PowerPoint Presentation

Published on Slideshow
Static slideshow
Download PDF version
Download PDF version
Embed video
Share video
Ask about this video

Scene 1 (0s)

. . General Data Protection Regulation. Awareness.

Scene 2 (9s)

. . • About GDPR – The Data Protection Act What is data privacy? Who does this affect? Why data privacy matters to us.

Scene 3 (44s)

. . . About GDPR – The Data Protection Act. • GDPR is a regulation that went into effect in 25th, May 2018. The goal of GDPR is to protect the personal data of European citizens..

Scene 4 (1m 23s)

. . . About GDPR – What is data privacy?. • Being open with people about how we use their information.

Scene 5 (1m 41s)

. . . About GDPR – Who does this affect?. • All of us - we all have a responsibility to keep people’s information safe..

Scene 6 (1m 58s)

. . . About GDPR – Why data privacy matters to us.

Scene 7 (2m 18s)

. . . Definitions (As per Article 4). Establishment –.

Scene 8 (2m 59s)

. . . Definitions (As per Article 4). Special categories of personal data –.

Scene 9 (3m 36s)

. . . Definitions (As per Article 4). • Processing –.

Scene 10 (4m 0s)

. . . Definitions (As per Article 4). Profiling –.

Scene 11 (4m 39s)

. . . Definitions (As per Article 4). Data subject consent.

Scene 12 (5m 16s)

. . • Under the GDPR there are certain types of information which are.

Scene 13 (5m 43s)

. . • When working with different types of information we need to consider what can be interpreted or inferred when we combine them..

Scene 14 (6m 14s)

. . Personal information Sensitive personal information.

Scene 15 (6m 35s)

. . • All information is important, and while there are differences, it is best practice to ensure you take measures to maintain the confidentiality of anything that is shared with you..

Scene 16 (7m 8s)

. . • Before you work with any data it is important that you take a moment to ask yourself: can I manage this information securely?.

Scene 17 (7m 37s)

. . . Processing Personal Data. Personal data must be processed:.

Scene 18 (8m 1s)

. . . Processing Sensitive Personal Data. • Restrictions on use of ‘sensitive personal data’.

Scene 19 (8m 27s)

. . PERSONAL DATA SPECIAL CATEGORIES OF PD. Consent Explicit consent.

Scene 20 (8m 55s)

. . • Restrictions on exports outside the EEA to countries without ‘adequate safeguards’.

Scene 21 (9m 15s)

. . • Breach by the data processor is the responsibility of the data controller.

Scene 22 (9m 34s)

. . NIPL’s Privacy Notice outlines how we use personal data, keeps people informed about the data we hold, and provides assurances that we work with data in a legal and ethical way..

Scene 23 (10m 4s)

. . • Under data protection regulations, it is vital that anyone sharing their data understands for what purpose they are giving their information and how it will be handled..

Scene 24 (10m 40s)

. . . Lawful bases for processing. Consent congnt of a data suW to tho of hismer data Legitimate interests Thn a weghed & '"derest is nterestis not ovemddenby others Public interest Puü auth«tjes ard in of put*c duties and interest Legitimate interests Public interest Consent LaMulness of processing Vital interests Contractual necessity Legal ligation Contractual necessity s in order to enter hto a contract Legal obligations The mntrot to prsonal data a •al oblqatm Vital interests It s vdal that sg±fic data for of Me ard death.

Scene 25 (10m 56s)

. . . Seven Principles of GDPR. LAWFULNESS. FAIRNESS AND TRANSPARENCY Personal data shall processed •awfully, fairly and in a transparent manner in relation to the data su bject. PURPOSE Personal data shall be collected for specified, explicit ard legitimate purposes and not further processed in a that is incompatible with those purposes. DATA MINIMISATION Personal data shall he adequate, relevant and limited to what is necessary in relation to the far which they are processed. ACCURACY Personal data shall be accurate and. where necessary, kept up todate, STORAGE LIMITATION Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, INTEGRITY AND CONFIDENTIALITY Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental toss, destruction or damage, using appropriate technical or organisational measures. ACCOUNTABILITY The controller shall be responsible for. and he able to demonstrate compliance with the Dara Protestion Principles,.

Scene 26 (11m 35s)

. . Be informed Access Rectification. Erasure Restrict processing Data portability.

Scene 27 (11m 44s)

. . Individuals have the right to receive privacy information such as:.

Scene 28 (12m 6s)

. . Individuals have the right to:. • Have confirmation that their data is being processed.

Scene 29 (12m 25s)

. . • You may charge a reasonable fee or refuse to respond when a request is manifestly unfounded or excessive, particularly if it is repetitive.

Scene 30 (13m 0s)

. . Individuals have the right to:. • Their personal data being accurate.

Scene 31 (13m 19s)

. . Individuals have the right to erasure if:. • Personal data is no longer necessary in relation to the purpose for which it was originally collected/processed.

Scene 32 (13m 47s)

. . Individuals can request:. • Restriction of processing until an accuracy claim is verified.

Scene 33 (14m 6s)

. . Individuals have the right to:. • Receive their personal data in a structured, commonly used and machine readable format..

Scene 34 (14m 34s)

. . Individuals have the right to object to:. • Processing for direct marketing.

Scene 35 (14m 56s)

. . Under Article 22, individuals have the right not to be subject to a decision when:.

Scene 36 (15m 24s)

. . The GDPR’s accountability principle (Article 5(2)) requires you to be able to demonstrate how you comply with the data protection principles.

Scene 37 (15m 42s)

. . The first principle of the GDPR requires you to process data in a transparent manner in relation to the data subject (Article 5(1)(a)).

Scene 38 (16m 17s)

. . Personal data must be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality).”.

Scene 39 (16m 44s)

. . Data Protection Impact Assessments. Data protection impact assessments (DPIAs) are required by Article 35 of GDPR. It is up to the organization to determine when a DPIA as GDPR allows consideration based on the scope of processing and risk to data subjects..

Scene 40 (17m 9s)

. . Required when:. • using new technologies,. • profiling,.

Scene 41 (17m 34s)

. . • Contract laying out multiple party commitments to personal data.

Scene 42 (17m 51s)

. . • Implement implement appropriate technical and organizatonal controls based on DPIA and data protection design requirements to ensure safety of personal data held..

Scene 43 (18m 9s)

. . Technical measures include :. • Data encryption at rest.

Scene 44 (18m 26s)

. . • Pesudonymization. Is the process of removing personal identifiers from data and replacing those identifiers with placeholder values..

Scene 45 (18m 47s)

. . Organizational measures include : • Robust data security policy,.

Scene 46 (19m 9s)

. . A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed..

Scene 47 (19m 36s)

. . In brief, when reporting a breach:. Be quick Be open.

Scene 48 (19m 54s)

. . The Information Commissioner’s Office (ICO) is the UK’s independent body set up to uphold information rights. Its duties are to:.

Scene 49 (20m 22s)

. . GDPR clearly articulates the goal of penalties to be effective, proportionate and dissuasive. in Article 83. Fines under GDPR fall into two categories depending on the severity of the case..

Scene 50 (21m 3s)

. . There are two categories of fines. You can be fined the higher of 2% of your annual global turnover, or 10 million Euros, for shortcomings including:.