mark gracey [email protected] of processing - data subject has given consent required for...

39
How the GDPR will change the way you do business Mark Gracey [email protected]

Upload: buiquynh

Post on 15-Apr-2018

214 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

How the GDPR will change the way you do business

Mark [email protected]

Page 2: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Welcome

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

MarkGraceyFounder,FlavourfyDigitalConsultancy&DigitalComplianceHub

Page 3: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’sGDPR?

? !DoIneedtoworryaboutit?

"WhatdoIdoto

comply?

GDPRCompliance

Page 4: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

About data protection

Page 5: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Key Data Protection Definitions

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

PersonalData

Processing

DataSubject

DataController

DataProcessor

Page 6: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

The Principles of Data Protection

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Lawful,fair&transparent Specificpurpose Relevant

Accurate Retention Security

Individuals'rights

Internationaltransfer

Page 7: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Lawfulness of processing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

DataSubjecthasgivenconsent

Requiredforperformanceofacontract

Legalobligation

ToprotectinterestsoftheDataSubject

Inthepublicinterest

LegitimateinterestsoftheDataController

Page 8: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

General Data Protection Regulation

Page 9: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR: What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

GDPRMay2018

Scope

Accountability

Children

Consent

Rights Processors

By Design

DPOs

Breaches

Fines

Page 10: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Scope

AppliesacrossthewholeoftheEU

Affectsanynon-EUbusinessofferinggoods

andservicestoEUcitizens

Onlineidentifiersincludedindefinitionofpersonal

data

Page 11: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Accountability

Demonstrationofcompliance

Recordprocessingactivities

Page 12: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Children &OnlineServices

Childfriendlingmessaging

Guardianconsent

Ageverification

Page 13: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Consent

Clearmessaging

Positiveopt-in

Recordingconsent

Consentwithoutdetriment

Withdrawingconsent

Page 14: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Rights

Righttobeinformed

Subjectaccessrequests:nofee,lesstime

Therighttoerasure

Therighttodataportability

Page 15: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Processors

Controller– Processorrelationship

Contractualterms

Processorresponsibilities

Page 16: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

By Design

ByDesign&Default

DPIA

Page 17: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

DPOs

Specificperson

responsibleforcompliance

Page 18: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Breaches

Breachnotificationtoregulatorybody

Breachnotificationtodatasubjects

Page 19: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

What’s changing?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Fines

Upto4%ofglobal

turnoveror€20m

Page 20: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Marketing

Page 21: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Marketing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Consentfornewdata

ThirdPartyData

LegacyData

OngoingManagement

Page 22: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Marketing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Consentfornewdata

Auditexistingdatacapture

Adjustdatacapture&privacynoticestobeGDPRcompliant

Recordyourapproachand

findings

Page 23: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Marketing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

ThirdPartyData

Carryoutduediligenceon

providerandsource

Appropriateconsentandproof?

Recordyourapproachand

findings

Page 24: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Marketing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

LegacyData

DoesyourdatameetthenewGDPRconsent

rules?

Canyoulawfullyre-

verifyconsent?

Anopportunitytorefreshyour

data?

Recordyourapproachand

findings

Page 25: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Marketing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

OngoingManagement

Regulardataquality&consentrefresh

Makeiteasyforconsentwithdrawal

Actonwithdrawalofconsentimmediately

&remember

Documentyour

approach

MakesureyourteamaretrainedinthewaysoftheGDPR

Page 26: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Marketing compliance in the UK

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

DataProtection• lawfulbasisforprocessing

PrivacyRules• marketingrules

MarketingCompliance

Page 27: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR, Privacy and marketing

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Marketingdata

"Cold"consumers

Customers

Soletraders

Individualsinbusiness

Genericbusinessdata

Page 28: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Controller - Processor

Page 29: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Controller – Processor relationship

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

DataController

DataProcessor

Whichareyou?

Page 30: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Controller – Processor relationship

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Data

Controller

UseonlyprocessorsthatareGDPRcompliant

Carryoutduediligenceonthirdpartyprocessors

Putinplacecontractualrequirements

Page 31: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

GDPR challenge: Controller – Processor relationship

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Data

Processor

Expectduediligencefromclients

Expectstrictercontractualterms

Newresponsibilities

Page 32: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Being GDPR compliant

Page 33: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Steps to compliance

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Appointsomeonetotakeresponsibilityandactasasinglepointofcontact

Audityourdata,systemsandpolicies

Documentyourapproachtodataprotection&putpoliciesinplace

Provideinternaldocumentationandguidance

Trainyourstaff

Maintainyourcompliance&keepuptodate

Page 34: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Preparing your business for the GDPR

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Prepare

• KnowtheGDPR

• Getseniorbuy-in

• Setupaworkinggroup

Audit

• Data• Systems• Policies

Analyse

• Thestateofyourdata

• Policyupdates

• Systemchanges

Deliver

• Actionplan• Employeetraining

Manage

• Ongoingcompliance

• Keepuptodate

Page 35: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Managing Compliance

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

Security

Training

Policies

Review

UserRights

EffectivelymanagingyourGDPRcompliancewillnotonlyprotectyourbusinessbutwillinstilltrustandconfidenceinyourcustomersandfuturecustomers

Page 36: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

But… what else?

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

ePrivacyRegulations

DataProtection

Bill

ICOGuidanceGDPR2018&

BeyondA29WPGuidance

EnforcementBrexit

Page 37: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Digital Compliance Hub – Managing your compliance

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

DataProtection

&GDPR

$Privacy&Marketing

%Web,Data&CyberSecurity

Info,guidance,toolkits,advice,support&training

https://digitalcompliancehub.co.uk

Page 38: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

Flavourfy Digital Consultancy

https://flavourfydigital.co.uk - https://digitalcompliancehub.co.uk

&Compliance

Audits

'Management

(Consultancy&

Advice

)Training

DigitalComplianceHub

[email protected]://flavourfydigital.co.uk

Page 39: Mark Gracey mark@flavourfy.co of processing  - Data Subject has given consent Required for performance of a contract Legal obligation To protect interests of …

?MarkGracey

[email protected]

https://flavourfydigital.co.ukhttps://digitalcompliancehub.co.uk

Question Mark