GDPR: Challenges and Opportunities - Kinetic · GDPR: Challenges and Opportunities Andrew Cormack,...

Preview:

Citation preview

GDPR: Challenges and OpportunitiesAndrew Cormack, Chief Regulatory Adviser (@Janet_LegReg)

Have you heard?

So now we know…

•People know about Data Protection

•Regulators willing to enforce

•Universities visible

Martinvl [CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0)]

It’s (especially) complicated…

Just some of the challenges

Power, not Responsibility

Magic Data Sharing

Agreements

Unclear law e.g. public task Tool support

“only by consent”

Unclear law e.g. cookies

“They do it” Brexit

Research

It’s an opportunity…

Adopt the Accountability Principle

•Distinctive•Plenty of others ignore/deny•GDPR as guide to hard questions

•Plan to do the right thing•Willingly•Openly•Beyond minimum

•Don’t rely on quibbles

Plan by Nick Youngson CC BY-SA 3.0 Alpha Stock Images

E.g. Data Protection Impact Assessments

•Do them to learn•Not just to comply

•Publish them•Great way to build confidence

E.g. Intelligent Campus

•Think/discuss/agree•Purposes•Sensors•Minimisation•Balance•Creep

•Draft DPIA toolkit available…

•Also peer-reviewed paper

E.g. Wellbeing Analytics

•Think/discuss/agree•Legal Basis• Individual Rights•Student & staff support

•Draft Code of Practice available•Working on a DPIA template

•Accepted as ICO Sandbox project J

Challenge• Changing expectations

• Of us• By us

Opportunity

• Trusted DP leaders• New thinking• New practice

GDPR for education/research

References

• ICO Cambridge Analytica report• https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/07/findings-recommendations-and-actions-

from-ico-investigation-into-data-analytics-in-political-campaigns/

• DPIAs• SOC http://repository.jisc.ac.uk/6847/1/Jisc_security_operations_centre_-_data_protection_impact_assessment.pdf• Learning Analytics http://repository.jisc.ac.uk/7150/1/data_protection_impact_assessment_learning_analytics.pdf

• Intelligent Campus (DPIA and Paper)• https://intelligentcampus.jiscinvolve.org/wp/2019/04/09/intelligent-campus-risks-benefits-and-ethics/

• Wellbeing Analytics Code of Practice• https://community.jisc.ac.uk/blogs/regulatory-developments/document/draft-wellbeing-analytics-code-practice

• Blog https://community.jisc.ac.uk/blogs/regulatory-developments

customerservices@jisc.ac.uk

jisc.ac.uk

Andrew CormackChief Regulatory Adviser

Lumen House, Library Ave, Didcot OX11 0SG

01235 822200

Recommended