SlideShare a Scribd company logo
IRIS Customer Conference
GDPR – Game Changing Legislation
Will Richmond-Coggan, Pitmans Law
27 March 2018
GDPR – Game Changing Legislation
We’re lawyers, so we always start with a disclaimer.
The guidance that follows is in the nature of general information about
the subject matter concerned – it is invariably the case that detailed
legal advice requires a lot of fact-sensitive information that we will not
have while discussing points today. As such, no reliance should be
placed on the guidance given in this talk without first taking such
detailed advice.
Nevertheless, feel free to ask questions, even those embarrassing
ones on behalf of your “friend” who couldn’t make it – it will help us to
make sure that the content is as relevant as possible!
General overview – this talk
I am going to cover as much of the following as
possible!
• An introduction to key concepts / main changes
• Outlining a roadmap to GDPR readiness
• The data subject’s rights
Core Concept – Personal data
• Now includes identification numbers, location, online identifiers
and factors specific to the individual's physical, physiological,
genetic, mental, economic, cultural or social identity.
• Still includes information about activities when linked to an
identifier
• Sensitive data now includes genetic and biometric data
• Criminal records now occupy a separate category and are
treated distinctly
Core Concept – Lawful processing
• Contract – necessary for the formation or performance of
a contract between the controller and subject
• Obligation – necessary for performance of a legal
obligation, or discharge of a statutory function
• Vital interests – to protect the vital interests of the data
subject or someone else
• Legitimate interests – of the data processor and
controller, but only where other rights aren’t affected
Lawful processing (cont.) – Consent
• Consent must be freely given, specific, informed and
unambiguous by “some form of clear affirmative action”
• It cannot be signified by inaction, silence or be a pre-
condition to other actions
• It must be as easy for a subject to withdraw consent as
to give it – form and substance
• Remember that processing under consent gives the data
subject wider rights than other lawfulness gateways
General overview – the legislation
Key game-changers brought in by GDPR:
• Direct accountability of data processors
• Data controller/processor distinction
• Limited scope to re-allocate risk contractually
• Territorial extent
• The “Global” Data Protection Regulation?
• Third countries – nomination of a data regulator
• And (of course) Brexit!
General overview – the legislation
Key game-changers brought in by GDPR:
• Breach notification and record keeping
• “Accountability principle” – document intensive
• Mandatory notification – data regulator
• Mandatory notification – data subjects
• Consequences are broader
• Wider fines – the greater of EUR 10m or 2% of global group
turnover for “minor” issues, it’s 4% / EUR 20m for major ones!
• ICO audits; data subject compensation; reputation
Get ready with… D… P… R…
Roadmap - Data discovery
Headline points:
• What is “personal data”
• Identification of an individual or information about activities
• Where should the data be located…
• Think about local drives, servers, cloud services, portable
• …where else is it actually…
• Think about personal devices, webmail, pen drives, offshore
• …and data flows
• Internal/external, compliant processing chains, cross-border
Roadmap – Policies for compliance
Headline points:
• Compliance with standards
• e.g. Cyber-Essentials, ISO 27001, BS 10012:2017
• GDPR-specific procedures
• Consent management, privacy protection systems, notifications
• Policy and process review
• System capabilities, gap analysis, develop and implement
• Training and awareness at all levels
• “Baked in” compliance – privacy by design and by default
Roadmap – Record keeping
Headline points:
• Accountability principle
• Have to be able to “show” as well as “do”
• Records are essential
• Of data held, decisions taken, policies and procedures
• ICO ability to audit
• Including onsite inspection and requiring delivery of information
• As part of a supply chain
• Accountability up and down the chain
Processes – Risk assessment
• Identify each of the processes of your business which
engage personal data
• Do you process as controller or processor – what is the
lawfulness gateway?
• Is the processing proportionate to the objectives?
• What measures of safeguarding are appropriate –
anonymisation/pseudonymisation; encryption;
permissions; policies
Processes – Breach notification
• Now mandatory for breaches: “leading to the destruction,
loss, alteration, unauthorised disclosure of, or access to,
personal data”
• Notification must be made within 72 hours of detection
• Data subjects must also be notified “without undue
delay” where the breach poses a high risk to their rights
• Think about the steps that will need to be taken in those
72 hours – processes need to be in place already
The Data Subject’s Journey
Inform
Access Rectify
Restrict Transfer
Object Erase
With Pitmans Law you can be assured of the quality of advice and service
you demand from a city law firm – but with a distinction. The courage to stand apart, to
think and act personably, with an uncompromising focus on achieving outstanding client
outcomes. We say what we mean, matching our behaviours to our words.
Established for over 150 years, Pitmans Law is headquartered in Reading with offices in
London and Southampton. The lower overheads of a regional office ensure we can
provide city quality legal advice at a competitive price to deliver exceptional value for our
corporate and private clients locally, nationally and internationally.
Pitmans provides legal advice to address our clients’ needs across a wide range
of industry sectors and specialisms including particularly strong specialist teams in
pensions advisory, real estate, dispute resolution as well as corporate and commercial
law. Our clients draw confidence from the top tier recognition Pitmans achieves in the
industry benchmarking directories, Legal 500 and Chambers UK.
Reading, London, Southampton
Pitmans Law is the founding UK member firm of the global legal network, Interact Law.
Contact us
T +44 (0)345 222 9222
E law@pitmans.com

More Related Content

PPTX
Analytics in Action - Data Protection
PDF
DAMA Ireland - GDPR
PPTX
Privacy, Data Security and Anti-Spam Compliance
PDF
GDPR what you should know and how to minimize impact on your business
PPTX
PDF
12 02-14 information security managers - unannotated
PDF
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
PPTX
An Introduction to the General Data Protection Regulation (GDPR)
Analytics in Action - Data Protection
DAMA Ireland - GDPR
Privacy, Data Security and Anti-Spam Compliance
GDPR what you should know and how to minimize impact on your business
12 02-14 information security managers - unannotated
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
An Introduction to the General Data Protection Regulation (GDPR)

What's hot (19)

PDF
Csa privacy by design & gdpr austin chambers 11-4-17
PPTX
Embedding GDPR Within Your Information and Library Service
PDF
20170323 are you ready the new gdpr is here
PPTX
BigID GDPR Compliance Automation Webinar Slides
PPTX
GDPR: Your Journey to Compliance
PDF
GDPR changes affect direct marketing
PPTX
GDPR Breakfast Briefing for Business Advisors
PPTX
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
PPTX
GDPR From the Trenches - Real-world examples of how companies are approaching...
PPTX
GDPR – The Practicalities of a New Reality
PDF
Data Privacy & Security
PPTX
GDPR Presentation slides
PPTX
GDPR practical info session for development
PPTX
12 steps to gdpr compliance unleashed
PPTX
Payroll Data & GDPR: What you need to know?
PPT
S719a
PPTX
Human resources: protecting confidentiality
PPTX
Gdpr compliance. Presentation for Consulegis Lawyers network
PPTX
GDPR for developers
Csa privacy by design & gdpr austin chambers 11-4-17
Embedding GDPR Within Your Information and Library Service
20170323 are you ready the new gdpr is here
BigID GDPR Compliance Automation Webinar Slides
GDPR: Your Journey to Compliance
GDPR changes affect direct marketing
GDPR Breakfast Briefing for Business Advisors
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR – The Practicalities of a New Reality
Data Privacy & Security
GDPR Presentation slides
GDPR practical info session for development
12 steps to gdpr compliance unleashed
Payroll Data & GDPR: What you need to know?
S719a
Human resources: protecting confidentiality
Gdpr compliance. Presentation for Consulegis Lawyers network
GDPR for developers
Ad

Similar to Game changing legislation (20)

PDF
#HR and #GDPR: Preparing for 2018 Compliance
PDF
GDPR for your Payroll Bureau
PPTX
Prepare Your Firm for GDPR
PPTX
ABM Display Advertising Success in the World of GDPR [PPT]
PPTX
GDPR Enforcement is here. Are you ready?
PPTX
Vuzion Love Cloud GDPR Event
PPTX
GDPR Privacy Introduction
PPTX
Introduction to GDPR
PPTX
Getting to grips with General Data Protection Regulation (GDPR)
PPTX
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
PPTX
GDPR Breakfast Briefing for Business Advisors
PPTX
Global Data Privacy Regulation
PPTX
What does GDPR mean for your business?
PPTX
Why We Require GDPR?
PPT
13687562.ppt
PDF
GDPR for your Payroll Bureau
PDF
GDPRforum London
PDF
What's Next - General Data Protection Regulation (GDPR) Changes
PPSX
Gdpr demystified - making sense of the regulation
#HR and #GDPR: Preparing for 2018 Compliance
GDPR for your Payroll Bureau
Prepare Your Firm for GDPR
ABM Display Advertising Success in the World of GDPR [PPT]
GDPR Enforcement is here. Are you ready?
Vuzion Love Cloud GDPR Event
GDPR Privacy Introduction
Introduction to GDPR
Getting to grips with General Data Protection Regulation (GDPR)
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Advisors
Global Data Privacy Regulation
What does GDPR mean for your business?
Why We Require GDPR?
13687562.ppt
GDPR for your Payroll Bureau
GDPRforum London
What's Next - General Data Protection Regulation (GDPR) Changes
Gdpr demystified - making sense of the regulation
Ad

More from IRIS (10)

PPTX
IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
PPTX
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
PPTX
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
PPTX
IRIS World 2018 - Keynote - Thrive in the Digital Economy
PPTX
HMRC
PDF
Software impact of gdpr
PDF
Opportunity or burden
PDF
Don't panic - cyber security for the faint hearted
PDF
Happy clients happy compliance
PDF
Whos role is it anyway
IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital Economy
HMRC
Software impact of gdpr
Opportunity or burden
Don't panic - cyber security for the faint hearted
Happy clients happy compliance
Whos role is it anyway

Recently uploaded (20)

PPTX
social-studies-subject-for-high-school-globalization.pptx
PPTX
Introduction to Customs (June 2025) v1.pptx
PPTX
Unilever_Financial_Analysis_Presentation.pptx
PDF
Corporate Finance Fundamentals - Course Presentation.pdf
PDF
Mathematical Economics 23lec03slides.pdf
PDF
ADVANCE TAX Reduction using traditional insurance
PPTX
Understanding-Economic-Growth in macro..
PPTX
Introduction to Managemeng Chapter 1..pptx
PDF
ECONOMICS AND ENTREPRENEURS LESSONSS AND
PPT
E commerce busin and some important issues
PDF
final_dropping_the_baton_-_how_america_is_failing_to_use_russia_sanctions_and...
PPTX
Introduction to Essence of Indian traditional knowledge.pptx
PDF
Topic Globalisation and Lifelines of National Economy.pdf
PPTX
Session 3. Time Value of Money.pptx_finance
PPTX
Basic Concepts of Economics.pvhjkl;vbjkl;ptx
PDF
financing insitute rbi nabard adb imf world bank insurance and credit gurantee
PDF
Is Retirement Income a Three Dimensional (3-D) problem_ What is the differenc...
PDF
NAPF_RESPONSE_TO_THE_PENSIONS_COMMISSION_8 _2_.pdf
PDF
Why Ignoring Passive Income for Retirees Could Cost You Big.pdf
PDF
way to join Real illuminati agent 0782561496,0756664682
social-studies-subject-for-high-school-globalization.pptx
Introduction to Customs (June 2025) v1.pptx
Unilever_Financial_Analysis_Presentation.pptx
Corporate Finance Fundamentals - Course Presentation.pdf
Mathematical Economics 23lec03slides.pdf
ADVANCE TAX Reduction using traditional insurance
Understanding-Economic-Growth in macro..
Introduction to Managemeng Chapter 1..pptx
ECONOMICS AND ENTREPRENEURS LESSONSS AND
E commerce busin and some important issues
final_dropping_the_baton_-_how_america_is_failing_to_use_russia_sanctions_and...
Introduction to Essence of Indian traditional knowledge.pptx
Topic Globalisation and Lifelines of National Economy.pdf
Session 3. Time Value of Money.pptx_finance
Basic Concepts of Economics.pvhjkl;vbjkl;ptx
financing insitute rbi nabard adb imf world bank insurance and credit gurantee
Is Retirement Income a Three Dimensional (3-D) problem_ What is the differenc...
NAPF_RESPONSE_TO_THE_PENSIONS_COMMISSION_8 _2_.pdf
Why Ignoring Passive Income for Retirees Could Cost You Big.pdf
way to join Real illuminati agent 0782561496,0756664682

Game changing legislation

  • 1. IRIS Customer Conference GDPR – Game Changing Legislation Will Richmond-Coggan, Pitmans Law 27 March 2018
  • 2. GDPR – Game Changing Legislation We’re lawyers, so we always start with a disclaimer. The guidance that follows is in the nature of general information about the subject matter concerned – it is invariably the case that detailed legal advice requires a lot of fact-sensitive information that we will not have while discussing points today. As such, no reliance should be placed on the guidance given in this talk without first taking such detailed advice. Nevertheless, feel free to ask questions, even those embarrassing ones on behalf of your “friend” who couldn’t make it – it will help us to make sure that the content is as relevant as possible!
  • 3. General overview – this talk I am going to cover as much of the following as possible! • An introduction to key concepts / main changes • Outlining a roadmap to GDPR readiness • The data subject’s rights
  • 4. Core Concept – Personal data • Now includes identification numbers, location, online identifiers and factors specific to the individual's physical, physiological, genetic, mental, economic, cultural or social identity. • Still includes information about activities when linked to an identifier • Sensitive data now includes genetic and biometric data • Criminal records now occupy a separate category and are treated distinctly
  • 5. Core Concept – Lawful processing • Contract – necessary for the formation or performance of a contract between the controller and subject • Obligation – necessary for performance of a legal obligation, or discharge of a statutory function • Vital interests – to protect the vital interests of the data subject or someone else • Legitimate interests – of the data processor and controller, but only where other rights aren’t affected
  • 6. Lawful processing (cont.) – Consent • Consent must be freely given, specific, informed and unambiguous by “some form of clear affirmative action” • It cannot be signified by inaction, silence or be a pre- condition to other actions • It must be as easy for a subject to withdraw consent as to give it – form and substance • Remember that processing under consent gives the data subject wider rights than other lawfulness gateways
  • 7. General overview – the legislation Key game-changers brought in by GDPR: • Direct accountability of data processors • Data controller/processor distinction • Limited scope to re-allocate risk contractually • Territorial extent • The “Global” Data Protection Regulation? • Third countries – nomination of a data regulator • And (of course) Brexit!
  • 8. General overview – the legislation Key game-changers brought in by GDPR: • Breach notification and record keeping • “Accountability principle” – document intensive • Mandatory notification – data regulator • Mandatory notification – data subjects • Consequences are broader • Wider fines – the greater of EUR 10m or 2% of global group turnover for “minor” issues, it’s 4% / EUR 20m for major ones! • ICO audits; data subject compensation; reputation
  • 9. Get ready with… D… P… R…
  • 10. Roadmap - Data discovery Headline points: • What is “personal data” • Identification of an individual or information about activities • Where should the data be located… • Think about local drives, servers, cloud services, portable • …where else is it actually… • Think about personal devices, webmail, pen drives, offshore • …and data flows • Internal/external, compliant processing chains, cross-border
  • 11. Roadmap – Policies for compliance Headline points: • Compliance with standards • e.g. Cyber-Essentials, ISO 27001, BS 10012:2017 • GDPR-specific procedures • Consent management, privacy protection systems, notifications • Policy and process review • System capabilities, gap analysis, develop and implement • Training and awareness at all levels • “Baked in” compliance – privacy by design and by default
  • 12. Roadmap – Record keeping Headline points: • Accountability principle • Have to be able to “show” as well as “do” • Records are essential • Of data held, decisions taken, policies and procedures • ICO ability to audit • Including onsite inspection and requiring delivery of information • As part of a supply chain • Accountability up and down the chain
  • 13. Processes – Risk assessment • Identify each of the processes of your business which engage personal data • Do you process as controller or processor – what is the lawfulness gateway? • Is the processing proportionate to the objectives? • What measures of safeguarding are appropriate – anonymisation/pseudonymisation; encryption; permissions; policies
  • 14. Processes – Breach notification • Now mandatory for breaches: “leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data” • Notification must be made within 72 hours of detection • Data subjects must also be notified “without undue delay” where the breach poses a high risk to their rights • Think about the steps that will need to be taken in those 72 hours – processes need to be in place already
  • 15. The Data Subject’s Journey Inform Access Rectify Restrict Transfer Object Erase
  • 16. With Pitmans Law you can be assured of the quality of advice and service you demand from a city law firm – but with a distinction. The courage to stand apart, to think and act personably, with an uncompromising focus on achieving outstanding client outcomes. We say what we mean, matching our behaviours to our words. Established for over 150 years, Pitmans Law is headquartered in Reading with offices in London and Southampton. The lower overheads of a regional office ensure we can provide city quality legal advice at a competitive price to deliver exceptional value for our corporate and private clients locally, nationally and internationally. Pitmans provides legal advice to address our clients’ needs across a wide range of industry sectors and specialisms including particularly strong specialist teams in pensions advisory, real estate, dispute resolution as well as corporate and commercial law. Our clients draw confidence from the top tier recognition Pitmans achieves in the industry benchmarking directories, Legal 500 and Chambers UK. Reading, London, Southampton Pitmans Law is the founding UK member firm of the global legal network, Interact Law. Contact us T +44 (0)345 222 9222 E law@pitmans.com