gdpr an introduction - community works · 2017. 11. 15. · gdpr an introduction are you ready?...

28
GDPR an Introduction Are You ready?

Upload: others

Post on 03-Sep-2020

8 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

GDPR an Introduction

Are You ready?

Page 2: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance
Page 3: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

GDPR monetary penalties

Page 4: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

GDPR an Introduction

Are You ready?

Paul Hamill - Assurance Team Manager Sarah Carr - Assurance Lead Auditor

Page 5: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Transparency Control Accountability

Page 6: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q1 – Under GDPR , what type of information is now included in the definition of personal data?

a)IP address

b)Banking history

c)Spent convictions

Page 7: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q2 – Which of the following is a “special category” of personal data in the GDPR?

a)credit scores

b)genetic and biometric data

c)educational records

Page 8: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q3 – At what age can a child give their own consent to the processing of their personal data under GDPR?

a)13

b)16

c)18

Page 9: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

It is not back to the starting line

GDPR

Page 10: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Individual’s Rights

Page 11: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q4 –Do you provide privacy notices to your customers?

a)Yes

b)No

Page 12: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Communicating Privacy Information

Page 13: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q5 – How many of your organisations use an “opt in” for consent?

a) Yesb) No

Page 14: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Clear and Affirmative Action

Right to withdraw

Easy to Distinguish

“Freely given, specific, informed and an unambiguous indication of the individual’s wishes”

Page 15: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q6 – Under GDPR what is the timescale for responding to a Subject Access Request

a)1 month

b)40 days

c)3 months

Page 16: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Subject Access requests!

Page 17: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Accountability and Governance

“The controller shall be responsible for, and be able to demonstrate, compliance with the principles.”

GDPR Article 5 (2)

Page 18: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q7 – How many of you think you will need to appoint a Data Protection Officer?

a)Yes

b)No

Page 19: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

When must you appoint a DPO?

Public Authority

Systematic monitoring

Large scale processing

Page 20: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q8 – Have you ever had to report a Breach to the ICO?

a)Yes

b)No

Page 21: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q9– How quickly did you do so after becoming aware of the breach ?

a)Within 72 Hours

b)Within a week

c)Within a month

d)Longer

Page 22: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Breach Notification

72 Hours

Page 23: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Q10– What is the maximum possible fine that can be imposed under GDPR?

a)500K euros

b)1m euros

c)5m euros and 2% of Global turnover

d)20m euros or 4% of global turnover

Page 24: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

GDPR monetary penalties

Page 25: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

ico.org.uk/dpreformTwitter: @iconews

Page 26: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance
Page 27: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance
Page 28: GDPR an Introduction - Community Works · 2017. 11. 15. · GDPR an Introduction Are You ready? GDPR monetary penalties. GDPR an Introduction Are You ready? Paul Hamill - Assurance

Transparency Control Accountability