SlideShare una empresa de Scribd logo
1 de 29
Presented by: Karel Holst
Legal Counsel IFORI
karel.holst@ifori.be
Blog: www.gdprexpert.be
THE GENERAL DATA PROTECTION REGULATION - GDPR
Legal Perspective
DE ALGEMENE VERORDENING GEGEVENSBESCHERMING - AVG
Overview
Data Protection
4
Fundamental Rights
EU Charter of Fundamental Rights, article 8(1): “Everyone has the right to the
protection of personal data concerning him or her.”
[≠ ECHR/UDHR] [≠ right to privacy]
Through the expansion of the ‘information society’ the public and private
sector increasingly process larger quantities of Personal Data (e.g.
HR/Customer-data)
EU and national legislative initiatives
5
1995: Directive
‒ Requires national
implementation
‒ EU Data Protection Directive
(95/46/EC)
E.g. Belgium: The Privacy Act
EU Legislative Acts
2016: Regulation
‒ Direct effect in the EU
‒ From the day it enters into force
GDPR: 24 May 2016, but applies from 25
May 2018 (2 year transitional period)
6
Why a new overriding Regulation?
Directive 95/46/EC sought to harmonize national legislations and ensure
free flow of data within the EU
But:
– Still differences in national implementation and application
– Limited cooperation between Data Protection Authorities (‘DPA’)
– Many technological & societal changes in the 20 years since Dir. 95/45/EC
– Strengthen Data Subject's rights
7
Personal Data are everywhere!
“Any information relating to an identified or identifiable natural person”
E.g. Name, location data, IP-address, customer number, …
Stricter rules for special categories of Personal Data (general
prohibition)
‒ Racial or ethnic origin
‒ Political options
‒ Genetic and biometric data, solely for identification purposes
‒ Health data
‒ …
Personal Data
8
Processing
Personal Data
e.g. Customer Data
‒ Name
‒ Date of birth
‒ Address
‒ …
Controller
Determines the purposes
and the manner of the
processing
e.g. iFORi
For marketing purposes,
through an online registration
form
Data Subject Processor
Separate legal
entity
processes on behalf
of the Controller
e.g. Marketer
carries out mail
marketing
9
Main objective
Ensure the right of an individual to make his own decisions regarding the
information that relates to him.
Principles of processing:
‒ Fair, lawful and transparent
‒ Purpose limitation
‒ Data minimization
‒ Accuracy
‒ Storage limitation
‒ Integrity and confidentiality
Key Obligations/Changes
GDPR
11
I. Territorial Scope
The GDPR applies when:
‒ Processing in the context of activities of an establishment in the EU
‒ When the data subjects are located in the EU, and the processing is
related to:
• Offering goods or services
• Monitoring of their behavior (in the EU)
12
II. Lawfulness
A valid legal basis to process the data is required:
‒ Consent
• Freely given, specific, informed and unambiguous
• It must be given by a statement or a clear affirmative action (thus opt-
out NOT possible)
• Proof of consent to be provided by Controller
• Withdrawable
• Obtained separately
• Children: when offering information society services, processing is only
lawful where the child is at least 16 years old. Younger = consent by
holder of parental responsibility
13
III. Rights of the data subject
‒ Transparency
‒ Access
‒ Rectify
‒ Erasure (right to be forgotten)
‒ Restriction
‒ Portability
‒ Object
‒ Not be subject to automated decision making/profiling
14
IV. Controllers and Processors
Controllers
‒ Privacy by default & design
‒ Records (Notification)
• Not where <250 employees, unless high risk
• Including general description of security measures
‒ Data breach notification
‒ Privacy Impact Assessment(PIA)/Prior consultation of DPA
‒ Data Protection Officer (DPO)
‒ Data security
Data Breach Notification
To Data Protection Authority (DPA)
– 72h deadline
– Specific information
– Documentation
To data subject
– High risk to rights and freedoms
– Clear and plain language
– Exceptions
Data Protection Officer (DPO)
When?
‒ Public authority or body
‒ Regular and systematic monitoring of data subjects
‒ Processing of special categories of data
Tasks?
‒ Inform and advise on the obligations pursuant the GDPR
‒ Monitor compliance
‒ Advise on draft of PIA
‒ Cooperate with DPA
‒ External contact
Who?
Data Security
Ensure confidentiality, integrity, availability, resilience
By implementing appropriate technical and organizational measures
Risk based approach (the state of the art, the costs of implementation, …)
– Encryption/Pseudonymisation
– Audits
– Back-up and redundancy
Pseudonymisation
“The processing of personal data in such a way that the data can no longer be
attributed to a specific data subject without the use of additional information”
– Process beyond original collection purposes;
– Safeguard for processing personal data for scientific, historical and statistical purposes;
– Feature of data protection by design;
– Helps meet Data Security requirements;
– Limits the rights of Data Subjects
19
Processors
‒ Comply with specific obligations
• Records
• Data Security
• PIA/DPO
• Breach notification to Controller
‒ Directly liable
20
V. Transfers
General prohibition on transfers outside EEA (28+3)
– Adequacy Decision
• White list
• Privacy Shield (US)
– Appropriate Safeguards
• Model Clauses (EC/DPA/Ad hoc)
• Binding Corporate rules
• Codes of conduct/ Certification
– Derogations (e.g. explicit consent)
21
VI. Sanctions
Administrative Fines by DPA: effective, proportionate & dissuasive
– Up to, the greater of €20.000.000 or 4% of total worldwide annual turnover of
an undertaking
Private claims by data subjects
– DPA
– Courts for compensation from Controller or Processor
Criminal penalties possible where provided by member states
22
VII. “One-stop-shop”
Controllers and Processors answer to a ‘lead supervisory authority’
– Based on their single or main establishment in the EU
– For cross-border processing
But supervisory authorities may still address infringements
– If it relates to an establishment in its MS or;
– If it substantially affects data subjects in its MS
Consistency through cooperation between DPA’s with EDPB oversight
Cookies, Network Infrastructure, Employees
Related Legal Acts
24
Directive on privacy and electronic communications - Telecoms Law
– Information
– Consent
GDPR
– Processing of personal data
‒ Controller: You/Third party cookie provider
‒ Processor: Third party cookie provider
Cookies
25
 Strengthening Cybersecurity within the EU
 For sectors which are vital for economy and society:
– Operators Of Essential Services
– Energy
– Transport
– Banking
– Financial market infrastructures
– Health sector
– Drinking water supply and distribtuion
– Digital infrastructure
– Digital Service Providers
– Online Marketplaces
– Online search engines
– Cloud computing services
NIS: Network and Information Security Directive
26
Monitoring E-mail: Belgium: CAO nr. 81 & Privacy Act
Principles: Finality, Proportionality, Transparency
– Professional communications(?): Access (?)
– Non-professional communications: Individualization Procedure
See also recommendations by Privacy Commission
GDPR allows for more specific national rules in the context of employment
Employees
Call to action
Conclusion
28
Take Action
Not everything has changed, just as not everything has been harmonized
New obligations but also removal of some administrative burdens and
further guidance
(New) technologies introduce new compliance risks, but technologies can
also be used to mitigate risk and/or ensure compliance
Take action now!
GDPR applies from 25 May 2018
IFORI GENT
Victor Braeckmanlaan 107
9040 Gent, Belgium
Tel: +32 9 230 36 62
Fax: +32 9 231 63 71
E-mail: info@ifori.be
IFORI ANTWERPEN
Satellietkantoor
Kapelsesteenweg 195/1
2180 Antwerpen, Belgium
FACTURATIEGEGEVENS
IFORI BVBA
RPR: 472.073.759 (Gent)
BTW: BE 472.073.759
IBAN: BE17 2900 5044 0021
BIC: GEBABEBB
Thank you
Questions?
WWW.IFORI.BE
WWW.GDPREXPERT.BE

Más contenido relacionado

La actualidad más candente

EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
VYTIS MALECKAS
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
Pavol Balaj
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 

La actualidad más candente (18)

Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Privacy and data protection in credit scoring
Privacy and data protection in credit scoring Privacy and data protection in credit scoring
Privacy and data protection in credit scoring
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 

Similar a GDPR presentation BE-Com - IFORI

Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
Rachel Aldighieri
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
Rachel Aldighieri
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Dr. Donald Macfarlane
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Constantine Karbaliotis
 

Similar a GDPR presentation BE-Com - IFORI (20)

2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrity
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 
CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 

Último

一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
Airst S
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
F La
 
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
e9733fc35af6
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
Airst S
 
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
Fir La
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
ss
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
yogita9398
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
F La
 

Último (20)

一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?
 
Chambers Global Practice Guide - Canada M&A
Chambers Global Practice Guide - Canada M&AChambers Global Practice Guide - Canada M&A
Chambers Global Practice Guide - Canada M&A
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
Common Legal Risks in Hiring and Firing Practices.pdf
Common Legal Risks in Hiring and Firing Practices.pdfCommon Legal Risks in Hiring and Firing Practices.pdf
Common Legal Risks in Hiring and Firing Practices.pdf
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
 
Reason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaReason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in India
 
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptx
 

GDPR presentation BE-Com - IFORI

  • 1.
  • 2. Presented by: Karel Holst Legal Counsel IFORI karel.holst@ifori.be Blog: www.gdprexpert.be THE GENERAL DATA PROTECTION REGULATION - GDPR Legal Perspective DE ALGEMENE VERORDENING GEGEVENSBESCHERMING - AVG
  • 4. 4 Fundamental Rights EU Charter of Fundamental Rights, article 8(1): “Everyone has the right to the protection of personal data concerning him or her.” [≠ ECHR/UDHR] [≠ right to privacy] Through the expansion of the ‘information society’ the public and private sector increasingly process larger quantities of Personal Data (e.g. HR/Customer-data) EU and national legislative initiatives
  • 5. 5 1995: Directive ‒ Requires national implementation ‒ EU Data Protection Directive (95/46/EC) E.g. Belgium: The Privacy Act EU Legislative Acts 2016: Regulation ‒ Direct effect in the EU ‒ From the day it enters into force GDPR: 24 May 2016, but applies from 25 May 2018 (2 year transitional period)
  • 6. 6 Why a new overriding Regulation? Directive 95/46/EC sought to harmonize national legislations and ensure free flow of data within the EU But: – Still differences in national implementation and application – Limited cooperation between Data Protection Authorities (‘DPA’) – Many technological & societal changes in the 20 years since Dir. 95/45/EC – Strengthen Data Subject's rights
  • 7. 7 Personal Data are everywhere! “Any information relating to an identified or identifiable natural person” E.g. Name, location data, IP-address, customer number, … Stricter rules for special categories of Personal Data (general prohibition) ‒ Racial or ethnic origin ‒ Political options ‒ Genetic and biometric data, solely for identification purposes ‒ Health data ‒ … Personal Data
  • 8. 8 Processing Personal Data e.g. Customer Data ‒ Name ‒ Date of birth ‒ Address ‒ … Controller Determines the purposes and the manner of the processing e.g. iFORi For marketing purposes, through an online registration form Data Subject Processor Separate legal entity processes on behalf of the Controller e.g. Marketer carries out mail marketing
  • 9. 9 Main objective Ensure the right of an individual to make his own decisions regarding the information that relates to him. Principles of processing: ‒ Fair, lawful and transparent ‒ Purpose limitation ‒ Data minimization ‒ Accuracy ‒ Storage limitation ‒ Integrity and confidentiality
  • 11. 11 I. Territorial Scope The GDPR applies when: ‒ Processing in the context of activities of an establishment in the EU ‒ When the data subjects are located in the EU, and the processing is related to: • Offering goods or services • Monitoring of their behavior (in the EU)
  • 12. 12 II. Lawfulness A valid legal basis to process the data is required: ‒ Consent • Freely given, specific, informed and unambiguous • It must be given by a statement or a clear affirmative action (thus opt- out NOT possible) • Proof of consent to be provided by Controller • Withdrawable • Obtained separately • Children: when offering information society services, processing is only lawful where the child is at least 16 years old. Younger = consent by holder of parental responsibility
  • 13. 13 III. Rights of the data subject ‒ Transparency ‒ Access ‒ Rectify ‒ Erasure (right to be forgotten) ‒ Restriction ‒ Portability ‒ Object ‒ Not be subject to automated decision making/profiling
  • 14. 14 IV. Controllers and Processors Controllers ‒ Privacy by default & design ‒ Records (Notification) • Not where <250 employees, unless high risk • Including general description of security measures ‒ Data breach notification ‒ Privacy Impact Assessment(PIA)/Prior consultation of DPA ‒ Data Protection Officer (DPO) ‒ Data security
  • 15. Data Breach Notification To Data Protection Authority (DPA) – 72h deadline – Specific information – Documentation To data subject – High risk to rights and freedoms – Clear and plain language – Exceptions
  • 16. Data Protection Officer (DPO) When? ‒ Public authority or body ‒ Regular and systematic monitoring of data subjects ‒ Processing of special categories of data Tasks? ‒ Inform and advise on the obligations pursuant the GDPR ‒ Monitor compliance ‒ Advise on draft of PIA ‒ Cooperate with DPA ‒ External contact Who?
  • 17. Data Security Ensure confidentiality, integrity, availability, resilience By implementing appropriate technical and organizational measures Risk based approach (the state of the art, the costs of implementation, …) – Encryption/Pseudonymisation – Audits – Back-up and redundancy
  • 18. Pseudonymisation “The processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information” – Process beyond original collection purposes; – Safeguard for processing personal data for scientific, historical and statistical purposes; – Feature of data protection by design; – Helps meet Data Security requirements; – Limits the rights of Data Subjects
  • 19. 19 Processors ‒ Comply with specific obligations • Records • Data Security • PIA/DPO • Breach notification to Controller ‒ Directly liable
  • 20. 20 V. Transfers General prohibition on transfers outside EEA (28+3) – Adequacy Decision • White list • Privacy Shield (US) – Appropriate Safeguards • Model Clauses (EC/DPA/Ad hoc) • Binding Corporate rules • Codes of conduct/ Certification – Derogations (e.g. explicit consent)
  • 21. 21 VI. Sanctions Administrative Fines by DPA: effective, proportionate & dissuasive – Up to, the greater of €20.000.000 or 4% of total worldwide annual turnover of an undertaking Private claims by data subjects – DPA – Courts for compensation from Controller or Processor Criminal penalties possible where provided by member states
  • 22. 22 VII. “One-stop-shop” Controllers and Processors answer to a ‘lead supervisory authority’ – Based on their single or main establishment in the EU – For cross-border processing But supervisory authorities may still address infringements – If it relates to an establishment in its MS or; – If it substantially affects data subjects in its MS Consistency through cooperation between DPA’s with EDPB oversight
  • 23. Cookies, Network Infrastructure, Employees Related Legal Acts
  • 24. 24 Directive on privacy and electronic communications - Telecoms Law – Information – Consent GDPR – Processing of personal data ‒ Controller: You/Third party cookie provider ‒ Processor: Third party cookie provider Cookies
  • 25. 25  Strengthening Cybersecurity within the EU  For sectors which are vital for economy and society: – Operators Of Essential Services – Energy – Transport – Banking – Financial market infrastructures – Health sector – Drinking water supply and distribtuion – Digital infrastructure – Digital Service Providers – Online Marketplaces – Online search engines – Cloud computing services NIS: Network and Information Security Directive
  • 26. 26 Monitoring E-mail: Belgium: CAO nr. 81 & Privacy Act Principles: Finality, Proportionality, Transparency – Professional communications(?): Access (?) – Non-professional communications: Individualization Procedure See also recommendations by Privacy Commission GDPR allows for more specific national rules in the context of employment Employees
  • 28. 28 Take Action Not everything has changed, just as not everything has been harmonized New obligations but also removal of some administrative burdens and further guidance (New) technologies introduce new compliance risks, but technologies can also be used to mitigate risk and/or ensure compliance Take action now! GDPR applies from 25 May 2018
  • 29. IFORI GENT Victor Braeckmanlaan 107 9040 Gent, Belgium Tel: +32 9 230 36 62 Fax: +32 9 231 63 71 E-mail: info@ifori.be IFORI ANTWERPEN Satellietkantoor Kapelsesteenweg 195/1 2180 Antwerpen, Belgium FACTURATIEGEGEVENS IFORI BVBA RPR: 472.073.759 (Gent) BTW: BE 472.073.759 IBAN: BE17 2900 5044 0021 BIC: GEBABEBB Thank you Questions? WWW.IFORI.BE WWW.GDPREXPERT.BE

Notas del editor

  1. In sum, it is a privacy-enhancing technique where directly identifying data is held separately and securely from processed data to ensure non-attribution. Still personal data! Other purposes: Encryption and pseudo Encryption: adhere to Data security principles + no breach notification + for other purposes (appropriate safeguards)
  2. Niet voor: technische cookies ookies over de inhoud zelf van de transactie/uitdrukkelijk gevraagd: de taalkeuze, de inhoud van een formulier of een winkelmandje; er kan gesteld worden dat deze cookies in feite gedekt zijn door de impliciete toestemming van de betrokken persoon, op voorwaarde dat die persoon geïnformeerd is over het gebruik en dat ze niet langer worden bewaard dan de tijd die nodig is of dat ze door de bezoeker zelf kunnen gewist worden. protection of privacy in the electronic communications sector  electronic communications networks and services (Framework Directive)
  3. Pragmatisch: toegang blokkeren + opzetten OOO Finaliteit: voorkomen ongeloorlfode feiten, geode zeten; bescherming bedrijfsbelangen; veiligheid, werking ICT system; naleving ICT policy. Recommend: Preventieve maatregelen; Controle: finaliteit (continuiteit), informatie (gedragscode), proportionaliteit (vertrouwenspersoon, enkel relevante emails)