SlideShare a Scribd company logo
GDPR – Big Bang
or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
OVERVIEW
 Moore Law
• What’s the fuss?
• Big Bang Theory?
• Reality = Evolution?
• Accountability
• Compliance / Privacy by Design
• Demonstrating Consent
• ‘Appropriate’ Measures
• Opportunities (& Competitive Edge)
 Contacts
What’s the Fuss?
 “GDPR affects anyone holding data on EU citizens.
A survey of 1350 companies around the world by
cybersecurity firm NTT found that a lot of them
have no clue about this yet, even Europeans
seemed unaware. The Brits were the worst. 39% of
UK companies realised that they were subject to
the regulation.” TheRegister.co.uk
 ‘Personal Data' – Employees, clients, users / suppliers
 Presumption of application to businesses
 Enhanced enforcement / fines for data protection
breaches
 Deadline for implementation = 25 May 2018
Big Bang Theory?
 1995 EU Data Protection Directive –>DPA 98
 Applies broadly to the collection and processing of data able
to identify living individuals (filing system) = ‘Person Data”
 DPA 98 introduced 6 x Data Principles:
 Lawfulness, fairness and transparency
 Purpose limitation
 Data Minimisation
 Accuracy
 Storage Limitation
 Integrity & Confidentiality
 Definitions: ‘Data Controller’ / ‘Data Processor’ / ‘Sensitive
Personal Data’/ ‘Consent’
 Roles: Data Protection Officer (DPO)
Reality = Evolution
 GDPR = accepts the world has moved and extends the existing Principles:
• All EU-based businesses
• Any business targeting EU citizens (USA, Australia, etc)
• All EU citizens
 Regulation vs Directive
• GDPR = Direct Effect
• No domestic Member State law required
• Intended to promote greater harmonisation and consistency across EU in
terms of application and interpretation
 Reverses DPA 98 position
• Register with Information Commissioner’s Office (ICO) –> inference of
application
• DPA 98 -> Data Protection Bill (Post-Brexit)
Accountability
 Accountability
• Move away from mere lip service. Businesses have to demonstrate
(ongoing) compliance, often in written form:
• Internal policies and processes that are GDPR-compliant
• Implementation of the policies and processes
• Effective internal compliance measures.
• External controls & contracting (model clauses)
 Demonstrable protections for specific types of data / subjects:
• Sensitive Personal Data (genetic, biometric)
• Children (16+ / 13+)
 Introduces new concepts
• Data Protection Risk Assessment
• Pseudonymisation (vs anonymisation) to better protect data
Compliance/
Privacy by Design
 Day-to-day compliance –> Obligation to justify data position to Regulator (ICO)
• What is the purpose the data will be used for
• Retained solely to fulfil the stated purpose
• Where it will be stored (UK / EU / EEA)
• Not keep for longer than necessary (2 years?)
• Uphold data subjects rights (right of access / right to be forgotten / data
portability)
• Data Controllers and Data Processers are treated equally (previous focus on DCs)
• Data Controllers required to perform due diligence on Data Processers (supply chain)
• DPO requirement (or justify why not have one)
 Breaches – Obligation to Report
 Regulator will look at what has happened, why, and whether ‘appropriate’ measures
put in place to safeguard data.
 ICO extended powers £500,000 -> €20,000,000 / 4% Global Turnover (+ PR DAMAGE)
 Specific (6) justifications for collecting data: performance of
contract / compliance with legal obligation / vital interests / public
interest / legitimate interests of DC / consent
• Implied consent no longer valid – ICO / pre-checked boxes /
‘continue to use our site accept our Ts&Cs’
 Have to be able to prove actual consent: ‘freely given, specific,
informed & unambiguous’
 Children: must be able to demonstrate steps to show capability
• GDPR @ 16+
• Member State discretion @ 13+ (UK)
 Death of Data
• Reassess sign-up / consent processes -> compliant
• Death of data – can’t rely on past consent for post May 2018
Demonstrating Consent
 Must be able to demonstrate ‘appropriate technical and
organisational measures’ for data compliance / protection
• Demonstrate how and why collect personal data
• ‘Consent’ / Privacy Policy / Terms & Conditions / Terms of Use
 Internal processes
• Data risk Impact Assessment / Data Use Policy / Data Retention
Policy / Employment Contracts
 Awareness of GDPR principles - Staff training / DPO (qualified)
 Contractual Relationships - GDPR model clauses incorporated
 Breach Obligations
• Requirement to log breaches
• Report to the Regulator (and potentially data subjects) within 72
hours of a notifiable breach
‘Appropriate’ Measures
 GDPR is a reality
 Brexit – GDPR continue to apply if businesses target EU will apply
• -> Data Protection Bill
• -> UK require an ‘equivalent’ regime
 Businesses need to assess own situation / audit
• how & why collect data (consent, etc) / how protect data / enforcement
policies (internal & external) / supplier terms.
 Case Studies
• Clients wanting to get their house in order – Compliance = Biz Dev
• Breach = costly (£££) + PR / Reputational risk
 Bigger businesses doing GDPR due diligence:
• expect their supply chains to have ‘adequate’ measures in place
• want to see policies (privacy / data protection / data retention)
• expect awareness of GDPR implications
• practical importance of new concepts – i.e. pseudonymisation
Opportunities
(& Competitive Edge)
 Scott Appleton
 scottappleton@moore-law.co.uk
 T 01237 704789
 M 07557 447054
 @TalkingLawyer

More Related Content

PPTX
Findability Day 2016 - What is GDPR?
PDF
MindMap AVG Louwers Advocaten V 4.0 (EN)
PPTX
Taking the Fear Out of GDPR
PDF
GDPR Overview
PPT
Data protection
PPTX
ABM Display Advertising Success in the World of GDPR [PPT]
PPTX
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
PDF
GDPR and Irish SMEs May 2017
Findability Day 2016 - What is GDPR?
MindMap AVG Louwers Advocaten V 4.0 (EN)
Taking the Fear Out of GDPR
GDPR Overview
Data protection
ABM Display Advertising Success in the World of GDPR [PPT]
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
GDPR and Irish SMEs May 2017

What's hot (19)

PDF
GDPR what you should know and how to minimize impact on your business
PPTX
Simple GDPR Overview
PPTX
GDPR security services - Areyou ready ?
PPTX
Quick Introduction to the EU GDPR by Sami Zahran
PPTX
Ready for the GDPR, Ready for the Digital Economy
PPTX
The Meaning and Impact of the General Data Protection Regulation
PPTX
Preparing for general data protection regulations (gdpr) within the hous...
PPTX
GDPR: Training Materials by Qualsys
PPTX
Gdpr action plan - ISSA
PDF
Checklist for SMEs for GDPR compliance
PPTX
The Practical Impact of the General Data Protection Regulation
PDF
The Essential Guide to GDPR
PPTX
Sophie's Privacy - a story about GDPR
PPTX
General Data Protection Regulation
PPTX
European GDPR for Good Technology Collective (GTC)
PDF
What is the new data protection regulation GDPR and why should you care? Jesp...
PDF
GDPR in a nutshell
PPTX
GDPR – The Practicalities of a New Reality
GDPR what you should know and how to minimize impact on your business
Simple GDPR Overview
GDPR security services - Areyou ready ?
Quick Introduction to the EU GDPR by Sami Zahran
Ready for the GDPR, Ready for the Digital Economy
The Meaning and Impact of the General Data Protection Regulation
Preparing for general data protection regulations (gdpr) within the hous...
GDPR: Training Materials by Qualsys
Gdpr action plan - ISSA
Checklist for SMEs for GDPR compliance
The Practical Impact of the General Data Protection Regulation
The Essential Guide to GDPR
Sophie's Privacy - a story about GDPR
General Data Protection Regulation
European GDPR for Good Technology Collective (GTC)
What is the new data protection regulation GDPR and why should you care? Jesp...
GDPR in a nutshell
GDPR – The Practicalities of a New Reality
Ad

Similar to Scott Appleton: GDPR - Big Bang or Data Evolution? (20)

PPTX
What is the General Data Protection Regulation (GDPR)?
PPTX
A Brief Overview on GDPR
PDF
#HR and #GDPR: Preparing for 2018 Compliance
PPTX
My presentation- Ala about privacy and GDPR
PPT
GDPR webinar presentation | LawBite
PPTX
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
PPTX
Ritz 4th-july-gdpr
PPTX
EU GDPR(general data protection regulation)
PPTX
What does GDPR mean for your business?
PPTX
GDPR Enforcement is here. Are you ready?
PPTX
GDPR- GENERAL DATA PROTECTION REGULATION
PPTX
GDPR- GENERAL DATA PROTECTION REGULATION
PDF
LW-Privacy-GDPR-Compliance-Checklist.pdf
PPSX
Gdpr demystified - making sense of the regulation
PPTX
GDPR: Your Journey to Compliance
PPT
The Countdown is on: Key Things to Know About the GDPR
PPTX
Prepare Your Firm for GDPR
PDF
GDPR most actionable cheatsheet and checklist by cyberstratg
PDF
Mcis 2018 DEFeND Project
PPTX
Vuzion Love Cloud GDPR Event
What is the General Data Protection Regulation (GDPR)?
A Brief Overview on GDPR
#HR and #GDPR: Preparing for 2018 Compliance
My presentation- Ala about privacy and GDPR
GDPR webinar presentation | LawBite
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Ritz 4th-july-gdpr
EU GDPR(general data protection regulation)
What does GDPR mean for your business?
GDPR Enforcement is here. Are you ready?
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
LW-Privacy-GDPR-Compliance-Checklist.pdf
Gdpr demystified - making sense of the regulation
GDPR: Your Journey to Compliance
The Countdown is on: Key Things to Know About the GDPR
Prepare Your Firm for GDPR
GDPR most actionable cheatsheet and checklist by cyberstratg
Mcis 2018 DEFeND Project
Vuzion Love Cloud GDPR Event
Ad

Recently uploaded (20)

PDF
Ricado Antonio Pellerano Paradas The Criminal
PPTX
Constitution of india module one of ktu
PPTX
lecture 5.pptx on family law notes well detailed
PDF
The family of Tagin tribe of Arunachal Pradesh -- by B_B_ Pandey -- First edi...
PPTX
kabarak lecture 2.pptx on development of family law in kenya
PPTX
Basic key concepts of law by Shivam Dhawal
PPTX
DepEd 4A Gender Issues and Promoting Gender Equality.pptx
PPT
LAW OF TORT IN VICARIOUS LIABILITY COMPLETE
PPTX
Sexual Harassment Prevention training class
PPT
2025 KATARUNGANG PAMBARANGAY LECTURE.ppt
PPTX
BL - Chapter 1 - Law and Legal Reasoning
PDF
NRL_Legal Regulation of Forests and Wildlife.pdf
PPTX
Philippine Politics and Governance - Lesson 10 - The Executive Branch
PDF
8-14-25 Examiner Report from NJ Bankruptcy (Heller)
PDF
Palghar-SGupta-ScreesnShots-12Aug25.pdf The image of the voter list with phot...
PPTX
Evolution of First Amendment Jurisprudence.pptx
PDF
Brown and Beige Vintage Classic Illustration Paper Project History Presenta_2...
PPTX
PoSH act in a nutshell by Lovely Kumari .pptx
PDF
OBLICON (Civil Law of the Philippines) Obligations and Contracts
PPTX
Democracy DISCUSSION//////////////////////////.pptx
Ricado Antonio Pellerano Paradas The Criminal
Constitution of india module one of ktu
lecture 5.pptx on family law notes well detailed
The family of Tagin tribe of Arunachal Pradesh -- by B_B_ Pandey -- First edi...
kabarak lecture 2.pptx on development of family law in kenya
Basic key concepts of law by Shivam Dhawal
DepEd 4A Gender Issues and Promoting Gender Equality.pptx
LAW OF TORT IN VICARIOUS LIABILITY COMPLETE
Sexual Harassment Prevention training class
2025 KATARUNGANG PAMBARANGAY LECTURE.ppt
BL - Chapter 1 - Law and Legal Reasoning
NRL_Legal Regulation of Forests and Wildlife.pdf
Philippine Politics and Governance - Lesson 10 - The Executive Branch
8-14-25 Examiner Report from NJ Bankruptcy (Heller)
Palghar-SGupta-ScreesnShots-12Aug25.pdf The image of the voter list with phot...
Evolution of First Amendment Jurisprudence.pptx
Brown and Beige Vintage Classic Illustration Paper Project History Presenta_2...
PoSH act in a nutshell by Lovely Kumari .pptx
OBLICON (Civil Law of the Philippines) Obligations and Contracts
Democracy DISCUSSION//////////////////////////.pptx

Scott Appleton: GDPR - Big Bang or Data Evolution?

  • 1. GDPR – Big Bang or Data Evolution?
  • 3. OVERVIEW  Moore Law • What’s the fuss? • Big Bang Theory? • Reality = Evolution? • Accountability • Compliance / Privacy by Design • Demonstrating Consent • ‘Appropriate’ Measures • Opportunities (& Competitive Edge)  Contacts
  • 4. What’s the Fuss?  “GDPR affects anyone holding data on EU citizens. A survey of 1350 companies around the world by cybersecurity firm NTT found that a lot of them have no clue about this yet, even Europeans seemed unaware. The Brits were the worst. 39% of UK companies realised that they were subject to the regulation.” TheRegister.co.uk  ‘Personal Data' – Employees, clients, users / suppliers  Presumption of application to businesses  Enhanced enforcement / fines for data protection breaches  Deadline for implementation = 25 May 2018
  • 5. Big Bang Theory?  1995 EU Data Protection Directive –>DPA 98  Applies broadly to the collection and processing of data able to identify living individuals (filing system) = ‘Person Data”  DPA 98 introduced 6 x Data Principles:  Lawfulness, fairness and transparency  Purpose limitation  Data Minimisation  Accuracy  Storage Limitation  Integrity & Confidentiality  Definitions: ‘Data Controller’ / ‘Data Processor’ / ‘Sensitive Personal Data’/ ‘Consent’  Roles: Data Protection Officer (DPO)
  • 6. Reality = Evolution  GDPR = accepts the world has moved and extends the existing Principles: • All EU-based businesses • Any business targeting EU citizens (USA, Australia, etc) • All EU citizens  Regulation vs Directive • GDPR = Direct Effect • No domestic Member State law required • Intended to promote greater harmonisation and consistency across EU in terms of application and interpretation  Reverses DPA 98 position • Register with Information Commissioner’s Office (ICO) –> inference of application • DPA 98 -> Data Protection Bill (Post-Brexit)
  • 7. Accountability  Accountability • Move away from mere lip service. Businesses have to demonstrate (ongoing) compliance, often in written form: • Internal policies and processes that are GDPR-compliant • Implementation of the policies and processes • Effective internal compliance measures. • External controls & contracting (model clauses)  Demonstrable protections for specific types of data / subjects: • Sensitive Personal Data (genetic, biometric) • Children (16+ / 13+)  Introduces new concepts • Data Protection Risk Assessment • Pseudonymisation (vs anonymisation) to better protect data
  • 8. Compliance/ Privacy by Design  Day-to-day compliance –> Obligation to justify data position to Regulator (ICO) • What is the purpose the data will be used for • Retained solely to fulfil the stated purpose • Where it will be stored (UK / EU / EEA) • Not keep for longer than necessary (2 years?) • Uphold data subjects rights (right of access / right to be forgotten / data portability) • Data Controllers and Data Processers are treated equally (previous focus on DCs) • Data Controllers required to perform due diligence on Data Processers (supply chain) • DPO requirement (or justify why not have one)  Breaches – Obligation to Report  Regulator will look at what has happened, why, and whether ‘appropriate’ measures put in place to safeguard data.  ICO extended powers £500,000 -> €20,000,000 / 4% Global Turnover (+ PR DAMAGE)
  • 9.  Specific (6) justifications for collecting data: performance of contract / compliance with legal obligation / vital interests / public interest / legitimate interests of DC / consent • Implied consent no longer valid – ICO / pre-checked boxes / ‘continue to use our site accept our Ts&Cs’  Have to be able to prove actual consent: ‘freely given, specific, informed & unambiguous’  Children: must be able to demonstrate steps to show capability • GDPR @ 16+ • Member State discretion @ 13+ (UK)  Death of Data • Reassess sign-up / consent processes -> compliant • Death of data – can’t rely on past consent for post May 2018 Demonstrating Consent
  • 10.  Must be able to demonstrate ‘appropriate technical and organisational measures’ for data compliance / protection • Demonstrate how and why collect personal data • ‘Consent’ / Privacy Policy / Terms & Conditions / Terms of Use  Internal processes • Data risk Impact Assessment / Data Use Policy / Data Retention Policy / Employment Contracts  Awareness of GDPR principles - Staff training / DPO (qualified)  Contractual Relationships - GDPR model clauses incorporated  Breach Obligations • Requirement to log breaches • Report to the Regulator (and potentially data subjects) within 72 hours of a notifiable breach ‘Appropriate’ Measures
  • 11.  GDPR is a reality  Brexit – GDPR continue to apply if businesses target EU will apply • -> Data Protection Bill • -> UK require an ‘equivalent’ regime  Businesses need to assess own situation / audit • how & why collect data (consent, etc) / how protect data / enforcement policies (internal & external) / supplier terms.  Case Studies • Clients wanting to get their house in order – Compliance = Biz Dev • Breach = costly (£££) + PR / Reputational risk  Bigger businesses doing GDPR due diligence: • expect their supply chains to have ‘adequate’ measures in place • want to see policies (privacy / data protection / data retention) • expect awareness of GDPR implications • practical importance of new concepts – i.e. pseudonymisation Opportunities (& Competitive Edge)
  • 12.  Scott Appleton  scottappleton@moore-law.co.uk  T 01237 704789  M 07557 447054  @TalkingLawyer

Editor's Notes

  • #9: DPO – scale of collection / processing / size / dealing with sensitive data / public body (+ adequately qualified -> reporting to Senior Management). Justify why not.
  • #11: CONSIDER IF THERE IS SCOPE OR TIME TO EXPLORE REVOCATION, INVALIDITY AND GROUNDS FOR OPPOSITION. THIS WILL LIKELY FALL UNDER THE DUE DILIGENCE CATEGORY ABOVE. IT IS IMPORTANT FOR CLIENTS TO APPRECIATE THAT TRADEMARK APPLICATIONS CAN SOMETIMES DRAW ATTENTION FROM MUCH LARGER RIGHTS HOLDERS WITH DEEPER POCKETS WHO ARE AGGRESSIVE ABOUT PURSUING INFRINGERS. SMALLER ORGANISATIONS OPERATING UNDER THE RADAR MAY HAVE HITHERTO GONE UNNOTICED BUT APPLYING FOR A REGISTERED TRADEMARK MAY BRING YOU TO THEIR ATTENTION. ALSO THE POINT SHOULD BE MADE THAT IT IS NOT UNUSUAL TO BE SURPRISED BY A CAUTIOUS EXAMINER’S VIEW WHICH MIGHT INCLUDE NOTIFICATION WHERE IT WOULD NOT SEEM TO BE MERITED.
  • #12: Ketchup – more sales / bigger bottles = easier to use 112 iteration 1991 – 95 $13m Licensing NASA / HEINZ etc Patent Box - JCL (80% sales on patented driver)