PowerPoint Presentation

1 of
Published on Video
Go to video
Download PDF version
Download PDF version
Embed video
Share video
Ask about this video

Page 1 (0s)

. . General Data Protection Regulation. Awareness.

Page 2 (9s)

. . • About GDPR – The Data Protection Act What is data privacy? Who does this affect? Why data privacy matters to us.

Page 3 (44s)

. . . About GDPR – The Data Protection Act. • GDPR is a regulation that went into effect in 25th, May 2018. The goal of GDPR is to protect the personal data of European citizens..

Page 4 (1m 23s)

. . . About GDPR – What is data privacy?. • Being open with people about how we use their information.

Page 5 (1m 41s)

. . . About GDPR – Who does this affect?. • All of us - we all have a responsibility to keep people’s information safe..

Page 6 (1m 58s)

. . . About GDPR – Why data privacy matters to us.

Page 7 (2m 18s)

. . . Definitions (As per Article 4). Establishment –.

Page 8 (2m 59s)

. . . Definitions (As per Article 4). Special categories of personal data –.

Page 9 (3m 36s)

. . . Definitions (As per Article 4). • Processing –.

Page 10 (4m 0s)

. . . Definitions (As per Article 4). Profiling –.

Page 11 (4m 39s)

. . . Definitions (As per Article 4). Data subject consent.

Page 12 (5m 16s)

. . • Under the GDPR there are certain types of information which are.

Page 13 (5m 43s)

. . • When working with different types of information we need to consider what can be interpreted or inferred when we combine them..

Page 14 (6m 14s)

. . Personal information Sensitive personal information.

Page 15 (6m 35s)

. . • All information is important, and while there are differences, it is best practice to ensure you take measures to maintain the confidentiality of anything that is shared with you..

Page 16 (7m 8s)

. . • Before you work with any data it is important that you take a moment to ask yourself: can I manage this information securely?.

Page 17 (7m 37s)

. . . Processing Personal Data. Personal data must be processed:.

Page 18 (8m 1s)

. . . Processing Sensitive Personal Data. • Restrictions on use of ‘sensitive personal data’.

Page 19 (8m 27s)

. . PERSONAL DATA SPECIAL CATEGORIES OF PD. Consent Explicit consent.

Page 20 (8m 55s)

. . • Restrictions on exports outside the EEA to countries without ‘adequate safeguards’.

Page 21 (9m 15s)

. . • Breach by the data processor is the responsibility of the data controller.

Page 22 (9m 34s)

. . NIPL’s Privacy Notice outlines how we use personal data, keeps people informed about the data we hold, and provides assurances that we work with data in a legal and ethical way..

Page 23 (10m 4s)

. . • Under data protection regulations, it is vital that anyone sharing their data understands for what purpose they are giving their information and how it will be handled..

Page 24 (10m 40s)

. . . Lawful bases for processing. Consent congnt of a data suW to tho of hismer data Legitimate interests Thn a weghed & '"derest is nterestis not ovemddenby others Public interest Puü auth«tjes ard in of put*c duties and interest Legitimate interests Public interest Consent LaMulness of processing Vital interests Contractual necessity Legal ligation Contractual necessity s in order to enter hto a contract Legal obligations The mntrot to prsonal data a •al oblqatm Vital interests It s vdal that sg±fic data for of Me ard death.

Page 25 (10m 56s)

. . . Seven Principles of GDPR. LAWFULNESS. FAIRNESS AND TRANSPARENCY Personal data shall processed •awfully, fairly and in a transparent manner in relation to the data su bject. PURPOSE Personal data shall be collected for specified, explicit ard legitimate purposes and not further processed in a that is incompatible with those purposes. DATA MINIMISATION Personal data shall he adequate, relevant and limited to what is necessary in relation to the far which they are processed. ACCURACY Personal data shall be accurate and. where necessary, kept up todate, STORAGE LIMITATION Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, INTEGRITY AND CONFIDENTIALITY Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental toss, destruction or damage, using appropriate technical or organisational measures. ACCOUNTABILITY The controller shall be responsible for. and he able to demonstrate compliance with the Dara Protestion Principles,.

Page 26 (11m 35s)

. . Be informed Access Rectification. Erasure Restrict processing Data portability.

Page 27 (11m 44s)

. . Individuals have the right to receive privacy information such as:.

Page 28 (12m 6s)

. . Individuals have the right to:. • Have confirmation that their data is being processed.

Page 29 (12m 25s)

. . • You may charge a reasonable fee or refuse to respond when a request is manifestly unfounded or excessive, particularly if it is repetitive.

Page 30 (13m 0s)

. . Individuals have the right to:. • Their personal data being accurate.

Page 31 (13m 19s)

. . Individuals have the right to erasure if:. • Personal data is no longer necessary in relation to the purpose for which it was originally collected/processed.

Page 32 (13m 47s)

. . Individuals can request:. • Restriction of processing until an accuracy claim is verified.

Page 33 (14m 6s)

. . Individuals have the right to:. • Receive their personal data in a structured, commonly used and machine readable format..

Page 34 (14m 34s)

. . Individuals have the right to object to:. • Processing for direct marketing.

Page 35 (14m 56s)

. . Under Article 22, individuals have the right not to be subject to a decision when:.

Page 36 (15m 24s)

. . The GDPR’s accountability principle (Article 5(2)) requires you to be able to demonstrate how you comply with the data protection principles.

Page 37 (15m 42s)

. . The first principle of the GDPR requires you to process data in a transparent manner in relation to the data subject (Article 5(1)(a)).

Page 38 (16m 17s)

. . Personal data must be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality).”.

Page 39 (16m 44s)

. . Data Protection Impact Assessments. Data protection impact assessments (DPIAs) are required by Article 35 of GDPR. It is up to the organization to determine when a DPIA as GDPR allows consideration based on the scope of processing and risk to data subjects..

Page 40 (17m 9s)

. . Required when:. • using new technologies,. • profiling,.

Page 41 (17m 34s)

. . • Contract laying out multiple party commitments to personal data.

Page 42 (17m 51s)

. . • Implement implement appropriate technical and organizatonal controls based on DPIA and data protection design requirements to ensure safety of personal data held..

Page 43 (18m 9s)

. . Technical measures include :. • Data encryption at rest.

Page 44 (18m 26s)

. . • Pesudonymization. Is the process of removing personal identifiers from data and replacing those identifiers with placeholder values..

Page 45 (18m 47s)

. . Organizational measures include : • Robust data security policy,.

Page 46 (19m 9s)

. . A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed..

Page 47 (19m 36s)

. . In brief, when reporting a breach:. Be quick Be open.

Page 48 (19m 54s)

. . The Information Commissioner’s Office (ICO) is the UK’s independent body set up to uphold information rights. Its duties are to:.

Page 49 (20m 22s)

. . GDPR clearly articulates the goal of penalties to be effective, proportionate and dissuasive. in Article 83. Fines under GDPR fall into two categories depending on the severity of the case..

Page 50 (21m 3s)

. . There are two categories of fines. You can be fined the higher of 2% of your annual global turnover, or 10 million Euros, for shortcomings including:.