Director of Best Practice Gary Yantin was once again joined by Director of Course Development Nick Henderson to help you prepare for the General Data Protection Regulation. During the webinar, Nick delved into the world of privacy notices.
Under GDPR, as well as meeting all of the GDPR principles, an organisation must rely on one of six legal justifications to use personal data, known as the conditions for processing. For instance, you could process a sale to a customer by relying on condition 2, fulfilling a contract.
Different conditions give different rights to individuals. Relying on consent, for instance, gives the person the right to withdraw their consent, a right they must be informed about, usually in a privacy notice.
If the data is sensitive, i.e. about a person’s race, religion, or health status, there must be an additional justification to process this which can include explicit consent, employment law, or for medical purposes. Under GDPR, genetic and biometric data such as data from a biometric passport or fingerprint scans will now count as sensitive personal data.
As Facebook CEO Mark Zuckerberg continues his testimony in Congress following the Cambridge Analytica scandal, he has been set a pile of homework to beef up Facebook’s data protection policies and become GDPR compliant. While the enquiry came about following an investigation into cambridge analytica, in the long run it may have come at the perfect time, with GDPR just weeks away from coming into full force. During the hearing, Zuckerberg committed to implementing GDPR’s standards worldwide.
Here is what the social network giant must do ensure they are at least on the way to full compliance come 25 May 2018.
Under GDPR, Organisations that process large amounts of personal data, are in the public sector or process particularly sensitive data are required to appoint a DPO. Facebook has certainly recognised this need, advertising the vacant position on their website and other forums. It remains to be seen, however, whether Zuckerberg will seek to appoint a DPO, or someone in a similar role, to strengthen their data protection compliance across the US.
Data protection impact assessments (DPIAs) help organisations identify, assess and mitigate or minimise privacy risks with data processing activities. They’re particularly relevant when a new data processing process, system or technology is being introduced. A DPIA should be managed by the data controller, or data protection officer (DPO) if you have appointed one. Some organisations may consider appointing someone externally to conduct the project.
DPIAs contain a detailed description of the processing operations, an assessment of risks, and what controls need to be put in place to protect people’s information. DPIA’s must be carried out using new technologies or if there is a high risk. It’s also good practice to conduct them on any large scale data processing you carry out. A DPIA needs to contain a detailed description of the processing operations, an assessment of the necessity and proportionality of the processing in relation to the purpose, an assessment of risks to individuals, and what controls are put in place to mitigate any risks.
Read more: sign up for a free webinar about DPIAs
Under GDPR, organisations must undertake a DPIA when processing risky or large scale data. High risk data processing includes systematic and extensive processing activities, large scale processing, processing of special categories (sensitive) data, including those related to criminal convictions, and systematic monitoring of public areas such as CCTV.
We are excited to share that the VinciWorks Learning Management System (LMS) will be upgraded to version 6.0 in the next few months. The new version of the LMS has many improvements that focus on creating a rich user-friendly learning experience. With a beautiful new user interface, learning plans, video course creation and more, this upgrade improves many aspects of the system, without changing any of the current functionality. You can view a video demonstration of the new version by clicking on the image below.
LMS 6.0 includes hundreds of enhancements to the system architecture, improved user experience and many new features.
With GDPR (General Data Protection Regulation) day approaching, the number of vacancies in roles as a Data Protection Officer (DPO) has reportedly increased by over 700% in the last two years. Data protection professionals are finding that their skills and knowledge are suddenly invaluable and in high demand compared to a few years ago. VinciWorks’ guide to being a DPO will give you a clearer idea of what is required from a DPO, helping you appoint the right person for the role. The guide will also help those being promoted to the role of DPO gain an understanding of what is required of them under GDPR.
Often used as a free marketing tool, and with some staff having thousands of personal followers on social media platforms such as Twitter, Facebook and LinkedIn, social media is becoming an important cog in many companies’ marketing campaigns. Here is some guidance on what GDPR requires of us when using social media for marketing purposes.
GDPR does not apply to individuals using social media for their own purposes, but does apply to individuals acting as sole traders or organisations who use social media in the following ways:
This year has already been significant in terms of compliance breaches by some of the world’s largest companies. And it’s not just business who’ve seen major failings recently, as we review recent compliance scandals in this years’ Compliance Update: 1 April Special.
The Easter Bunny has been fined a record £21m by the Office of Financial Sanctions
Implementation (OFSI) for illegally importing up to 40 million Easter eggs. The eggs were illegally imported from Never Never Land in violation of international sanctions against the rogue state, with The Easter Bunny allegedly committing serious acts of bribery during the import of the eggs to cover up their origins.
Never Never Land continues to remain under severe international sanctions due to its failure to adhere to data protection laws and the continued WMD programme of dictator Captain Hook. With recent EU legislation expanding the scope of sanctions compliance, all organisations are being reminded to ensure their compliance is up to speed and they are not doing business with designated persons such as Captain Hook.
VinciWorks’ online GDPR course, GDPR: Privacy at Work, together with the other courses in VinciWorks’ GDPR training suite, is now available in French. The course combines the latest in policy and law with best practice guidelines. It provides real-world scenarios, interactive features and review questions to test understanding of key points. By completing this course users will learn how to comply with data protection laws for their specific role in the organisation. The online training is based on the General Data Protection Regulations (GDPR).
While GDPR will be coming into force across Europe on 25 May 2018, France has already enacted some legislation to prepare for the new data protection regime.
As GDPR day gets ever closer, Director of Course Development Nick Henderson will continue to help you prepare for the new EU wide regulation. During the webinar, Nick will guide you through the process of conducting a DPIA. He will also answer questions on the topic of DPIAs and give guidance on next steps to those who have already begun the process.
The webinar will cover:
The webinar is suitable for both those who have attended previous webinars on the topic and those who are joining us for the first time.