18. GDPR Flashcards
GDPR
GDPR
- Regulation in EU Law on data protection and privacy
- All individuals within the EU and EEA
EU - European Uniion
EEA - European Economic Area
GDPR
Customers in EU/EEA
must comply
If you have customers in EU/EEA, company MUST adhere to GDPR
GDPR
Violations and Fines
- Up to EUR; 20m
- 4% annual worldwide turnover (preceeding financial year)
Whichever is greater
GDPR
Personal Consent
Personal data MAY NOT be processed
UNLESS;
1. Subject provided informed consent
2. At least one legal basis to do so
- Unless express consent given, its not legal to process it
- Anything that can be identified as yours
GDPR
Restrictions
- Lawful interception
- National Sceurity
- Military Police
- Justice System
- Above have rights to the information and restricts GDPR
GDPR
Personal Data
- Names
- Email addresses
- Addresses
- Unsubscribe confirmation URLS (contain email/name/IP address)
GDPR
End User Rights
- Right to access
- Right to erasure
- Data portability
- Breach notification
- Right to access - Data controllers must provide free copy on request to subject
- Right to erasure - subjects have “right to be forgotten”
- Data portability - Users have right to access their data in electronic format
- Breach notification - Subjects must be notified of breaches within 72 hours
GDPR
Right to access
End User Rights
Data controllers must provide free copy on request to subject
GDPR
Right to erasure
End User Rights
subjects have “right to be forgotten”
- Where there are no laws or regulations for a company to be keeping your data
GDPR
Data Portability
End User Rights
Users have right to access their data in electronic format
GDPR
Breach Notification
End User Rights
Subjects must be notified of breaches within 72 hours
GDPR
Privacy by Design
Care MUST be taken to ensure personal data is secure
- Only data that is “absolutely necessary for completio of duties” is stored
GDPR
Data Protection Officers
Companies MUST appoint a Data Protection Officer
- Where companies whose activities involve data processing and monitoring
- Senior management liable. Does not mean other people are not
- Remember due dilligence and due care
GDPR
Legacy Laws in EU and between EU and US
- EU Data Protection Directive
- EU-US Safe Harbor
- Privacy Shield
GDPR
EU Data Protection Directive
Legacy Laws in EU and between EU and US
Predecessor to GDPR
- Pro privacy law
- Organisations must notify individuals how they gather and use data
- Allow subjects to opt out of sharing your data with third parties
- Subjects must opt in for use of most sensitive data
- Not legal to transport data outside of EU unless that country has adequate (same level) of privacy protection
- US as example does not have same level of protections
- No longer exists