SlideShare una empresa de Scribd logo
1 de 38
Descargar para leer sin conexión
EFA Skillshare
GDPR and Fundraising
Jitty van Doodewaerd – DMCC Nederland B.V.
© 20171
New obligations under the GDPR
In 5 questions
- What data do you collect
- Is this documented
- Who’s responsible
- Are you transparant about your collection
- Do you ever delete data
But first:
Some privacy basics
Today’s program
2 www.dmcc.nl
What personal data do you collect?
© 20173
Personal data
4 www.dmcc.nl
Privacy = processing of personal data
• Processing
• Personal data
Personal data (Art 1 GDPR): any information relating to an identified or identifiable
natural person (‘data subject’); an identifiable natural person is one who can be
identified, directly or indirectly, in particular by reference to an identifier such as a name,
an identification number, location data, an online identifier or to one or more factors
specific to the physical, physiological, genetic, mental, economic, cultural or social
identity of that natural person.
Special categories of personal data (Art. 9/ 10 GDPR): data revealing racial or ethnic origin,
political opinions, religious or philosophical beliefs, trade union membership, genetic
data, biometric data for the purpose of uniquely identifying a natural person, data
concerning health or data concerning a natural person's sex life or sexual orientation,
data relating to criminal convictions and offences.
Personal data
5 www.dmcc.nl
Personal data
6 www.dmcc.nl
Personal data
7 www.dmcc.nl
Personal data
8 www.dmcc.nl
Where point (a) of Article 6(1) applies, in
relation to the offer of information society
services directly to a child, the processing of
the personal data of a child shall be lawful
where the child is at least 16 years old.
Where the child is below the age of 16
years, such processing shall be lawful only if
and to the extent that consent is given or
authorised by the holder of parental
responsibility over the child.
Member States may provide by law for a
lower age for those purposes provided that
such lower age is not below 13 years.
Is your processing documented?
© 20179
Register of processings
10 www.dmcc.nl
1. Each controller and, where applicable, the controller's representative, shall maintain
a record of processing activities under its responsibility. That record shall contain all of
the following information:
a. the name and contact details of the controller and, where applicable, the joint
controller, the controller's representative and the data protection officer;
b. the purposes of the processing;
c. a description of the categories of data subjects and of the categories of personal
data;
d. the categories of recipients to whom the personal data have been or will be
disclosed including recipients in third countries or international organisations;
e. where applicable, transfers of personal data to a third country or an international
organisation, including the identification of that third country or international
organisation and, in the case of transfers referred to in the second subparagraph of
Article 49(1), the documentation of suitable safeguards;
f. where possible, the envisaged time limits for erasure of the different categories of
data;
g. where possible, a general description of the technical and organisational security
measures referred to in Article 32(1).
Data mapping
11 www.dmcc.nl
Fundraising
➢Donor administration
➢Volunteer administration
➢Collection
➢Petitions
➢Patient association
➢Patient/ member travels
➢Website(s) en action pages
➢News letter registrars
➢Legacies
➢Major donors
➢affiliates
➢Social media
➢Cookies
➢Analytics
Projects
➢ Project management
➢ Investments
➢ Investee/ Investor due
dilligence
HRM
➢Personell administration
➢Payroll
➢Social security
➢Learning management
➢Time and attendance
Finance
➢ Creditors
➢ Debtors
➢ Beneficiaries
➢ Billing
➢ Reporting
12
Donor Ex donor participant Prospect Site visitor Beschikbaarheid Vertrouwelijkheid
Adress detaiils X X X X
E-mail X X X X
Gender X X X X
Data of birth X X
Contact and order history X X X X
Data regarding payments,
transactions etc
X X X X x
Financial data X X X
Derived financial data X X X
Lifestyle characteristics, prifile
information
X X
Special categories of data
Data mapping
13
Partij 1 Partij 1
Partij 1
Intern beheerd Partij 2
Externally managed
Partij 1
Partij 2
Partij 3
Inernally managed Externaly managed
Internally managed
Retention
Data analyses
Customer
(data warehouse)
Customer
database
Online accounts
Single Customer View
(selection tool)
(database marketing en
sales trial and ex-
subscribers)
e-mail tool sales
and marketing
Blacklist
opt-out requests
(automated
dialer)
websites/
landing pages
Data
enrichment
and validation
Telemarketing
E-mail Direct mail
(field marketing
tool) Direct sales
Data mapping
14
Data mapping
Who’s responsible?
(governance structure)
© 201715
DPA (Art. 28 GDPR)
Governance
16 www.dmcc.nl
Processing by a processor shall be governed by a contract or other legal act under Union
or Member State law, that is binding on the processor with regard to the controller and
that sets out the subject-matter and duration of the processing, the nature and purpose
of the processing, the type of personal data and categories of data subjects and the
obligations and rights of the controller. That contract or other legal act shall stipulate, in
particular, that the processor:
a. operates under clear instructions
b. ensures confidentiallity;
c. takes appropriate security measures
d. will inform about any sub processors
e. helps the controller respond to requests from data subjects
f. assists the controller in ensuring compliance
g. at the choice of the controller, deletes or returns all the personal data to the
controller after the end of the provision of services relating to processing
h. makes available to the controller all information necessary to demonstrate
compliance with the obligations laid down in this Article and allow for and contribute
to audits, including inspections, conducted by the controller or another auditor
mandated by the controller.
DPO (Art 37 GDPR)
Governance
17 www.dmcc.nl
The controller and the processor shall designate a data protection officer in any case
where:
a. the processing is carried out by a public authority or body, except for courts acting in
their judicial capacity;
b. the core activities of the controller or the processor consist of processing operations
which, by virtue of their nature, their scope and/or their purposes, require regular
and systematic monitoring of data subjects on a large scale; or
c. the core activities of the controller or the processor consist of processing on a large
scale of special categories of data pursuant to Article 9 and personal data relating to
criminal convictions and offences referred to in Article 10.
Are you transparent about your data
collection?
© 201718
A. Fair and lawfull processing
Art. 6 GDPR
a) consent(= opt-in, e-mail, sms, social media and cookie data)
b) contract (gift, donor agreement, legacies)
f) legitimate interest (profiling, direct mail etc.)
Direct Marketing is een gerechtvaardigd ondernemersbelang
Lawfull processing
B) In a transparant manner
Art 12, 13 and 14 GDPR
Information relating to processing to the data subject in a concise, transparent, intelligible
and easily accessible form, using clear and plain language about:
1) Identity
2)Purpose
3) category of data
4) rights
5) third parties
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
Privacy statement
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
At te time of collection
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
Direct Marketing is een gerechtvaardigd ondernemersbelang
Transparancy
Art 4 GDPR
(8) ‘the data subject’s consent’ means any freely-given, specific and informed (…) indication
of his or her wishes by which the data subject, either by a statement or by a clear
affirmative action, signifies agreement to personal data relating to them being
processed;
is een gerechtvaardigd ondernemersbelang
Consent
Art 7 GDPR
1. Where processing is based on consent, the controller shall be able to demonstrate that
the data subject has consented to processing of his or her personal data.
2. If the data subject's consent is given in the context of a written declaration which also
concerns other matters, the request for consent shall be presented in a manner which is
clearly distinguishable from the other matters, in an intelligible and easily accessible form,
using clear and plain language. Any part of such a declaration which constitutes an
infringement of this Regulation shall not be binding.
3. The data subject shall have the right to withdraw his or her consent at any time. The
withdrawal of consent shall not affect the lawfulness of processing based on consent before
its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be
as easy to withdraw as to give consent.
4. When assessing whether consent is freely given, utmost account shall be taken of
whether, inter alia, the performance of a contract, including the provision of a service, is
conditional on consent to the processing of personal data that is not necessary for the
performance of that contract.
is een gerechtvaardigd ondernemersbelang
Consent
Freely given
The freedom to say ‘no’to the transaction without it significantly affecting you or
produce a legal effect
is een gerechtvaardigd ondernemersbelang
Consent
Specific
Third parties, advertisers etc?
is een gerechtvaardigd ondernemersbelang
Consent
Informed?
is een gerechtvaardigd ondernemersbelang
Consent
is een gerechtvaardigd ondernemersbelang
Consent
is een gerechtvaardigd ondernemersbelang
Consent
Consent
35
When
• In effect since 2016
• Implemented by you in May 2018
Positive elements
• Instrument of a regulation
• Transparency obligations
• Fundraising is recognised as a legtimate purpose
Consent
Do you ever delete data?
© 201736
37
• Use of data limited to as long as necessary for purpose of collection
• De-activating is not enough
• Adequate data retention periods?
Data retention
Jitty van Doodewaerd (+31 (0)625516373)
DMCC Netherlands B.V.
38
Telefoon : +31 (0)88-7779311
E-mail: info@dmcc.nl
Website: www.dmcc.nl

Más contenido relacionado

La actualidad más candente

La actualidad más candente (19)

Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
20180305 the dayafter_bavovdh_cranium_dpo_pro
20180305 the dayafter_bavovdh_cranium_dpo_pro20180305 the dayafter_bavovdh_cranium_dpo_pro
20180305 the dayafter_bavovdh_cranium_dpo_pro
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
Startups - data protection
Startups  - data protectionStartups  - data protection
Startups - data protection
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization
 
Star II sme hotline 21.01.20
Star II sme hotline 21.01.20Star II sme hotline 21.01.20
Star II sme hotline 21.01.20
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
 
250220 blockchain gdpr_blockchain_hillemann_presentation
250220 blockchain gdpr_blockchain_hillemann_presentation250220 blockchain gdpr_blockchain_hillemann_presentation
250220 blockchain gdpr_blockchain_hillemann_presentation
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Go
 
Records Retention and Destruction Policies 2015
Records Retention and Destruction Policies 2015Records Retention and Destruction Policies 2015
Records Retention and Destruction Policies 2015
 
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
 
20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreements20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreements
 

Similar a EFA Skillshare - Jitty van Doodewaerd

Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
N N
 

Similar a EFA Skillshare - Jitty van Doodewaerd (20)

NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Asia Counsel Insights May 2023
Asia Counsel Insights May 2023
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
CEU DPA
CEU DPACEU DPA
CEU DPA
 
Feedback on Personal Data Protection Bill 2019
Feedback on Personal Data Protection Bill 2019Feedback on Personal Data Protection Bill 2019
Feedback on Personal Data Protection Bill 2019
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
CHINA PIP LAW ppt.pptx
CHINA PIP LAW ppt.pptxCHINA PIP LAW ppt.pptx
CHINA PIP LAW ppt.pptx
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPR
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?
 
The Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCMThe Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCM
 

Más de Patrick Jordens (6)

Privacy en compliance accept easy paydays
Privacy en compliance accept easy paydaysPrivacy en compliance accept easy paydays
Privacy en compliance accept easy paydays
 
DMCC Webinar compliance
DMCC Webinar complianceDMCC Webinar compliance
DMCC Webinar compliance
 
Presentatie marketing automation & privacy
Presentatie marketing automation & privacyPresentatie marketing automation & privacy
Presentatie marketing automation & privacy
 
Compliance met de Richtlijn Consumentenrechten
Compliance met de Richtlijn ConsumentenrechtenCompliance met de Richtlijn Consumentenrechten
Compliance met de Richtlijn Consumentenrechten
 
Gedragscode Telemarketing - 24jan2013
Gedragscode Telemarketing - 24jan2013Gedragscode Telemarketing - 24jan2013
Gedragscode Telemarketing - 24jan2013
 
Vakdag fondsenwerving 29nov2012
Vakdag fondsenwerving 29nov2012Vakdag fondsenwerving 29nov2012
Vakdag fondsenwerving 29nov2012
 

Último

If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Kayode Fayemi
 
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
David Celestin
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
amilabibi1
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
raffaeleoman
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
Kayode Fayemi
 

Último (15)

Dreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video TreatmentDreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video Treatment
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
Digital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of DrupalDigital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of Drupal
 
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
 
SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdfSOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 

EFA Skillshare - Jitty van Doodewaerd

  • 1. EFA Skillshare GDPR and Fundraising Jitty van Doodewaerd – DMCC Nederland B.V. © 20171
  • 2. New obligations under the GDPR In 5 questions - What data do you collect - Is this documented - Who’s responsible - Are you transparant about your collection - Do you ever delete data But first: Some privacy basics Today’s program 2 www.dmcc.nl
  • 3. What personal data do you collect? © 20173
  • 4. Personal data 4 www.dmcc.nl Privacy = processing of personal data • Processing • Personal data Personal data (Art 1 GDPR): any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Special categories of personal data (Art. 9/ 10 GDPR): data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation, data relating to criminal convictions and offences.
  • 8. Personal data 8 www.dmcc.nl Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.
  • 9. Is your processing documented? © 20179
  • 10. Register of processings 10 www.dmcc.nl 1. Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information: a. the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; b. the purposes of the processing; c. a description of the categories of data subjects and of the categories of personal data; d. the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations; e. where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; f. where possible, the envisaged time limits for erasure of the different categories of data; g. where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
  • 11. Data mapping 11 www.dmcc.nl Fundraising ➢Donor administration ➢Volunteer administration ➢Collection ➢Petitions ➢Patient association ➢Patient/ member travels ➢Website(s) en action pages ➢News letter registrars ➢Legacies ➢Major donors ➢affiliates ➢Social media ➢Cookies ➢Analytics Projects ➢ Project management ➢ Investments ➢ Investee/ Investor due dilligence HRM ➢Personell administration ➢Payroll ➢Social security ➢Learning management ➢Time and attendance Finance ➢ Creditors ➢ Debtors ➢ Beneficiaries ➢ Billing ➢ Reporting
  • 12. 12 Donor Ex donor participant Prospect Site visitor Beschikbaarheid Vertrouwelijkheid Adress detaiils X X X X E-mail X X X X Gender X X X X Data of birth X X Contact and order history X X X X Data regarding payments, transactions etc X X X X x Financial data X X X Derived financial data X X X Lifestyle characteristics, prifile information X X Special categories of data Data mapping
  • 13. 13 Partij 1 Partij 1 Partij 1 Intern beheerd Partij 2 Externally managed Partij 1 Partij 2 Partij 3 Inernally managed Externaly managed Internally managed Retention Data analyses Customer (data warehouse) Customer database Online accounts Single Customer View (selection tool) (database marketing en sales trial and ex- subscribers) e-mail tool sales and marketing Blacklist opt-out requests (automated dialer) websites/ landing pages Data enrichment and validation Telemarketing E-mail Direct mail (field marketing tool) Direct sales Data mapping
  • 16. DPA (Art. 28 GDPR) Governance 16 www.dmcc.nl Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor: a. operates under clear instructions b. ensures confidentiallity; c. takes appropriate security measures d. will inform about any sub processors e. helps the controller respond to requests from data subjects f. assists the controller in ensuring compliance g. at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing h. makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
  • 17. DPO (Art 37 GDPR) Governance 17 www.dmcc.nl The controller and the processor shall designate a data protection officer in any case where: a. the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; b. the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or c. the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.
  • 18. Are you transparent about your data collection? © 201718
  • 19. A. Fair and lawfull processing Art. 6 GDPR a) consent(= opt-in, e-mail, sms, social media and cookie data) b) contract (gift, donor agreement, legacies) f) legitimate interest (profiling, direct mail etc.) Direct Marketing is een gerechtvaardigd ondernemersbelang Lawfull processing
  • 20. B) In a transparant manner Art 12, 13 and 14 GDPR Information relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language about: 1) Identity 2)Purpose 3) category of data 4) rights 5) third parties Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 21. Privacy statement Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 22. Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 23. Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 24. At te time of collection Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 25. Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 26. Direct Marketing is een gerechtvaardigd ondernemersbelang Transparancy
  • 27. Art 4 GDPR (8) ‘the data subject’s consent’ means any freely-given, specific and informed (…) indication of his or her wishes by which the data subject, either by a statement or by a clear affirmative action, signifies agreement to personal data relating to them being processed; is een gerechtvaardigd ondernemersbelang Consent
  • 28. Art 7 GDPR 1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data. 2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding. 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent. 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. is een gerechtvaardigd ondernemersbelang Consent
  • 29. Freely given The freedom to say ‘no’to the transaction without it significantly affecting you or produce a legal effect is een gerechtvaardigd ondernemersbelang Consent
  • 30. Specific Third parties, advertisers etc? is een gerechtvaardigd ondernemersbelang Consent
  • 31. Informed? is een gerechtvaardigd ondernemersbelang Consent
  • 32. is een gerechtvaardigd ondernemersbelang Consent
  • 33. is een gerechtvaardigd ondernemersbelang Consent
  • 35. 35 When • In effect since 2016 • Implemented by you in May 2018 Positive elements • Instrument of a regulation • Transparency obligations • Fundraising is recognised as a legtimate purpose Consent
  • 36. Do you ever delete data? © 201736
  • 37. 37 • Use of data limited to as long as necessary for purpose of collection • De-activating is not enough • Adequate data retention periods? Data retention
  • 38. Jitty van Doodewaerd (+31 (0)625516373) DMCC Netherlands B.V. 38 Telefoon : +31 (0)88-7779311 E-mail: info@dmcc.nl Website: www.dmcc.nl