Skip to content
Presentation SliderStuart Davenport2018-07-15T00:34:20+01:00

Data Protection

Awareness Presentation

Welcome

  • Introduction
    – Why / When / Myths / Purpose / Definitions
  • Accountability
  • Principles
  • Rights of individuals
  • Legal Basis
  • Special Categories
  • Approach
  • Documentation

Definitions

  • GDPR – Regulation 25/5/18
  • ICO (DPA)
  • Data
  • Processing
  • Controllers & Processors
  • PECR
  • Reach
  • DPO

Each country has it’s own “Member State Authority” – The UK has the “Information Commissioners Office” based in Wilmslow, Cheshire

Data Protection is all about Data and Processing

Data is defined as something which can identify someone – a name on it’s own does not do that (there are thousands of John Smiths) however most organisations will have a name plus other information such as an address or telephone number which means the combination of information identifies the individual. Another example is a business email address, which (usually) provides a name and where they work

Processing is defined as anything which allows you to take in information, that could be on a PC/laptop screen, via a recorded conversation, within archived files, on paper.. If you can take in data, it is considered processing.

Organisations that process data are generally split in to 2 categories – Controllers who decide how the data is managed and Processors who process data on behalf of a controller, and have strict instructions on how to do so.

GDPR – (represented by the Data Protection Bill 2018) is about how you manage data. There is a separate regulation on how your might use for communications. This is called PECR (Privacy & Electronic Communications Regulation) which is due to be replaced by e-Privacy Regulation probably in early 2019.

The reach of GDPR extends to all countries that form part of the EEA. As and when Brexit occurs, the UK may still be a part of it, if not we will need what is called an “Adequacy Agreement” which means Europe considers our Data Protection Legislation satisfactory for UK companies to deal with people living in Europe.

The position of Data Protection Officer (DPO) is usually reserved for organisations that have the resource to appoint someone to that position who does not have any conflict of interest. Because the role of a Data Protection Officer includes elements of IT and budget (amongst other things), it is likely that only likely that larger organisations can facilitate this. It is fine for companies to use the term DPO to 3rd parties, so organisations may provide DPO details for the person who deals with data protection, however it is unlikely to be their actual job role. Many organisations might use the term Compliance Officer instead.

Why

  • 1998 – DPA
             –11% consumers using the internet
             –Taking power back
  • Value of data

                  –Cambridge Analytica

  • Ethical approach
  • Reputation
  • Competitive Edge
  • Cost of Clear up

              –“Wannacry”

In 1998 only 11% of us used the internet. This has obviously changed dramatically which the vast majority of us being on-line most of (if not all of) the time, sharing elements of data such as our location, finance details as well as email addresses on a daily basis. Many organisations have taken advantage of a lack of regulation around data to profit from the vast amounts of data available, and one of the purposes of GDPR is to take power back from them

Cambridge Analaytica used personal data for which they had no legal basis to help provide very powerful arguments about how they could affect the results of elections and referendums

The Wannacry virus held organisations to ransom by denying them access to their own data. This virus became well known when it hit some NHS Trusts in 2017, causing some operations to be cancelled amongst many other problems.

If a client provided a mobile phone to their supplier (for whatever reason) you can be assured they would treat it with the upmost care. Personal Data is no different, and it should be an expected right that organisations of all sizes protect the data for which they have been entrusted. There is excellent moral justification for following the principles of GDPR.

In the event of a breach of data (for which there have thousands of examples from Talk Talk to Currys more recently), the company is legally obliged to report the breach to the ICO if the rights and freedoms of the data subject have been put at risk. This is likely to include most breaches and is likely to damage the reputation of the business

Any business that is aligned with GDPR, is likely to be a more attractive proposition to anyone looking to place their business. It’s common sense that if you knew that an organisation would keep your personal information secure, you would be more likely to deal with them rather than a rival company that weren’t offering the same guarantees.

In the event of a breach, the company responsible is likely to face significant costs to make right their errors

ICO

  • Elizabeth Denham IC – 17/1/17

–“more than legislative box ticking”

–“the biggest change is around accountability”

–“The last ICO survey found 75 per cent of adults in the UK don’t trust businesses with their personal data”

–“cyber attack on TalkTalk in 2015 – Names, addresses, dates of birth, phone numbers and email addresses of over 150,000 customers were compromised & 15,000 peoples’ bank details”

–Facebook / Google

Elizabeth Denham is the Information Commissioner (in charge of the ICO)

These were her comments with regard to GDPR and the reasons it is necessary. Trust in our digital economy is vital for growth

Currently people place very little trust in organisations like Facebook and Google