SlideShare una empresa de Scribd logo
1 de 41
GDPR for Employers:
What does it mean for your
business?
Tuesday 13th March 2018
Agenda
➢GDPR Overview
➢Key Changes to Data Protection Law
➢Start preparing now
➢How BrightPay is preparing for GDPR
GDPR, what is it?
General Data Protection Regulation
• Aims to provide better protection for personal data
• Current data legislation dates back to 1998
GDPR D-Day
53 Working Days to go
Reasons to Pay Attention!
€20,000,000 /
4% of turnover
€10,000,000 /
2% of turnover
FINES
CIVIL LIABILITY CLAIMS
BRAND DAMAGE
LOSS OF BUSINESS
COST OF INVESTIGATION
Who does it apply to?
• EU establishments that process personal data,
regardless of whether the processing takes place in
the EU
• Non-EU establishments who offer goods or services to
individuals in the EU, irrespective of whether payment
is required.
• Non-EU establishments who monitor individual’s
behaviour that takes place in the EU.
Supervising Authority
Website www.ico.org.uk
E-mail: registration@ico.org.uk
Helpline
Mon – Fri
9am – 5pm
0303 123 1113 (option 4)
Key Terms
Data Subject
An individual
who is the
subject of the
personal data
Data
Controller
Controls the
contents and
use of
personal data
Processing
Operations
performed on
personal data
whether or not
by automated
means
Processor
Processes
personal data
on behalf of
the controller
Personal data breach:
A breach of security
leading to the accidental
or unlawful destruction,
loss, alteration,
unauthorised disclosure
of, or access to,
personal data
transmitted, stored or
otherwise processed.
-KEY CHANGES TO DATA PROTECTION LAW
1. Definition of
Personal Data
2. Special categories of
data
3. Data Protection Principles
4. Lawful Processing of
Data
5. Consent
6. Data Processors
7. Security
8. DPOs
10. Data Protection by
Design & Default
9. Data Subject
Rights
Employee Rights
1. What is Personal Data?
“Any information related on a natural person or ‘Data Subject’, that can be
used to directly or indirectly identify a person.”
✓ A name
✓ A photo
✓ An email address
✓ Bank details
✓ Posts on social networking websites
✓ Medical information
✓ CCTV images
✓ Records of websites visited
✓ A computer IP address
2. Special Categories of Data
➢Racial or ethnic origin
➢Political opinions
➢Religious or philosophical beliefs
➢Trade union membership
➢The processing of genetic data, biometric data for the purpose of uniquely
identifying a person
➢Data concerning health, a person's sex life or sexual orientation
3. Data Protection Principles
Lawfulness Purpose
Limitation
Data
Minimisation
Accuracy Storage
Limitation
Integrity &
Confidentiality
4. Lawful Processing
Processing is only lawful if:
Data subject has given consent (consent has been given)
or
➢ Necessary for the performance of a contract (needed for the contract)
or
➢ Necessary for the compliance with legal obligation
or
➢ In order to protect vital interests of a person
or
 Necessary for public interest or official authority
or
➢ For the legitimate interests of data controller/3rd party
5. Changes to Consent Rules
1. Consent must be:
- Specific, informed,
unambiguous and freely given
- Must be for a specified purpose
2. Where consent is
obtained as part of a larger
document covering other
things, consent must be
clearly distinguished from
everything else
3. Evidence needs to be
retained as to how the consent
was obtained
Forms, brochures signage,
website screenshots etc.
4. Language must be
accessible and easily
understood
6. Data Controller / Data Processors
Increased liability for Data Processors
Processors: guarantee that technical and organisational measures have been
taken in preparation for GDPR
A written contract must exist
Process may only process data in accordance with written instruction
7. Security
1. Preventative: “technical & organisational measures”
Technical: encryption & regular testing
Organisational:
Using unsupported programs
Avoiding unnecessary copies
1. Breaches:
Reported within 72 Hours
ICO The Individuals
The breach likely to result in a risk to the
rights and freedoms of individuals
The breach likely to result in a high risk to
the rights and freedoms of individuals
8. The Data Protection Officer (DPO)
Mandatory for:
✓ Public Bodies
✓ Organisations engaged in “Large Scale” regular/systematic monitoring
✓ Organisations whose core activities consist of processing “special categories” of
data or data relating to criminal convictions
✓ May be mandatory in other contexts as defined by Member State Law
The DPO must:
✓ Have “expert knowledge” of Data Protection Law
✓ Sufficiently Senior
✓ Details must be provided to the DPC
9. Enhanced Rights for Data Subjects
The right to
erasure
The right to
restrict
processing
The right to data
portability
The right to
object
Rights in relation to
automated
decision making
Right to be
informed
The right to
access
The right to
rectification
GDPR from a HR Perspective
Lawful processing
• What is your reason for retaining and processing personal data?
• Consent no longer an option for HR data
• Imbalance of power between employee & employer
1. Legitimate interests of the business
2. Performance of a contract or legal obligation
Increased employee rights
• Clear policies
• Have access to a self service portal?
10. Other New Concepts
• Privacy by design: seeks to ensure that privacy issues are considered
at the outset of a project, rather than being an add on at a later stage
of a project.
• Privacy by default: by default only such personal data as is necessary
for the identified purposes should be processed.
• Data Protection Impact Assessments (PIAs) – to be conducted in high
risk data processing activities.
Definition of
Personal Data
Special categories of data
Data Protection Principles
Lawful Processing of
Data
Consent
Data Processor
Security
DPOs
Data Protection by
Design & Default
Data Subject Rights
Employee Rights
-Start Preparing Now
7 Step Preparation Guide
1. Data
Inventory
2. Employee
Preparation
3. Customers
& 3rd Party
Providers
4. Capturing
Consent
5.
Governance
6. Security
7. PIAs
&
Data by
Design
1. Your Data Inventory
• Create in inventory of all personal data held
• Why are you holding the data? The legal basis?
• How is data obtained?
• Why was it originally gathered.
• How long data is held for?
• How is data saved? Securely?
• Is data shared? With whom? Outside EU?
• Do you process children’s data or special data?
2. Employee Preparation
Policies & Procedures
Implement an Employee Privacy Policy
 Update your Data Protection Policy
 Clean Desk Policy?
 Working from Home Policy?
Consider a self-service option
GDPR
3. Customers & Third Party Providers
Privacy Policy
Notices
• Checklist includes:
• Non-EU transfers
• Retention periods
• No legalese
3rd Party Contracts
• Who are your data
processors?
• Specific information must
be in writing
4. Capturing Consent
• Review terms & conditions that
capture consent
5. Governance
• Reviewing how you will deal with data
subject access request
• Appoint a DPO if necessary
• Update staff on data protection
6. Security
• Technical:
• Encryption
• Firewalls
• Organisational:
• clean desk policy
• Secure Wifi
7. Data by Design / PIA’s
• Develop privacy impact assessment
and privacy by design implementation
and review process
-How BrightPay is Preparing
It’s your data
Keep your
password safe!
What we have done
 New in-program features
 Updated our Privacy Policies
 Internal IT audits
 Increased security – in house
 Introduced extra consent fields
 Staff training
 BrightPay Online Support
 BrightPay Connect
 Bright Contracts updated policies
Sign up to our Newsletter
Sign up to our newsletter to hear about our free webinars, events, industry
updates and special offers across our range of products. You can
unsubscribe from the newsletter at anytime.
Thank You!
G.D.P.R.
General Data Protection Regulation
25th May 2018
BrightPay
www.brightpay.co.uk
support@brightpay.co.uk
PH +44 (0) 845300304
Bright Contracts
www.brightcontracts.co.uk
support@brightcontracts.co.uk
PH +44 (0) 8453004305
-Appendix: GDPR List of Offences
2% Offences
• Breaches of provisions relating to consent of Children
• Asking for personal data, citing GDPR as basis, where you are not
processing identifiable data
• Failure to implement Privacy by Design/by Default
• Failure to document & communicate Joint Controller relationships
• Failure to appoint a representative if based outside EU
• Failure to ensure contract with Data Processor
• Engagement of a sub-processor by processor without authorisation
• Failure to include prescribe content in Processor Contracts
• Processing data by a Data Processor other than on instruction of
Data Controller
• Failure to ensure DPO does not have conflict of interest in execution
of duties
• Failure to execute tasks of the DPO under Article 39
• Failure to apply required controls or safeguards under a DP
certification scheme
• Failure to keep records of processing activities (Article 30)
• Failure to cooperate with the Supervisory Authority
• Failure to ensure appropriate level of security over personal data
• Failure to ensure ability to restore availability and access to data
• Failure to conduct regular testing of effectiveness of technical and
organisational controls for information security
• Failure to notify data breach to Supervisory Authority
• Failure to communicate data breach to Data Subjects (where
required)
• Failure to conduct Data Protection Impact Assessments (when
required)
• Failure to consult with Supervisory Authority where PIA suggests
high risk to rights of individuals
• Failure to engage DPO in a timely manner
• Failure to support DPO in performance of tasks, including provision
of resources, access to data and processing operations, and
opportunity to maintain expert knowledge
• Failure by a certification body to meet the conditions for
accreditation or where actions of the accrediting body infringe the
Regulation
4% Offences
• Breaching any of the core principles of
GDPR
• Failure to implement measures to comply
with the accountability principle
• Failure to comply with standards required
for consent, where consent only basis for
processing
• Unlawful processing of “special
categories” of personal information
• Infringement of rights under Article 12 –
22
• Transfers to 3rd countries in
contravention of provisions of Articles 44
to 49
• Failure to comply with any obligation
under Member State Law under
“Delegated Acts” under Regulation
• Non-compliance with a prohibition under
Article 58(2) on processing or data
transfers, whether temporary or
definitive
• Failure to provide access to Data
Protection Supervisory Authority to
conduct investigations as per Article 58(1)

Más contenido relacionado

La actualidad más candente

Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
joshquarrie
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
CFG
 

La actualidad más candente (20)

GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
An introduction to data protection - Edinburgh
An introduction to data protection - EdinburghAn introduction to data protection - Edinburgh
An introduction to data protection - Edinburgh
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Legal and data protection update
Legal and data protection updateLegal and data protection update
Legal and data protection update
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Privacy 101
Privacy 101Privacy 101
Privacy 101
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for Ops
 
Data protection
Data protectionData protection
Data protection
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 

Similar a What does GDPR mean for your business?

GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!

Similar a What does GDPR mean for your business? (20)

GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?A5: Data protection: Your charity's biggest risk?
A5: Data protection: Your charity's biggest risk?
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 

Más de BrightPay Payroll and Auto Enrolment Software

Más de BrightPay Payroll and Auto Enrolment Software (20)

Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back Bringing payroll in-house: Don't let the fear hold you back
Bringing payroll in-house: Don't let the fear hold you back
 
BrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it worksBrightPay's Integration with Surf Accounts - How it works
BrightPay's Integration with Surf Accounts - How it works
 
Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022Updated EWSS Guidance Webinar - Changes from 1st February 2022
Updated EWSS Guidance Webinar - Changes from 1st February 2022
 
Webinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQWebinar: BrightPay Ireland Integration with AccountsIQ
Webinar: BrightPay Ireland Integration with AccountsIQ
 
Revenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for OctoberRevenue Update: EWSS Changes for October
Revenue Update: EWSS Changes for October
 
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker RevenueEmployment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
Employment Wage Subsidy Scheme EWSS | Guest Speaker Revenue
 
EWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to knowEWSS Changes & The Return to Work: What you need to know
EWSS Changes & The Return to Work: What you need to know
 
The End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term ImpactsThe End of Furlough: Key Changes & The Long Term Impacts
The End of Furlough: Key Changes & The Long Term Impacts
 
BrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for AccountantsBrightPay and Modulr: Webinar for Accountants
BrightPay and Modulr: Webinar for Accountants
 
BrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting SoftwareBrightPay & QuickFile: Connecting Payroll and Accounting Software
BrightPay & QuickFile: Connecting Payroll and Accounting Software
 
Furlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from JulyFurlough Wind-Down: Key changes to the CJRS from July
Furlough Wind-Down: Key changes to the CJRS from July
 
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine PolicyLeaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
Leaving Lockdown: Furlough Wind Down, Redundancies and a Vaccine Policy
 
Take the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflowsTake the pain out of payroll: Integrate your payroll and payment workflows
Take the pain out of payroll: Integrate your payroll and payment workflows
 
Payroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule ChangesPayroll in a Pandemic: Furlough Extension & Rule Changes
Payroll in a Pandemic: Furlough Extension & Rule Changes
 
Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...Payroll in the Connected Era: How integration has transformed the world of pa...
Payroll in the Connected Era: How integration has transformed the world of pa...
 
Optimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve ProfitabilityOptimising your Payroll Offering to Improve Profitability
Optimising your Payroll Offering to Improve Profitability
 
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC QuirksCJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
CJRS Rule Changes, Furlough Extensions & Other HMRC Quirks
 
IR35 - Are you Ready?
IR35 - Are you Ready?IR35 - Are you Ready?
IR35 - Are you Ready?
 
The Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-HouseThe Transition to Bringing Payroll In-House
The Transition to Bringing Payroll In-House
 
Switch to BrightPay
Switch to BrightPaySwitch to BrightPay
Switch to BrightPay
 

Último

Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
chiefasafspells
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
masabamasaba
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
masabamasaba
 
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
masabamasaba
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
masabamasaba
 

Último (20)

Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdfPayment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
 
VTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learnVTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learn
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
 
Architecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastArchitecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the past
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
 
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
 

What does GDPR mean for your business?

  • 1. GDPR for Employers: What does it mean for your business? Tuesday 13th March 2018
  • 2. Agenda ➢GDPR Overview ➢Key Changes to Data Protection Law ➢Start preparing now ➢How BrightPay is preparing for GDPR
  • 3. GDPR, what is it? General Data Protection Regulation • Aims to provide better protection for personal data • Current data legislation dates back to 1998
  • 5. Reasons to Pay Attention! €20,000,000 / 4% of turnover €10,000,000 / 2% of turnover FINES CIVIL LIABILITY CLAIMS BRAND DAMAGE LOSS OF BUSINESS COST OF INVESTIGATION
  • 6. Who does it apply to? • EU establishments that process personal data, regardless of whether the processing takes place in the EU • Non-EU establishments who offer goods or services to individuals in the EU, irrespective of whether payment is required. • Non-EU establishments who monitor individual’s behaviour that takes place in the EU.
  • 7. Supervising Authority Website www.ico.org.uk E-mail: registration@ico.org.uk Helpline Mon – Fri 9am – 5pm 0303 123 1113 (option 4)
  • 8. Key Terms Data Subject An individual who is the subject of the personal data Data Controller Controls the contents and use of personal data Processing Operations performed on personal data whether or not by automated means Processor Processes personal data on behalf of the controller Personal data breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
  • 9. -KEY CHANGES TO DATA PROTECTION LAW
  • 10. 1. Definition of Personal Data 2. Special categories of data 3. Data Protection Principles 4. Lawful Processing of Data 5. Consent 6. Data Processors 7. Security 8. DPOs 10. Data Protection by Design & Default 9. Data Subject Rights Employee Rights
  • 11. 1. What is Personal Data? “Any information related on a natural person or ‘Data Subject’, that can be used to directly or indirectly identify a person.” ✓ A name ✓ A photo ✓ An email address ✓ Bank details ✓ Posts on social networking websites ✓ Medical information ✓ CCTV images ✓ Records of websites visited ✓ A computer IP address
  • 12. 2. Special Categories of Data ➢Racial or ethnic origin ➢Political opinions ➢Religious or philosophical beliefs ➢Trade union membership ➢The processing of genetic data, biometric data for the purpose of uniquely identifying a person ➢Data concerning health, a person's sex life or sexual orientation
  • 13. 3. Data Protection Principles Lawfulness Purpose Limitation Data Minimisation Accuracy Storage Limitation Integrity & Confidentiality
  • 14. 4. Lawful Processing Processing is only lawful if: Data subject has given consent (consent has been given) or ➢ Necessary for the performance of a contract (needed for the contract) or ➢ Necessary for the compliance with legal obligation or ➢ In order to protect vital interests of a person or  Necessary for public interest or official authority or ➢ For the legitimate interests of data controller/3rd party
  • 15. 5. Changes to Consent Rules 1. Consent must be: - Specific, informed, unambiguous and freely given - Must be for a specified purpose 2. Where consent is obtained as part of a larger document covering other things, consent must be clearly distinguished from everything else 3. Evidence needs to be retained as to how the consent was obtained Forms, brochures signage, website screenshots etc. 4. Language must be accessible and easily understood
  • 16. 6. Data Controller / Data Processors Increased liability for Data Processors Processors: guarantee that technical and organisational measures have been taken in preparation for GDPR A written contract must exist Process may only process data in accordance with written instruction
  • 17. 7. Security 1. Preventative: “technical & organisational measures” Technical: encryption & regular testing Organisational: Using unsupported programs Avoiding unnecessary copies 1. Breaches: Reported within 72 Hours ICO The Individuals The breach likely to result in a risk to the rights and freedoms of individuals The breach likely to result in a high risk to the rights and freedoms of individuals
  • 18. 8. The Data Protection Officer (DPO) Mandatory for: ✓ Public Bodies ✓ Organisations engaged in “Large Scale” regular/systematic monitoring ✓ Organisations whose core activities consist of processing “special categories” of data or data relating to criminal convictions ✓ May be mandatory in other contexts as defined by Member State Law The DPO must: ✓ Have “expert knowledge” of Data Protection Law ✓ Sufficiently Senior ✓ Details must be provided to the DPC
  • 19. 9. Enhanced Rights for Data Subjects The right to erasure The right to restrict processing The right to data portability The right to object Rights in relation to automated decision making Right to be informed The right to access The right to rectification
  • 20. GDPR from a HR Perspective Lawful processing • What is your reason for retaining and processing personal data? • Consent no longer an option for HR data • Imbalance of power between employee & employer 1. Legitimate interests of the business 2. Performance of a contract or legal obligation Increased employee rights • Clear policies • Have access to a self service portal?
  • 21. 10. Other New Concepts • Privacy by design: seeks to ensure that privacy issues are considered at the outset of a project, rather than being an add on at a later stage of a project. • Privacy by default: by default only such personal data as is necessary for the identified purposes should be processed. • Data Protection Impact Assessments (PIAs) – to be conducted in high risk data processing activities.
  • 22. Definition of Personal Data Special categories of data Data Protection Principles Lawful Processing of Data Consent Data Processor Security DPOs Data Protection by Design & Default Data Subject Rights Employee Rights
  • 24. 7 Step Preparation Guide 1. Data Inventory 2. Employee Preparation 3. Customers & 3rd Party Providers 4. Capturing Consent 5. Governance 6. Security 7. PIAs & Data by Design
  • 25. 1. Your Data Inventory • Create in inventory of all personal data held • Why are you holding the data? The legal basis? • How is data obtained? • Why was it originally gathered. • How long data is held for? • How is data saved? Securely? • Is data shared? With whom? Outside EU? • Do you process children’s data or special data?
  • 26. 2. Employee Preparation Policies & Procedures Implement an Employee Privacy Policy  Update your Data Protection Policy  Clean Desk Policy?  Working from Home Policy? Consider a self-service option
  • 27. GDPR
  • 28.
  • 29.
  • 30.
  • 31. 3. Customers & Third Party Providers Privacy Policy Notices • Checklist includes: • Non-EU transfers • Retention periods • No legalese 3rd Party Contracts • Who are your data processors? • Specific information must be in writing
  • 32. 4. Capturing Consent • Review terms & conditions that capture consent 5. Governance • Reviewing how you will deal with data subject access request • Appoint a DPO if necessary • Update staff on data protection
  • 33. 6. Security • Technical: • Encryption • Firewalls • Organisational: • clean desk policy • Secure Wifi 7. Data by Design / PIA’s • Develop privacy impact assessment and privacy by design implementation and review process
  • 34. -How BrightPay is Preparing
  • 35. It’s your data Keep your password safe!
  • 36. What we have done  New in-program features  Updated our Privacy Policies  Internal IT audits  Increased security – in house  Introduced extra consent fields  Staff training  BrightPay Online Support  BrightPay Connect  Bright Contracts updated policies
  • 37. Sign up to our Newsletter Sign up to our newsletter to hear about our free webinars, events, industry updates and special offers across our range of products. You can unsubscribe from the newsletter at anytime.
  • 38. Thank You! G.D.P.R. General Data Protection Regulation 25th May 2018 BrightPay www.brightpay.co.uk support@brightpay.co.uk PH +44 (0) 845300304 Bright Contracts www.brightcontracts.co.uk support@brightcontracts.co.uk PH +44 (0) 8453004305
  • 39. -Appendix: GDPR List of Offences
  • 40. 2% Offences • Breaches of provisions relating to consent of Children • Asking for personal data, citing GDPR as basis, where you are not processing identifiable data • Failure to implement Privacy by Design/by Default • Failure to document & communicate Joint Controller relationships • Failure to appoint a representative if based outside EU • Failure to ensure contract with Data Processor • Engagement of a sub-processor by processor without authorisation • Failure to include prescribe content in Processor Contracts • Processing data by a Data Processor other than on instruction of Data Controller • Failure to ensure DPO does not have conflict of interest in execution of duties • Failure to execute tasks of the DPO under Article 39 • Failure to apply required controls or safeguards under a DP certification scheme • Failure to keep records of processing activities (Article 30) • Failure to cooperate with the Supervisory Authority • Failure to ensure appropriate level of security over personal data • Failure to ensure ability to restore availability and access to data • Failure to conduct regular testing of effectiveness of technical and organisational controls for information security • Failure to notify data breach to Supervisory Authority • Failure to communicate data breach to Data Subjects (where required) • Failure to conduct Data Protection Impact Assessments (when required) • Failure to consult with Supervisory Authority where PIA suggests high risk to rights of individuals • Failure to engage DPO in a timely manner • Failure to support DPO in performance of tasks, including provision of resources, access to data and processing operations, and opportunity to maintain expert knowledge • Failure by a certification body to meet the conditions for accreditation or where actions of the accrediting body infringe the Regulation
  • 41. 4% Offences • Breaching any of the core principles of GDPR • Failure to implement measures to comply with the accountability principle • Failure to comply with standards required for consent, where consent only basis for processing • Unlawful processing of “special categories” of personal information • Infringement of rights under Article 12 – 22 • Transfers to 3rd countries in contravention of provisions of Articles 44 to 49 • Failure to comply with any obligation under Member State Law under “Delegated Acts” under Regulation • Non-compliance with a prohibition under Article 58(2) on processing or data transfers, whether temporary or definitive • Failure to provide access to Data Protection Supervisory Authority to conduct investigations as per Article 58(1)