SlideShare una empresa de Scribd logo
1 de 25
GETTING READY FOR
GDPR (WITH ONLY ONE
MONTH TO GO)
CHAIR
SUSAN CORDINGLEY
DIRECTOR OF PLANNING AND RESOURCES,
NCVO
SPEAKERS
KATIE BONAS
LEGAL COUNSEL, SAMARITANS
VICTORIA HORDERN
HEAD OF DATA PRIVACY,
BATESWELLS BRAITHWAITE
Dinner
sponsors:
Media
partner:
Headline
sponsor:
Lead
sponsor:
Digital
partner:
16 April 2018
Getting ready for GDPR
…and does it matter if we’re not.
NCVO Annual Conference 2018
What does Elizabeth Denham think?
ICO @ICOnews Apr 9
Q: What do you think is the most
important aspect of the GDPR?
ED: Transparency. That's the
expectation of the public. #DPPC2018
Your shopfront
So what will happen on 26th May 2018?
OR
What will likely happen on 26th May 2018?
“I hope by now you know that enforcement is a last resort. I
have no intention of changing the ICO’s proportionate and
pragmatic approach after 25th of May. Hefty fines will be
reserved for those organisations that persistently,
deliberately or negligently flout the law.
Those organisations that self-report, engage with us to
resolve issues and can demonstrate effective
accountability arrangements can expect this to be a factor
when we consider any regulatory action”.
9th April 2018
What usually leads to scrutiny from the ICO?
Avoiding Data Security Breaches
• Operational safeguards
– Governance and responsibility
• Technical safeguards
– IT security measures fit for purpose
– Regular checks and audits
– Deploying robust encryption
• Policy and Procedure safeguards
– Data Security Policy and Incident Response Plan
– Have they been road tested?
• Personnel safeguards
– Training and Education
• Legal safeguards
– Auditing third party processors
Avoiding Complaints being made to the ICO
• Transparency
– Privacy Notices
• Control
– Giving individuals sufficient control of their data
• Systems
– Systems devised that assist with responding to requests
• Policies and Procedures
– Individual Rights Policy – responsive and efficient
– Has it been road tested?
• Personnel
– Training and education
– Can identify requests from individuals quickly
Final Thoughts
• The ICO expects you to have effective accountability
arrangements
• Know your vulnerabilities/ high risk areas
• Concentrate on what you can fix now:
– Governance
– Privacy notices
– Internal policies
– Training
• Have a plan for the more complex/ time consuming areas
– Third party processor contracts
– Internal data audit/ data mapping
– Data protection by design
Victoria Hordern
Head of Data Privacy
v.hordern@bwbllp.com
020 7551 7951
GETTING READY FOR
GDPR
SUSAN CORDINGLEY
(DIRECTOR PLANNING &
RESOURCES, NCVO)
APRIL 2018
Dinner
sponsors:
Media
partner:
Headline
sponsor:
Lead
sponsor:
Digital
partner:
ASK AN EXPERT
13
ENGAGE THE TRUSTEES
14
ADOPT A RISK BASED APPROACH
15
“ Staff who can be
relied on to exercise
good judgement and
use their common
sense when required
are more likely to
achieve compliance
with Data Protection
than good policies
alone”
16
PEOPLE NOT POLICIES
DOCUMENT WHAT YOU ARE DOING
17
This Photo by Unknown Author is licensed under CC BY-NC
DATA ASSET REGISTER
• Data asset
• Data controller
• Data processor
• Asset manager
• Type of data collected
• Purpose of data
• Data retention policy
• GDPR compliant
18
SOME OF OUR TRICKIER ISSUES
Soft opt in
Recognition – what is in scope?
When does an organisation become an individual?
Data sharing
Don’t forget paper copies/ physical archives
Keeping an eye on the big picture
19
PRACTICAL HELP AND SUPPORT
ICO
ico.org.uk/for-organisations/guide-to-the-general-
data...
NCVO KnowHowNonProfit website
knowhownonprofit.org/organisation/operations/
dataprotection
20
DON’T PANIC – BUT DO ACT NOW!
GDPR – the final
countdown
Katie Bonas (Legal
Counsel,Samaritans)
Prioritise &
Focus
Communicate, communicate, communicate!
 ensure staff, volunteers and supporters know what we are
using their personal data for and on what basis
 ensure leadership team and Board are aware of progress
and risk areas
 set up FAQ pages for staff and volunteers
 attend team meetings to check how confident teams are
feeling about compliance
Cascade training & embed accountability
 compliance must be a team effort
 channel queries through one contact per department /team
to enable them to be dealt with efficiently
Prioritise &
Focus
Don’t wait for guidance
 there are many principles under the GDPR that can be
turned into action right away, without the need for
detailed guidance
 get your housekeeping in order
Record, record, record
 make sure all reviews, training sessions and
organisational changes are noted to enable you to
evidence the steps you have taken towards compliance
Prioritise &
Focus
Identify high risk areas
 document what has been done so far in these areas, what
has yet to be done, when it will be done and by whom
 allocate additional resources or time to addressing these
areas
Reach out to your network
 share ideas about how to tackle compliance
 you are not alone!
GETTING READY FOR
GDPR (WITH ONLY ONE
MONTH TO GO)
CHAIR
SUSAN CORDINGLEY
DIRECTOR OF PLANNING AND RESOURCES,
NCVO
SPEAKERS
KATIE BONAS
LEGAL COUNSEL, SAMARITANS
VICTORIA HORDERN
HEAD OF DATA PRIVACY,
BATESWELLS BRAITHWAITE
Dinner
sponsors:
Media
partner:
Headline
sponsor:
Lead
sponsor:
Digital
partner:

Más contenido relacionado

La actualidad más candente

Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides DATUM LLC
 
Achieving Regulatory Compliance The Devil Is In The Data Governance V2
Achieving Regulatory Compliance   The Devil Is In The Data Governance V2Achieving Regulatory Compliance   The Devil Is In The Data Governance V2
Achieving Regulatory Compliance The Devil Is In The Data Governance V2Ken O'Connor
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
Mwlug Compliance And E Discovery Policies
Mwlug   Compliance And E Discovery PoliciesMwlug   Compliance And E Discovery Policies
Mwlug Compliance And E Discovery PoliciesLotusDR
 
The Future Legal Marketplace: Innovation, Extrapreneurship, and a Law Withou...
The Future Legal Marketplace:  Innovation, Extrapreneurship, and a Law Withou...The Future Legal Marketplace:  Innovation, Extrapreneurship, and a Law Withou...
The Future Legal Marketplace: Innovation, Extrapreneurship, and a Law Withou...Michele DeStefano
 
Foundations non profits_and_open_source
Foundations non profits_and_open_sourceFoundations non profits_and_open_source
Foundations non profits_and_open_sourceCarol Smith
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionInfoGoTo
 
Achieving Regulatory Compliance The Devil Is In The Data Governance
Achieving Regulatory Compliance   The Devil Is In The Data GovernanceAchieving Regulatory Compliance   The Devil Is In The Data Governance
Achieving Regulatory Compliance The Devil Is In The Data GovernanceIAIDQ Community
 
ACEDS-Zylab 4-3-15 Webcast
ACEDS-Zylab 4-3-15 Webcast ACEDS-Zylab 4-3-15 Webcast
ACEDS-Zylab 4-3-15 Webcast Logikcull.com
 
Attorney Client Development for Associates
Attorney Client Development for AssociatesAttorney Client Development for Associates
Attorney Client Development for AssociatesMichael Blachly
 

La actualidad más candente (12)

Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
 
Achieving Regulatory Compliance The Devil Is In The Data Governance V2
Achieving Regulatory Compliance   The Devil Is In The Data Governance V2Achieving Regulatory Compliance   The Devil Is In The Data Governance V2
Achieving Regulatory Compliance The Devil Is In The Data Governance V2
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Mwlug Compliance And E Discovery Policies
Mwlug   Compliance And E Discovery PoliciesMwlug   Compliance And E Discovery Policies
Mwlug Compliance And E Discovery Policies
 
The Future Legal Marketplace: Innovation, Extrapreneurship, and a Law Withou...
The Future Legal Marketplace:  Innovation, Extrapreneurship, and a Law Withou...The Future Legal Marketplace:  Innovation, Extrapreneurship, and a Law Withou...
The Future Legal Marketplace: Innovation, Extrapreneurship, and a Law Withou...
 
Foundations non profits_and_open_source
Foundations non profits_and_open_sourceFoundations non profits_and_open_source
Foundations non profits_and_open_source
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
Achieving Regulatory Compliance The Devil Is In The Data Governance
Achieving Regulatory Compliance   The Devil Is In The Data GovernanceAchieving Regulatory Compliance   The Devil Is In The Data Governance
Achieving Regulatory Compliance The Devil Is In The Data Governance
 
Nick Moore: Making the bullets for others to fire (research and policy)
Nick Moore: Making the bullets for others to fire (research and policy)Nick Moore: Making the bullets for others to fire (research and policy)
Nick Moore: Making the bullets for others to fire (research and policy)
 
ACEDS-Zylab 4-3-15 Webcast
ACEDS-Zylab 4-3-15 Webcast ACEDS-Zylab 4-3-15 Webcast
ACEDS-Zylab 4-3-15 Webcast
 
Attorney Client Development for Associates
Attorney Client Development for AssociatesAttorney Client Development for Associates
Attorney Client Development for Associates
 

Similar a A2: Getting ready for GDPR (with only one month to go)

[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...AIIM International
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 Jim Kaplan CIA CFE
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Jim Kaplan CIA CFE
 
MRS Roadshow 2019
MRS Roadshow 2019MRS Roadshow 2019
MRS Roadshow 2019MRS
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsPost Media
 
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...Browne Jacobson LLP
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors
 
Hivos and Responsible Data
Hivos and Responsible DataHivos and Responsible Data
Hivos and Responsible DataTom Walker
 
Education law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOEducation law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOBrowne Jacobson LLP
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliantSiddharth Ram Dinesh
 
Implementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramImplementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramMSpadea
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Jim Kaplan CIA CFE
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 

Similar a A2: Getting ready for GDPR (with only one month to go) (20)

[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10)
 
MRS Roadshow 2019
MRS Roadshow 2019MRS Roadshow 2019
MRS Roadshow 2019
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
 
GDPR Seminar Slides
GDPR Seminar SlidesGDPR Seminar Slides
GDPR Seminar Slides
 
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
 
Hivos and Responsible Data
Hivos and Responsible DataHivos and Responsible Data
Hivos and Responsible Data
 
GDPR: Day 1 and beyond
GDPR: Day 1 and beyondGDPR: Day 1 and beyond
GDPR: Day 1 and beyond
 
Education law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPOEducation law conferences, March 2018, Workshop 1B - The role of the DPO
Education law conferences, March 2018, Workshop 1B - The role of the DPO
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliant
 
Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)
Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)
Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
Implementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramImplementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy Program
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10)
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 

Más de NCVO - National Council for Voluntary Organisations

Más de NCVO - National Council for Voluntary Organisations (20)

AGM 2022: Vision for Volunteering
AGM 2022: Vision for VolunteeringAGM 2022: Vision for Volunteering
AGM 2022: Vision for Volunteering
 
AGM 2022: Building networks
AGM 2022: Building networksAGM 2022: Building networks
AGM 2022: Building networks
 
AGM 2022: Membership
AGM 2022: MembershipAGM 2022: Membership
AGM 2022: Membership
 
AGM 2022: Time Well Spent
AGM 2022: Time Well SpentAGM 2022: Time Well Spent
AGM 2022: Time Well Spent
 
AGM 2022: Undertaking a governace review
AGM 2022: Undertaking a governace reviewAGM 2022: Undertaking a governace review
AGM 2022: Undertaking a governace review
 
National Volunteering Forum: Engaging volunteers and paid staff
National Volunteering Forum: Engaging volunteers and paid staffNational Volunteering Forum: Engaging volunteers and paid staff
National Volunteering Forum: Engaging volunteers and paid staff
 
Improving organisational resilience: What trustees need to consider
Improving organisational resilience: What trustees need to considerImproving organisational resilience: What trustees need to consider
Improving organisational resilience: What trustees need to consider
 
NCVO webinar: An update on changes to the Charity Governance Code
NCVO webinar: An update on changes to the Charity Governance CodeNCVO webinar: An update on changes to the Charity Governance Code
NCVO webinar: An update on changes to the Charity Governance Code
 
Undertaking a governance effectiveness review
Undertaking a governance effectiveness reviewUndertaking a governance effectiveness review
Undertaking a governance effectiveness review
 
NCVO/Zurich webinar: Beyond cyber essentials
NCVO/Zurich webinar: Beyond cyber essentialsNCVO/Zurich webinar: Beyond cyber essentials
NCVO/Zurich webinar: Beyond cyber essentials
 
NCVO/Zurich webinar: Safeguarding through covid-19 and beyond
NCVO/Zurich webinar: Safeguarding through covid-19 and beyondNCVO/Zurich webinar: Safeguarding through covid-19 and beyond
NCVO/Zurich webinar: Safeguarding through covid-19 and beyond
 
Decision making in a crisis: Collaboration and merger
Decision making in a crisis: Collaboration and mergerDecision making in a crisis: Collaboration and merger
Decision making in a crisis: Collaboration and merger
 
Easing of lockdown practical considerations for managing and support staff
Easing of lockdown practical considerations for managing and support staffEasing of lockdown practical considerations for managing and support staff
Easing of lockdown practical considerations for managing and support staff
 
How to manage operational change in a time of uncertainty
How to manage operational change in a time of uncertaintyHow to manage operational change in a time of uncertainty
How to manage operational change in a time of uncertainty
 
Easing of lockdown – practical considerations for managing and supporting staff
Easing of lockdown – practical considerations for managing and supporting staffEasing of lockdown – practical considerations for managing and supporting staff
Easing of lockdown – practical considerations for managing and supporting staff
 
NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...
NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...
NCVO webinar: Volunteering in a pandemic: Lessons from volunteering organisat...
 
NCVO webinar: UK Civil Society Almanac 2020: What the latest data tells us
NCVO webinar: UK Civil Society Almanac 2020: What the latest data tells usNCVO webinar: UK Civil Society Almanac 2020: What the latest data tells us
NCVO webinar: UK Civil Society Almanac 2020: What the latest data tells us
 
NCVO Webinar: Legal and practical considerations for returning to work
NCVO Webinar: Legal and practical considerations for returning to workNCVO Webinar: Legal and practical considerations for returning to work
NCVO Webinar: Legal and practical considerations for returning to work
 
NCVO Webinar: Board Leadership: Supporting your charity through the next phas...
NCVO Webinar: Board Leadership: Supporting your charity through the next phas...NCVO Webinar: Board Leadership: Supporting your charity through the next phas...
NCVO Webinar: Board Leadership: Supporting your charity through the next phas...
 
NCVO/CFG Webinar: Financial management and accessing government funding combi...
NCVO/CFG Webinar: Financial management and accessing government funding combi...NCVO/CFG Webinar: Financial management and accessing government funding combi...
NCVO/CFG Webinar: Financial management and accessing government funding combi...
 

Último

Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...
Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...
Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...SUHANI PANDEY
 
celebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hour
celebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hourcelebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hour
celebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hourCall Girls in Nagpur High Profile
 
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Dipal Arora
 
The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)Congressional Budget Office
 
Chakan ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Chakan ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Chakan ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Chakan ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...
celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...
celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...Call Girls in Nagpur High Profile
 
Election 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdfElection 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdfSamirsinh Parmar
 
1935 CONSTITUTION REPORT IN RIPH FINALLS
1935 CONSTITUTION REPORT IN RIPH FINALLS1935 CONSTITUTION REPORT IN RIPH FINALLS
1935 CONSTITUTION REPORT IN RIPH FINALLSarandianics
 
2024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 312024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 31JSchaus & Associates
 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 
VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...SUHANI PANDEY
 
The NAP process & South-South peer learning
The NAP process & South-South peer learningThe NAP process & South-South peer learning
The NAP process & South-South peer learningNAP Global Network
 
Call On 6297143586 Viman Nagar Call Girls In All Pune 24/7 Provide Call With...
Call On 6297143586  Viman Nagar Call Girls In All Pune 24/7 Provide Call With...Call On 6297143586  Viman Nagar Call Girls In All Pune 24/7 Provide Call With...
Call On 6297143586 Viman Nagar Call Girls In All Pune 24/7 Provide Call With...tanu pandey
 
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...nservice241
 
2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30JSchaus & Associates
 

Último (20)

Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...
Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...
Hinjewadi * VIP Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service ...
 
celebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hour
celebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hourcelebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hour
celebrity 💋 Patna Escorts Just Dail 8250092165 service available anytime 24 hour
 
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
 
The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)
 
Chakan ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Chakan ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Chakan ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Chakan ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
call girls in Raghubir Nagar (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service ...
call girls in Raghubir Nagar (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service ...call girls in Raghubir Nagar (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service ...
call girls in Raghubir Nagar (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service ...
 
celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...
celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...
celebrity 💋 Nagpur Escorts Just Dail 8250092165 service available anytime 24 ...
 
Election 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdfElection 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdf
 
1935 CONSTITUTION REPORT IN RIPH FINALLS
1935 CONSTITUTION REPORT IN RIPH FINALLS1935 CONSTITUTION REPORT IN RIPH FINALLS
1935 CONSTITUTION REPORT IN RIPH FINALLS
 
2024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 312024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 31
 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
 
AHMR volume 10 number 1 January-April 2024
AHMR volume 10 number 1 January-April 2024AHMR volume 10 number 1 January-April 2024
AHMR volume 10 number 1 January-April 2024
 
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
 
VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Baramati ( Pune ) Call ON 8005736733 Starting From 5K to...
 
The NAP process & South-South peer learning
The NAP process & South-South peer learningThe NAP process & South-South peer learning
The NAP process & South-South peer learning
 
Call On 6297143586 Viman Nagar Call Girls In All Pune 24/7 Provide Call With...
Call On 6297143586  Viman Nagar Call Girls In All Pune 24/7 Provide Call With...Call On 6297143586  Viman Nagar Call Girls In All Pune 24/7 Provide Call With...
Call On 6297143586 Viman Nagar Call Girls In All Pune 24/7 Provide Call With...
 
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
 
2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30
 
Sustainability by Design: Assessment Tool for Just Energy Transition Plans
Sustainability by Design: Assessment Tool for Just Energy Transition PlansSustainability by Design: Assessment Tool for Just Energy Transition Plans
Sustainability by Design: Assessment Tool for Just Energy Transition Plans
 
Russian🍌Dazzling Hottie Get☎️ 9053900678 ☎️call girl In Chandigarh By Chandig...
Russian🍌Dazzling Hottie Get☎️ 9053900678 ☎️call girl In Chandigarh By Chandig...Russian🍌Dazzling Hottie Get☎️ 9053900678 ☎️call girl In Chandigarh By Chandig...
Russian🍌Dazzling Hottie Get☎️ 9053900678 ☎️call girl In Chandigarh By Chandig...
 

A2: Getting ready for GDPR (with only one month to go)

  • 1. GETTING READY FOR GDPR (WITH ONLY ONE MONTH TO GO) CHAIR SUSAN CORDINGLEY DIRECTOR OF PLANNING AND RESOURCES, NCVO SPEAKERS KATIE BONAS LEGAL COUNSEL, SAMARITANS VICTORIA HORDERN HEAD OF DATA PRIVACY, BATESWELLS BRAITHWAITE Dinner sponsors: Media partner: Headline sponsor: Lead sponsor: Digital partner:
  • 2. 16 April 2018 Getting ready for GDPR …and does it matter if we’re not. NCVO Annual Conference 2018
  • 3. What does Elizabeth Denham think? ICO @ICOnews Apr 9 Q: What do you think is the most important aspect of the GDPR? ED: Transparency. That's the expectation of the public. #DPPC2018
  • 5. So what will happen on 26th May 2018? OR
  • 6. What will likely happen on 26th May 2018? “I hope by now you know that enforcement is a last resort. I have no intention of changing the ICO’s proportionate and pragmatic approach after 25th of May. Hefty fines will be reserved for those organisations that persistently, deliberately or negligently flout the law. Those organisations that self-report, engage with us to resolve issues and can demonstrate effective accountability arrangements can expect this to be a factor when we consider any regulatory action”. 9th April 2018
  • 7. What usually leads to scrutiny from the ICO?
  • 8. Avoiding Data Security Breaches • Operational safeguards – Governance and responsibility • Technical safeguards – IT security measures fit for purpose – Regular checks and audits – Deploying robust encryption • Policy and Procedure safeguards – Data Security Policy and Incident Response Plan – Have they been road tested? • Personnel safeguards – Training and Education • Legal safeguards – Auditing third party processors
  • 9. Avoiding Complaints being made to the ICO • Transparency – Privacy Notices • Control – Giving individuals sufficient control of their data • Systems – Systems devised that assist with responding to requests • Policies and Procedures – Individual Rights Policy – responsive and efficient – Has it been road tested? • Personnel – Training and education – Can identify requests from individuals quickly
  • 10. Final Thoughts • The ICO expects you to have effective accountability arrangements • Know your vulnerabilities/ high risk areas • Concentrate on what you can fix now: – Governance – Privacy notices – Internal policies – Training • Have a plan for the more complex/ time consuming areas – Third party processor contracts – Internal data audit/ data mapping – Data protection by design
  • 11. Victoria Hordern Head of Data Privacy v.hordern@bwbllp.com 020 7551 7951
  • 12. GETTING READY FOR GDPR SUSAN CORDINGLEY (DIRECTOR PLANNING & RESOURCES, NCVO) APRIL 2018 Dinner sponsors: Media partner: Headline sponsor: Lead sponsor: Digital partner:
  • 15. ADOPT A RISK BASED APPROACH 15
  • 16. “ Staff who can be relied on to exercise good judgement and use their common sense when required are more likely to achieve compliance with Data Protection than good policies alone” 16 PEOPLE NOT POLICIES
  • 17. DOCUMENT WHAT YOU ARE DOING 17 This Photo by Unknown Author is licensed under CC BY-NC
  • 18. DATA ASSET REGISTER • Data asset • Data controller • Data processor • Asset manager • Type of data collected • Purpose of data • Data retention policy • GDPR compliant 18
  • 19. SOME OF OUR TRICKIER ISSUES Soft opt in Recognition – what is in scope? When does an organisation become an individual? Data sharing Don’t forget paper copies/ physical archives Keeping an eye on the big picture 19
  • 20. PRACTICAL HELP AND SUPPORT ICO ico.org.uk/for-organisations/guide-to-the-general- data... NCVO KnowHowNonProfit website knowhownonprofit.org/organisation/operations/ dataprotection 20 DON’T PANIC – BUT DO ACT NOW!
  • 21. GDPR – the final countdown Katie Bonas (Legal Counsel,Samaritans)
  • 22. Prioritise & Focus Communicate, communicate, communicate!  ensure staff, volunteers and supporters know what we are using their personal data for and on what basis  ensure leadership team and Board are aware of progress and risk areas  set up FAQ pages for staff and volunteers  attend team meetings to check how confident teams are feeling about compliance Cascade training & embed accountability  compliance must be a team effort  channel queries through one contact per department /team to enable them to be dealt with efficiently
  • 23. Prioritise & Focus Don’t wait for guidance  there are many principles under the GDPR that can be turned into action right away, without the need for detailed guidance  get your housekeeping in order Record, record, record  make sure all reviews, training sessions and organisational changes are noted to enable you to evidence the steps you have taken towards compliance
  • 24. Prioritise & Focus Identify high risk areas  document what has been done so far in these areas, what has yet to be done, when it will be done and by whom  allocate additional resources or time to addressing these areas Reach out to your network  share ideas about how to tackle compliance  you are not alone!
  • 25. GETTING READY FOR GDPR (WITH ONLY ONE MONTH TO GO) CHAIR SUSAN CORDINGLEY DIRECTOR OF PLANNING AND RESOURCES, NCVO SPEAKERS KATIE BONAS LEGAL COUNSEL, SAMARITANS VICTORIA HORDERN HEAD OF DATA PRIVACY, BATESWELLS BRAITHWAITE Dinner sponsors: Media partner: Headline sponsor: Lead sponsor: Digital partner: