clie ntsg o fur ther faste rwith
play

Clie ntsg o fur ther , faste rwith Je ffre y Ja c o b s, E sq . - PowerPoint PPT Presentation

Clie ntsg o fur ther , faste rwith Je ffre y Ja c o b s, E sq . Dillo n Cra ig Do minic Cutri Ma rc h 13, 2018 Pe o ple . Pa rtne rship. Pe rfo rma nc e . Re g ula tio n Pro te c tio n Are Yo u Re a dy? Ge ne ra l Da ta Wha t is the


  1. Clie ntsg o fur ther , faste rwith Je ffre y Ja c o b s, E sq . Dillo n Cra ig Do minic Cutri Ma rc h 13, 2018 Pe o ple . Pa rtne rship. Pe rfo rma nc e .

  2. Re g ula tio n Pro te c tio n Are Yo u Re a dy? Ge ne ra l Da ta

  3. Wha t is the GDPR a nd wha t we nt b e fo re ? • T he muc h a ntic ipa te d Ge ne ra l Da ta Prote c tion Re g ula tion (GDPR) is the ne xt b ig c ha lle ng e o n the da ta priva c y ho rizo n. • T he GDPR will a pply a c ro ss the E urope a n E c onomic Are a GDPR A”) fro m 25 Ma y 2018 whe n the Da ta Pro te c tio n Dire c tive (“E E 95/ 46/ E C(“Dire c tive ”) is re pe a le d. • T he Dire c tive so ug ht to pro te c t the rig hts a nd fre e do ms o f individua ls re la ting to the pro c e ssing o f Pe rso na l Da ta while se e king to e nsure a fre e flo w o f pe rso na l da ta b e twe e n Me mb e r Sta te s.

  4. Why wa s the re a ne e d fo r c ha ng e ? • Sub sta ntia l inc re a se in c ross- borde r da ta flows • T hre a ts po se d b y ra pid te c hnolog ic a l c ha ng e a nd g loba lisa tion • Pa tc hwork o f c o untry-b y-c o untry Dire c tive imple me nting re g ula tio ns • Ne e d to b a la nc e the rig hts of individua ls to pro te c t the ir pe rso na l da ta a nd the inte re sts of busine sse s a nd public a uthoritie s in pro c e ssing tha t da ta

  5. Aims o f the GDPR T he GDPR e nvisa g e s: GDPR • a c o he re nt da ta pro te c tio n fra me wo rk; • stro ng e nfo rc e me nt; • da ta pro te c tio n a s pa rt o f the de ve lo pme nt o f the dig ita l e c o no my a c ro ss the inte rna l ma rke t; • g re a te r c o ntro l b y individua ls o f the ir pe rso na l da ta ; a nd • e nha nc e d le g a l a nd pra c tic a l c e rta inty fo r individua ls, b usine sse s a nd pub lic a utho ritie s.

  6. Wha t kind o f info rma tio n is “ Pe rsona l Da ta ”? Pe rsona l da ta is a ny info rma tio n re la ting to a n ide ntifie d o r ide ntifia b le na tura l pe rso n (the Da ta Sub je c t). F o r e xa mple a na me , a n ide ntific a tio n numb e r, a n a c c o unt numb e r, lo c a tio n da ta , a n o nline ide ntifie r o r o ne o r mo re fa c to rs spe c ific to the physic a l, physio lo g ic a l, g e ne tic , me nta l, e c o no mic , c ultura l o r so c ia l ide ntity o f a na tura l pe rso n. Wha t do e s " Proc e ssing " me a n? Proc e ssing me a ns a ny o pe ra tio n tha t is pe rfo rme d o n pe rso na l da ta , suc h a s c o lle c tio n, re c o rding , sto ra g e , a da pta tio n o r a lte ra tio n, re trie va l, use , disc lo sure b y tra nsmissio n, disse mina tio n o r o the rwise ma king a va ila b le , c o mb ina tio n, re stric tio n, e ra sure o r de struc tio n. E sse ntia lly, a nything tha t is done to or with pe rsona l da ta is “proc e ssing ”.

  7. “Da ta Pro te c tio n”: who is be ing prote c te d? T he Da ta Sub je c t is b e ing pro te c te d. GDPR pro vide s a b a la nc e b e twe e n the Da ta Sub je c t’ s rig hts re g a rding the pro c e ssing o f his o r he r pe rso na l da ta with the rig hts o f o rg a nisa tio ns to pro c e ss pe rso na l da ta in the c o urse o f b usine ss a nd in a c c o rda nc e with the ir o b lig a tio ns unde r GDPR. Who c ontrols yo ur pe rsona l da ta ? T he Controlle r is the na tura l o r le g a l pe rso n, pub lic a utho rity, a g e nc y o r a ny o the r e ntity tha t a lo ne o r jo intly with o the rs de te rmine s the purpo se s a nd me a ns o f the pro c e ssing o f pe rsona l da ta . Who proc e sse s yo ur pe rsona l da ta ? T he Proc e ssor is a na tura l o r le g a l pe rso n, pub lic a utho rity, a g e nc y o r a ny o the r e ntity tha t pro c e sse s pe rso na l da ta o n be half o f the c o ntro lle r.

  8. Wha t a re the e sse ntia l diffe re nc e s b e twe e n c ontrolle rs a nd proc e ssors ? T he c ontrolle r ha s o ve ra ll c o ntro l o ve r the da ta pro c e ssing . T he c o ntro lle r de c ide s to c o lle c t the pe rso na l da ta in the first pla c e a nd de te rmine s the le g a l b a sis fo r do ing so ; de te rmine s the purpo se (s) fo r whic h the da ta will b e use d; a nd de c ide s whe the r to disc lo se the da ta a nd, if so , to who m. T he proc e ssor use s its te c hnic a l kno wle dg e to de c ide ho w to c a rry o ut the da ta pro c e ssing o n b e ha lf o f the c o ntro lle r - wha t I T syste ms o r o the r me tho ds to use to c o lle c t pe rso na l da ta ; ho w to sto re the pe rso na l da ta ; a nd, the me a ns use d to tra nsfe r the pe rso na l da ta fro m o ne o rg a nisa tio n to a no the r - it c a nno t ma ke a ny o f the o ve ra rc hing de c isio ns o f the c o ntro lle r a s de sc rib e d a b o ve .

  9. Pro c e ssing Pe rso na l Da ta I n o rde r to pro c e ss pe rso na l da ta , yo u must ha ve a la wful b a sis fo r do ing so : • Co nse nt o f the Da ta Sub je c t; • E nte ring into a c o ntra c t; • F ulfilling the Co ntro lle r’ s le g a l o b lig a tio n; • F urthe ring a vita l inte re st o f the Da ta Sub je c t o r a no the r individua l; • Pub lic I nte re st; • L e g itima te inte re sts o f the Co ntro lle r. Of the se we will lo o k a t the first in mo re de ta il.

  10. Ba se s fo r Pro c e ssing : Conse nt T he data subje c t has give n his o r he r c o nse nt to the pro c e ssing o f his o r he r pe rso nal data fo r o ne o r mo re spe c ifie d purpo se s . Conse nt is de fine d a s “a ny fre e ly g ive n, spe c ific , informe d a nd una mbig uous indic a tio n o f the da ta sub je c t wishe s b y whic h he o r she , b y a sta te me nt o r b y a c le a r a ffirma tive a c tio n, sig nifie s a g re e me nt to the pro c e ssing o f pe rso na l da ta re la ting to him o r he r. re e ly Give n : Co nse nt is no t fre e ly g ive n, if the da ta sub je c t ha s no g e nuine o r fre e c ho ic e F o r is una b le to re fuse o r withdra w c o nse nt witho ut de trime nt. F o r e xa mple , whe re the re is a c le a r imb a la nc e o f po we r b e twe e n the c o ntro lle r a nd da ta sub je c t, suc h a s in a n e mplo ye r-e mplo ye e re la tio nship. Additio na lly, whe re the pe rfo rma nc e o f a c o ntra c t, inc luding the pro visio n o f a se rvic e , is de pe nde nt o n the c o nse nt de spite suc h c o nse nt no t b e ing ne c e ssa ry fo r suc h pe rfo rma nc e , c o nse nt ma y no t b e fre e ly g ive n. Informe d : F o r c o nse nt to b e info rme d, the da ta sub je c t sho uld kno w the ide ntity o f the c o ntro lle r a nd the pro c e sso r a nd the purpo se (s) o f the pro c e ssing .

  11. Ba se s fo r Pro c e ssing : De monstra ting Conse nt Onc e ha ving suc c e e de d in o b ta ining the ✔ c o nse nt o f the da ta sub je c t to the pro c e ssing in q ue stio n, the c o ntro lle r must b e a b le to YE S de monstra te tha t the da ta sub je c t ha s g ive n his o r he r c o nse nt. A c o ntro lle r must, the re fo re , NO ke e p up-to -da te re c o rds o f a ll da ta sub je c t c o nse nts tha t ha ve b e e n re c e ive d.

  12. Conse nt Withdra wa l • A da ta sub je c t ha s the rig ht to withdra w c onse nt to pro c e ssing a t a ny time . YE S • T he withdra wa l do e s no t a ffe c t the la wfulne ss ✔ o f pro c e ssing tha t to o k pla c e b e fo re the NO withdra wa l. • T he da ta sub je c t must b e to ld a b o ut this rig ht b e fo re g iving c o nse nt. “I t sha ll b e a s e a sy to withdra w a s to g ive c o nse nt”

  13. Da ta Sub je c t Rig hts • Rig ht o f a c c e ss to pe rso na l da ta • Rig ht to re c tific a tio n o f pe rso na l da ta • Rig ht to e ra sure (“rig ht to b e fo rg o tte n”) • Rig ht to re stric tio n o f pro c e ssing • Rig ht to da ta po rta b ility GDPR • Rig ht to o b je c t to pro c e ssing • Rig ht no t to b e sub je c te d to a uto ma tic pro c e ssing inc luding pro filing We sha ll lo o k a t the first a nd third o f the se rig hts in a b it mo re de ta il. But first …

  14. Da ta Sub je c t Rig hts: How long do you ha ve to re spond ? • Re spo nse re q uire d “witho ut undue de la y” • At the la te st within a mo nth • F urthe r e xte nsio n up to two mo nths de pe nding o n GDPR c o mple xity a nd numb e r o f re q ue sts

  15. Rig hts o f the Da ta Sub je c t: Subje c t Ac c e ss Re que st I n the time fra me se t o ut, a nd fo llo wing a writte n re q ue st, yo u must pro vide the individua l with: • Co nfirma tio n o f whe the r his / he r pe rso na l da ta a re b e ing pro c e sse d; GDPR • Ac c e ss to tha t da ta ; • Supple me nta l info rma tio n.

  16. Sub je c t Ac c e ss Re q ue sts: T he Proc e ss • Se a rc h fo r, ide ntify & re trie ve da ta fro m the c lie nt’ s syste ms; • Co lle c t, pro c e ss a nd a na lyse the da ta ; • Sub je c t the da ta to re da c tio n whe re re q uire d; • Pro vide the re spo nse within the time limit de sc rib e d to the individua l.

Recommend


More recommend