33
General Data Protection Regulation 14 March 2018 Branko Bjelobaba FCII Regulation & Compliance Consultant

General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

General DataProtectionRegulation

14 March 2018

Branko Bjelobaba FCII

Regulation & Compliance Consultant

Page 2: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Branko Ltd

FCA compliance consultants

* DIY Manuals

* Workshops

* Tailored solutions

Compliance

Partner

Page 3: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Today

1. ICO

2. GDPR/DPA 2018

3. Summary

Page 4: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 5: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Setting the scene

• You have a responsibility and opportunity to

show customers that you treat their

information with the utmost care

• GDPR will force you to examine how you

communicate and market your services,

tighten up your security measures against

cybercrime and enable you to build a new

layer of trust and loyalty with customers

Page 6: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Would it

matter?

Page 7: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 8: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

1. ICO

Page 9: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 10: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 11: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 12: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 13: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Who is in charge

then?

FCA or ICO?!

Page 14: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 15: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 16: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 17: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 18: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 19: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Fines in our sector

• FSA/FCA - £7.8m

• ICO £5.5m (max £500,000)

Page 20: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 21: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 22: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 23: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 24: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 25: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

ICO - Goals

1. All organisations which collect and use personal

information do so responsibly, securely and fairly.

2. All public authorities are open and transparent,

providing people with access to official information

as a matter of course.

3. People are aware of their information rights and are confident in using them.

4. People understand how their personal information is

used and are able to take steps to protect themselves

from its misuse.

Page 26: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Relevant law

• Data Protection/GDPR

– New Data Protection Act 2018

• Nuisance calls/unsolicited marketing

– Privacy and Electronic Communications

Regulations 2003 (PECR)

Page 27: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

ICO – numbers 2016/17

• 498,108 data controllers registered

• 204,281 overall concerns reported

• 21,393 cases investigated

• Fines totalled £3.5m

• Fee income £19.7m

• Expenditure £25m (439 FTE staff)

Page 28: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Fees from 2018

Page 29: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

ICO – work with firms

• 35 audits providing advice and recommendations

• 22 information risk reviews

• 23 follow-up audits

• 58 advisory visits to SMEs

Page 30: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393
Page 31: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

Which sectors

generate the most

issues?

Page 32: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

And why?

Page 33: General Data Protection Regulation - AMII agm 2018... · 2018. 3. 28. · ICO –numbers 2016/17 •498,108 data controllers registered •204,281 overall concerns reported •21,393

2,565 self reported incidents