SlideShare a Scribd company logo
CHILTERN BUSINESS
CONNECTIONS
GOOD MORNING
ARE YOU READY FOR
GENERAL DATA PROTECTION
REGULATIONS (GDPR)?
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
GDPR comes into effect May 2018
Initially EU ‘driven’ – set to become a worldwide
standard - builds upon existing data protection
rules
Information Commissioner’s Office (ICO) is relevant
U.K. ‘body’
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Prompted by the growth in data processing
Evolution rather than revolution of the rules
Not a new Millennium Bug
Aim to achieve privacy by design and default
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Requires personal data (PD) to be respected
- Accountability
- Transparency
- Individuals’ rights
An obligation on all businesses/organisations
Severe penalties for non- compliance
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Important in terms of client reassurance
An opportunity to focus on client care
Positive use of GDPR
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Organisations are required to have a legal
basis to process
1. Contract
2. Consent
3. Vital Interest
4. Public Task
5. Comply with legal obligations
6. Legitimate Interests
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Segmentation appropriate i.e.
- Contract basis for preparing wills/LPAs etc.
- Consent basis for marketing communication
A ‘granular‘ approach required
- Consent cannot be ‘bundled’
Consent must be ‘active’
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Privacy statements to include:
- Legal basis for processing data
- What is to happen to the data
- What a client does if there’s a problem
On website and in terms of trading
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Imposes general obligation to implement
technical and organisational measures to
show that consideration has been given to
data protection when processing.
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
IOC checklist:
Privacy Impact Assessment (PIA)
Audit and log what PD held and how it flows
Document who PD comes from - what you
do with it - with whom you share it
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Identify and document lawful basis for
processing PD
Review and record how consent is obtained
and recorded
Establish means to record/manage ongoing
consent
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Maintain registration with ICO
Ensure privacy notices readily available
Concise - easy to understand - identifies you
– confirms how PD to be handled - with whom
shared – how long to be retained
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Establish right for individuals to access PD
Establish process to keep PD accurate and up
to date (relevant for wills/LPAs?)
Provide for effective destruction of PD no
longer required.
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Establish procedure to respond to clients’
requests to restrict processing
Allow individuals to copy/move their PD
Reference to automated decision making
(NA)
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Ensure data protection policy in place and
review compliance periodically
Provide data protection training for all staff
Written contract with appropriately vetted
‘data processors’
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Clear security policies and procedures –
regularly reviewed
Ensure data protection is integrated into all
activities
Understand when and how Data Protection
Impact Assessments (DPIAs) should be used.
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Nominate Data Protection Officer (DPO)
Promote positive culture of data protection
Develop and maintain an information security
policy
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
Special rules for any information transferred
beyond the EEA
Establish procedure to deal with identifying,
reporting, managing and resolving PD
breaches
GENERAL DATA PROTECTION REGULATIONS
(GDPR)
That’s all there is to it !

More Related Content

PPT
CBC GDPR April 2018
PPTX
EU GDPR - 12 Steps To Compliance
PDF
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
PDF
How privacy by design can be the key of your success at the time of the digit...
PDF
Come cambia la cybersecurity con il regolamento privacy europeo
PDF
The Essential Guide to GDPR
PPTX
Wearable technologies, privacy and intellectual property rights
CBC GDPR April 2018
EU GDPR - 12 Steps To Compliance
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
How privacy by design can be the key of your success at the time of the digit...
Come cambia la cybersecurity con il regolamento privacy europeo
The Essential Guide to GDPR
Wearable technologies, privacy and intellectual property rights

What's hot (20)

PDF
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
PPTX
Quick Introduction to the EU GDPR by Sami Zahran
PPTX
Wearable technologies and remote patient remote monitoring system
PDF
VMTN6642E - GDPR Slide Deck
PDF
Developer view on new EU privacy legislation (GDPR)
PPT
What changes for Internet of Things technologies with the EU Data Protection ...
PDF
Privacy by design
PDF
Csa privacy by design & gdpr austin chambers 11-4-17
PPTX
Training privacy by design
PPTX
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
PPTX
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
PPTX
GDPR From the Trenches - Real-world examples of how companies are approaching...
PPTX
Gdpr action plan
PPTX
An Overview Of GDPR (General Data Protection Regulation)
PDF
Beginning your General Data Protection Regulation (GDPR) Journey
PPTX
New opportunities and business risks with evolving privacy regulations
PPTX
GDPR and NIS Compliance - How HyTrust Can Help
PPTX
GDPR and evolving international privacy regulations
PDF
Convince your board - Ten steps to GDPR compliance
PPTX
GDPR: Training Materials by Qualsys
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Quick Introduction to the EU GDPR by Sami Zahran
Wearable technologies and remote patient remote monitoring system
VMTN6642E - GDPR Slide Deck
Developer view on new EU privacy legislation (GDPR)
What changes for Internet of Things technologies with the EU Data Protection ...
Privacy by design
Csa privacy by design & gdpr austin chambers 11-4-17
Training privacy by design
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
GDPR From the Trenches - Real-world examples of how companies are approaching...
Gdpr action plan
An Overview Of GDPR (General Data Protection Regulation)
Beginning your General Data Protection Regulation (GDPR) Journey
New opportunities and business risks with evolving privacy regulations
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and evolving international privacy regulations
Convince your board - Ten steps to GDPR compliance
GDPR: Training Materials by Qualsys
Ad

Similar to GDPR Jan 2018 1 (20)

PPTX
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
PDF
GDPR for your Payroll Bureau
PPTX
What does GDPR mean for your business?
PPTX
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
PDF
10 Key GDPR Requirements You Must Know to Protect Your Business
PDF
GDPR: What does it mean for your business?
PPTX
GDPR Breakfast Briefing for Business Advisors
PDF
Gdpr for business full
PDF
A practical guide to GDPR preparation
PDF
GDPR: how IT works
PPTX
SCCE Processors and GDPR
PDF
GDPR for your Payroll Bureau
PPTX
Prepare Your Firm for GDPR
PDF
Horner Downey & Co Newsletter- GDPR
PDF
GDPR: What does it mean for your business?
PPTX
General Data Protection Regulation (GDPR)
PDF
How will GDPR affect small businesses?
PPTX
GDPR: Your Journey to Compliance
PPTX
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
PPTX
GDPR Enforcement is here. Are you ready?
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
GDPR for your Payroll Bureau
What does GDPR mean for your business?
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
10 Key GDPR Requirements You Must Know to Protect Your Business
GDPR: What does it mean for your business?
GDPR Breakfast Briefing for Business Advisors
Gdpr for business full
A practical guide to GDPR preparation
GDPR: how IT works
SCCE Processors and GDPR
GDPR for your Payroll Bureau
Prepare Your Firm for GDPR
Horner Downey & Co Newsletter- GDPR
GDPR: What does it mean for your business?
General Data Protection Regulation (GDPR)
How will GDPR affect small businesses?
GDPR: Your Journey to Compliance
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Enforcement is here. Are you ready?
Ad

More from Jason Chapman (20)

PPTX
Maths hub workgroup overview 2018 19
PPT
CBC – Wills and Lasting Powers of Attorney
PPTX
Ppt11 portfolio v2 slide share
PPTX
CBC GDPR – 1 month to go
PPTX
CBC GDPR The Physics
PPTX
Referrals
PPTX
CBC Referrals
PPTX
Rare design portfolio presentation 10
PPTX
Ppt9 portfolio
PPTX
CBC Presentation 22-May-2017
PPTX
Mind Keys
PPTX
Cma cbc overview 280217
PPTX
CBC Action Coach (Mind Body Heart Spirit Presentation)
PPTX
Rare portfolio dec16
PPTX
PPT7 portfolio
PPTX
PPT6 portfolio
PPTX
Rare Design Case Study Mead Open Farm
PPTX
Rare Design Case Study Vodafone
PPTX
Rare Case Study Ibicus
PDF
Ppt2 portfolio 3
Maths hub workgroup overview 2018 19
CBC – Wills and Lasting Powers of Attorney
Ppt11 portfolio v2 slide share
CBC GDPR – 1 month to go
CBC GDPR The Physics
Referrals
CBC Referrals
Rare design portfolio presentation 10
Ppt9 portfolio
CBC Presentation 22-May-2017
Mind Keys
Cma cbc overview 280217
CBC Action Coach (Mind Body Heart Spirit Presentation)
Rare portfolio dec16
PPT7 portfolio
PPT6 portfolio
Rare Design Case Study Mead Open Farm
Rare Design Case Study Vodafone
Rare Case Study Ibicus
Ppt2 portfolio 3

Recently uploaded (20)

PDF
COST SHEET- Tender and Quotation unit 2.pdf
PDF
Unit 1 Cost Accounting - Cost sheet
PDF
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PPTX
HR Introduction Slide (1).pptx on hr intro
PDF
Laughter Yoga Basic Learning Workshop Manual
PDF
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
PPTX
5 Stages of group development guide.pptx
PDF
Types of control:Qualitative vs Quantitative
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PPT
Data mining for business intelligence ch04 sharda
PDF
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
DOCX
Euro SEO Services 1st 3 General Updates.docx
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
PPTX
Business Ethics - An introduction and its overview.pptx
PDF
Chapter 5_Foreign Exchange Market in .pdf
PDF
MSPs in 10 Words - Created by US MSP Network
PPTX
Lecture (1)-Introduction.pptx business communication
PDF
Dr. Enrique Segura Ense Group - A Self-Made Entrepreneur And Executive
COST SHEET- Tender and Quotation unit 2.pdf
Unit 1 Cost Accounting - Cost sheet
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
New Microsoft PowerPoint Presentation - Copy.pptx
ICG2025_ICG 6th steering committee 30-8-24.pptx
HR Introduction Slide (1).pptx on hr intro
Laughter Yoga Basic Learning Workshop Manual
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
5 Stages of group development guide.pptx
Types of control:Qualitative vs Quantitative
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
Data mining for business intelligence ch04 sharda
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
Euro SEO Services 1st 3 General Updates.docx
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
Business Ethics - An introduction and its overview.pptx
Chapter 5_Foreign Exchange Market in .pdf
MSPs in 10 Words - Created by US MSP Network
Lecture (1)-Introduction.pptx business communication
Dr. Enrique Segura Ense Group - A Self-Made Entrepreneur And Executive

GDPR Jan 2018 1

  • 2. ARE YOU READY FOR GENERAL DATA PROTECTION REGULATIONS (GDPR)?
  • 3. GENERAL DATA PROTECTION REGULATIONS (GDPR) GDPR comes into effect May 2018 Initially EU ‘driven’ – set to become a worldwide standard - builds upon existing data protection rules Information Commissioner’s Office (ICO) is relevant U.K. ‘body’
  • 4. GENERAL DATA PROTECTION REGULATIONS (GDPR) Prompted by the growth in data processing Evolution rather than revolution of the rules Not a new Millennium Bug Aim to achieve privacy by design and default
  • 5. GENERAL DATA PROTECTION REGULATIONS (GDPR) Requires personal data (PD) to be respected - Accountability - Transparency - Individuals’ rights An obligation on all businesses/organisations Severe penalties for non- compliance
  • 6. GENERAL DATA PROTECTION REGULATIONS (GDPR) Important in terms of client reassurance An opportunity to focus on client care Positive use of GDPR
  • 7. GENERAL DATA PROTECTION REGULATIONS (GDPR) Organisations are required to have a legal basis to process 1. Contract 2. Consent 3. Vital Interest 4. Public Task 5. Comply with legal obligations 6. Legitimate Interests
  • 8. GENERAL DATA PROTECTION REGULATIONS (GDPR) Segmentation appropriate i.e. - Contract basis for preparing wills/LPAs etc. - Consent basis for marketing communication A ‘granular‘ approach required - Consent cannot be ‘bundled’ Consent must be ‘active’
  • 9. GENERAL DATA PROTECTION REGULATIONS (GDPR) Privacy statements to include: - Legal basis for processing data - What is to happen to the data - What a client does if there’s a problem On website and in terms of trading
  • 10. GENERAL DATA PROTECTION REGULATIONS (GDPR) Imposes general obligation to implement technical and organisational measures to show that consideration has been given to data protection when processing.
  • 11. GENERAL DATA PROTECTION REGULATIONS (GDPR) IOC checklist: Privacy Impact Assessment (PIA) Audit and log what PD held and how it flows Document who PD comes from - what you do with it - with whom you share it
  • 12. GENERAL DATA PROTECTION REGULATIONS (GDPR) Identify and document lawful basis for processing PD Review and record how consent is obtained and recorded Establish means to record/manage ongoing consent
  • 13. GENERAL DATA PROTECTION REGULATIONS (GDPR) Maintain registration with ICO Ensure privacy notices readily available Concise - easy to understand - identifies you – confirms how PD to be handled - with whom shared – how long to be retained
  • 14. GENERAL DATA PROTECTION REGULATIONS (GDPR) Establish right for individuals to access PD Establish process to keep PD accurate and up to date (relevant for wills/LPAs?) Provide for effective destruction of PD no longer required.
  • 15. GENERAL DATA PROTECTION REGULATIONS (GDPR) Establish procedure to respond to clients’ requests to restrict processing Allow individuals to copy/move their PD Reference to automated decision making (NA)
  • 16. GENERAL DATA PROTECTION REGULATIONS (GDPR) Ensure data protection policy in place and review compliance periodically Provide data protection training for all staff Written contract with appropriately vetted ‘data processors’
  • 17. GENERAL DATA PROTECTION REGULATIONS (GDPR) Clear security policies and procedures – regularly reviewed Ensure data protection is integrated into all activities Understand when and how Data Protection Impact Assessments (DPIAs) should be used.
  • 18. GENERAL DATA PROTECTION REGULATIONS (GDPR) Nominate Data Protection Officer (DPO) Promote positive culture of data protection Develop and maintain an information security policy
  • 19. GENERAL DATA PROTECTION REGULATIONS (GDPR) Special rules for any information transferred beyond the EEA Establish procedure to deal with identifying, reporting, managing and resolving PD breaches
  • 20. GENERAL DATA PROTECTION REGULATIONS (GDPR) That’s all there is to it !