerwith European members
on serviceprojects.
Whatis Rotary doing to help clubs and districts with GDPR?
We have updated Rotary’s Privacy Policy with terms that align with GDPR. And you can writeus at
privacy@rotary.org with any questions.

More Related Content

PPTX
GDPR - What You Need To Know
PDF
How to be CASL & GDPR Compliant for the New Year 2019
PPTX
GDPR - What you need to know about the General Data Protection Regulation
PDF
Lipocast bitoech uk privacy and data protection policy
PDF
Bonsoni privacy policy
PDF
PDF
GDPR: Are you EU Compliant?
PPTX
GDPR - Basics for Community Archives
GDPR - What You Need To Know
How to be CASL & GDPR Compliant for the New Year 2019
GDPR - What you need to know about the General Data Protection Regulation
Lipocast bitoech uk privacy and data protection policy
Bonsoni privacy policy
GDPR: Are you EU Compliant?
GDPR - Basics for Community Archives

What's hot (12)

PDF
Fulcio
PDF
Privacy Policy if No Personal Data is Collected
DOCX
privacy+policy
PPTX
General Data Protection Regulation for Ops
PDF
Australia Privacy Act of 1988
PDF
Gdprplan.com affiliate huddle 10th may 2018
PDF
The Basics of GDPR
PDF
GDPR Training Course - Training Express
PDF
The Countdown to the GDPR Regulations
PDF
GDPR Privacy Policy
PDF
Ipsos MORI Political Monitor February 2015: Tactical voting and preferred coa...
PPTX
How will GDPR affect your business - Marketing Fox & Birkett Long
Fulcio
Privacy Policy if No Personal Data is Collected
privacy+policy
General Data Protection Regulation for Ops
Australia Privacy Act of 1988
Gdprplan.com affiliate huddle 10th may 2018
The Basics of GDPR
GDPR Training Course - Training Express
The Countdown to the GDPR Regulations
GDPR Privacy Policy
Ipsos MORI Political Monitor February 2015: Tactical voting and preferred coa...
How will GDPR affect your business - Marketing Fox & Birkett Long
Ad

Similar to Data Privacy and Data Protection: Rotary’s Compliance with GDPR Handout (20)

PPTX
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
PPTX
Data Protection and Privacy for Rotary Clubs and Districts
PDF
Jowanna Conboye - Stephens Scown
PDF
Horner Downey & Co Newsletter- GDPR
PDF
SAP insider GDPR compendium Hernan Huwyler
PPT
Abridged Compliance Seminar for 1090 club members May 2016
PPTX
GDPR Privacy Introduction
PPTX
skillcast-gdpr-training-presentation-q320.pptx
PDF
Gdpr workshop module_1
PPTX
General data protection
PPTX
GDPR_Skillcast Presentation Template.pptx
PDF
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
PDF
GDPR A Practical Guide with Varonis
PPTX
De groote de man Ingrid de Poorter
PDF
20170323 are you ready the new gdpr is here
PDF
General Data Protection Regulation, a developer's story
PDF
GDPR for Dummies
PPTX
Gdpr presentation
PDF
Opportunity or burden
PPTX
GDPR_Skillcast Presentation Template (1).pptx
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Protection and Privacy for Rotary Clubs and Districts
Jowanna Conboye - Stephens Scown
Horner Downey & Co Newsletter- GDPR
SAP insider GDPR compendium Hernan Huwyler
Abridged Compliance Seminar for 1090 club members May 2016
GDPR Privacy Introduction
skillcast-gdpr-training-presentation-q320.pptx
Gdpr workshop module_1
General data protection
GDPR_Skillcast Presentation Template.pptx
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
GDPR A Practical Guide with Varonis
De groote de man Ingrid de Poorter
20170323 are you ready the new gdpr is here
General Data Protection Regulation, a developer's story
GDPR for Dummies
Gdpr presentation
Opportunity or burden
GDPR_Skillcast Presentation Template (1).pptx
Ad

More from Rotary International (20)

PPTX
THE_PROMOTER_-_DRR_TRAINING_PRECON_2022.pptx
PPTX
RIC 22 MDIO Breakout.pptx
PPTX
IC22 Winning Teams - Nicole Peña.pptx
PPTX
DRR Training The Organizer.pptx
PPTX
IC22 Rotaract - Keys to level up your influence_Casas&Guerra (2).pptx
PPTX
Service Ambassadors Presentation.pptx
PPTX
DRR Training_The Trainer 2022.pptx
PPTX
Burnout management.pptx
PPTX
Leadership Development Program Presentation.pptx
PPTX
RI Convention 2022_Rotaract Pre Convention_2022.06.04 NewGen Peacebuilders.pptx
PPTX
IC22 Rotaract Intro to DRR Training.pptx
PPTX
351 930-1020.pptx
PPTX
IC22 Rotaract Precon_Making an Impact Through Rotary Grants.pptx
PPTX
Lets Celebrate Inclusion.pptx
PPTX
IC22 Rotaract Networking Impactful Service Project.pptx
PPTX
Membership Engagement Presentation.pptx
PPTX
Lessons Learned.pptx
PDF
Nurturing Strategic Partnerships.pdf
PPTX
Panel Discussion environment_ (003).pptx
PPTX
General Session June 4.pptx
THE_PROMOTER_-_DRR_TRAINING_PRECON_2022.pptx
RIC 22 MDIO Breakout.pptx
IC22 Winning Teams - Nicole Peña.pptx
DRR Training The Organizer.pptx
IC22 Rotaract - Keys to level up your influence_Casas&Guerra (2).pptx
Service Ambassadors Presentation.pptx
DRR Training_The Trainer 2022.pptx
Burnout management.pptx
Leadership Development Program Presentation.pptx
RI Convention 2022_Rotaract Pre Convention_2022.06.04 NewGen Peacebuilders.pptx
IC22 Rotaract Intro to DRR Training.pptx
351 930-1020.pptx
IC22 Rotaract Precon_Making an Impact Through Rotary Grants.pptx
Lets Celebrate Inclusion.pptx
IC22 Rotaract Networking Impactful Service Project.pptx
Membership Engagement Presentation.pptx
Lessons Learned.pptx
Nurturing Strategic Partnerships.pdf
Panel Discussion environment_ (003).pptx
General Session June 4.pptx

Recently uploaded (20)

PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PDF
project resource management chapter-09.pdf
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
A comparative study of natural language inference in Swahili using monolingua...
PPTX
Tartificialntelligence_presentation.pptx
PPTX
The various Industrial Revolutions .pptx
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
Web App vs Mobile App What Should You Build First.pdf
PPTX
Chapter 5: Probability Theory and Statistics
PDF
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
1. Introduction to Computer Programming.pptx
PDF
Hybrid model detection and classification of lung cancer
PDF
STKI Israel Market Study 2025 version august
PPT
What is a Computer? Input Devices /output devices
PDF
1 - Historical Antecedents, Social Consideration.pdf
A contest of sentiment analysis: k-nearest neighbor versus neural network
project resource management chapter-09.pdf
Getting started with AI Agents and Multi-Agent Systems
NewMind AI Weekly Chronicles – August ’25 Week III
A comparative study of natural language inference in Swahili using monolingua...
Tartificialntelligence_presentation.pptx
The various Industrial Revolutions .pptx
Hindi spoken digit analysis for native and non-native speakers
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
Web App vs Mobile App What Should You Build First.pdf
Chapter 5: Probability Theory and Statistics
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
cloud_computing_Infrastucture_as_cloud_p
1. Introduction to Computer Programming.pptx
Hybrid model detection and classification of lung cancer
STKI Israel Market Study 2025 version august
What is a Computer? Input Devices /output devices
1 - Historical Antecedents, Social Consideration.pdf

Data Privacy and Data Protection: Rotary’s Compliance with GDPR Handout

  • 1. 1 ROTARY AND THE GENERAL DATA PROTECTION REGULATION (GDPR) Whatis GDPR? GDPR is a new European Union law that strengthens data protection rules for EU residents.The law applies to all companies that process data within the EU but also to foreign organizations, like Rotary International, that offer goods and services to EU residents. The law takes effect 25 May and replaces the EU’s 1995 Data Protection Directive. Whatdoes Rotary International do to protect personaldata? Long before GDPR, Rotary’s policies took care to protect your information. Rotary’s Website Privacy Policy explains what information we collect, how we collect it, and how we use it. We also striveto give you control over your data so you can decide what personal information to share,as well as review it whenever you want. The measures we take to safeguardyour personal data includeusing password-protected databases on secure servers behind firewalls and requiring all staffto attend information security awareness training each year. How has Rotary International prepared forGDPR? First, we completed a readiness assessment and risk analysis. These helped us understand how the new regulation would affect ourprocesses and what we needed to change to comply with GDPR. Our analysis led us to focus on these areas:  Process inventory. We inventoried all ofour personal data processing activities in order to comply with GDPR’s Article30.  Lawful basis. We reviewed all data processing to ensure that we have a documented legal basis, or reason, for every process,according to GDPR.  Policy and notices. We’re updating our Website PrivacyPolicy to meet GDPR expectations. And we’re making our notices about how yourpersonal data is used morespecific.  Records management. We updated our schedules for retaining records that contain personal data to make sure we’re keeping records only as long as necessary.  Data breach procedures.We revised our guidelines for responding to a breach,according to GDPR expectations for notifying constituents ofa breach.
  • 2. 2 Whatdoes GDPR mean for me? Rotary is applying thesenew standards globally, not just for our European constituents. So no matter where you live,ifRotary processes your personal data, you will have the following rights:  Right to be informed: Rotary will regularly disclose to you what personal data we collectand for what purpose.  Right to object: You can tell us ifyou no longer want your personal data to be processed in a certain way, such as for direct marketing.  Right to rectification: Y ou can write us at data@rotary.org to correct errors in yourpersonal data. Do I need to give Rotary International consentto use my personaldata? In general, no. Under GDPR, consent is just one ofsix legal bases used to determinethat processing someone’s data is lawful. Rotary will generally rely on “legitimate interest” as the lawful basis for processing personal data, because doing so is necessary to effectively manage and operateRotary and won’t unduly infringe yourlegal rights. We will ask for your consentonly when it’s truly appropriate,for example, when we are processing special categories ofpersonal data, like health information. My club or district is in the EU. Do I need to do anything? Y es. Ifyour clubor districtis in the EU and is processing the personal data ofyour members or other program participants, you areobligated to follow GDPR requirements. This may mean:  Providing notice to yourmembers abouthow their personal data is used  Minimizing the personal data that you have and keeping it secure  Getting consent when it’s appropriate(for example, for personal data ofyouths under the age of16) Further information can be found at EUGDPR.org or on one ofthe many EU country data protection authorities’ websites.Y ou may also want to consult with local privacyexperts to better understand your responsibilities underthe law.
  • 3. 3 I’m notin the EU. Do I need to do anything? Possibly.Even ifyour club or district is not in the EU, you are required to follow GDPR rules if you process the personal data ofEU residents. Youmay also need to comply with GDPR if you welcome European attendees at events, hostexchangestudents from Europe, or partnerwith European members on serviceprojects. Whatis Rotary doing to help clubs and districts with GDPR? We have updated Rotary’s Privacy Policy with terms that align with GDPR. And you can writeus at privacy@rotary.org with any questions.