Data Protection Regulations
James Davies and Steve Lorber
23 April 2013
Crystal ball
Cheap data
• Statistics/visual imagery about how workplace has changed
over last 15 years re collection and use of data
Data Protection – a brief history
Late 1960s First
electronic messaging
1969 First email
The UK in October 1969
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1984 First Data Protection legislation
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1998 Data
Protection Act
1998 Act – key principles
What has this meant over last 15 years?
• Data subject requests
• Data protection policies - consent
• Transfer overseas especially to US
• “Light touch” enforcement
• Globalisation and other less light
touch data protection laws
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1998 Data
Protection Act
2005 Employment
Practices Code
Who is this?
Christopher Graham, Information Commissioner
2005 ICO employment practices code
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1998 Data
Protection Act
2005 Employment
Practices Code
2007 ICO Personal
Data guidance
2007 ICO Personal Data Guidance
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1998 Data
Protection Act
2005 Employment
Practices Code
2010 Sanctions
increase to £500k
2007 ICO Personal
Data guidance
2010 Increase sanction to £500k
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1998 Data
Protection Act
2005 Employment
Practices Code
2010 Sanctions
increase to £500k
2013 ICO BYOD guidance
2007 ICO Personal
Data guidance
2013 ICO BYOD guidance
Data Protection – a brief history
Late 1960s First
electronic messaging 1984 Original Data Protection
law (minimal impact)
1998 Data
Protection Act
TODAY Proposed General
Data Protection Regulation
2005 Employment
Practices Code
2010 Sanctions
increase to £500k
2013 ICO BYOD guidance
2007 ICO Personal
Data guidance
TODAY Draft Regulation
Data Protection Regulation – introduction
• What’s the problem?
• Commission solution
• Strategy
• Particular measures proposed
• Practical implications for now?
Data protection – the need for change
• Change in nature and extent of processing
• Globalisation
Different rules in different states
Cloud
• Employment context
volume
free-form data
Commission solution – a Data Protection
Regulation
• What is a regulation?
• Aim
one-stop shop
greater legal certainty - and consistency
throughout EU
reduction of administrative burden
strengthened data subject rights
efficiency of supervision and enforcement
• And “it will save money” – not just red tape
Strategy proposed
• Strategy
similar to current rules....but more
stricter data protection principles
more specific and granular obligations
more extensive individual rights...right to be forgotten...
Backed up by tougher
enforcement – fines of 2% of
global turnover
Policy, process...and documentation (1)
• Internal documentation
adopt policies
implement measures to ensure
compliance with policies
be able to demonstrate compliance
if appropriate establish an audit
Policy, process...and documentation (2)
• Documentation for data subjects
Extensive information including
> purposes of processing
> if justified by "legitimate interests" ...what those
interests are
> data subject rights and how to complain
> who gets to see it ....recipients
> If data does not come from data subject, who the
source is
Policy, process...and documentation (3)
• Very granular..... underscored by new data protection
principle
for each processing operation, controller must ensure and
demonstrate compliance
• Lots of paper .....but does it protect privacy?
Right to be forgotten
• Right to have personal data
erased if
no longer necessary in
relation to purposes for
which collected
consent withdrawn
expiry of retention period
processing is non-
compliant
Right to be forgotten
• If personal data has been
made public, controller shall
take all reasonable steps to
tell third parties
• Controller may restrict
where issue over accuracy
data needed for purposes
of proof (evidence of
business operations)
Data security (1)
• Controller and processor must
do risk assessment
implement technical and organisations measures to ensure
security
• "Personal data breach" means breach of security .... leading
to accidental or unlawful
destruction, loss or alteration
unauthorised disclosure
Data security (2)
• Duty to notify
• Duty to document breaches
• If breach is likely to affect privacy of data subjects, controller
must tell data subject of breach and what it is doing
Data protection by design
• "Data protection by design" ...if developing business in ways
that impinge on personal data (e.g. a new HR system)
implement to ensure compliance (having regard to cost and
technology)
ensure that by default system
> only processes data
necessary for purpose
> does not collect too much
> does not store too long
> controls
Data protection officer
• Controller and processor must establish
a DPO if 250 employees or more
• What are the roles/functions of a DPO?
Data protection officer
• Controller and processor must establish
a DPO if 250 employees or more
• What are the roles/functions of a DPO?
Data protection officer
Monitoring data protection
breaches
Contact point for supervisory
authority
Informing controller and
processor of obligations
under DPR (and documenting)
Monitoring
implementation of
policies (including audit
and training)
Ensuring documentation is
maintained
Monitoring protection
by design and
security
Monitoring data protection
impact assessment
Remedies and sanctions
• Up to 2% of turnover
• Enforcement by "main establishment" regulator
In EU - where purposes of processing determined or, if not,
where main processing takes place
If not established in EU, must appoint a "representative"
Special rules on employment
• Regulation allows members states to adopt special rules for
employment....but upwards only
Extra conditions for processing
Regulatory consent?
Works Council approval?
• Defeats "one-stop" shop?
What to do now?
• Proposals will change............
• Share your thoughts with MoJ?
• Processing operations
identify and record
consider how you comply
• Establish extent to which you use "consent"
to justify processing...and find other ways
Thank you

More Related Content

PPTX
Data Privacy: What you need to know about privacy, from compliance to ethics
PPTX
Data protection and privacy
PDF
Privacy and Data Security
PPTX
OVERVIEW OF DATA PROTECTION AND PRIVACY.pptx
PPTX
The Data Protection Act
PDF
Privacy & Data Protection in the Digital World
PDF
Data Protection and Privacy
Data Privacy: What you need to know about privacy, from compliance to ethics
Data protection and privacy
Privacy and Data Security
OVERVIEW OF DATA PROTECTION AND PRIVACY.pptx
The Data Protection Act
Privacy & Data Protection in the Digital World
Data Protection and Privacy

What's hot (20)

PPTX
Data protection ppt
PPTX
Privacy & Data Protection
PDF
Data Privacy & Security
PDF
Internet Governance
PDF
GDPR Basics - General Data Protection Regulation
PPTX
Introduction to Cybersecurity Fundamentals
PPTX
National Cyber Security Policy-2013
PDF
Overview on data privacy
PPTX
Data Privacy Introduction
PPT
Chapter 5
PPT
Basics of Information System Security
PPTX
Data Security - English
PPTX
General Data Protection Regulations (GDPR): Do you understand it and are you ...
PPT
Information Security
PPTX
Ethics In Information Technology
PPTX
Information security
PPTX
Presentation on Information Privacy
PPTX
Introduction to information security
DOCX
The CIA Triad - Assurance on Information Security
Data protection ppt
Privacy & Data Protection
Data Privacy & Security
Internet Governance
GDPR Basics - General Data Protection Regulation
Introduction to Cybersecurity Fundamentals
National Cyber Security Policy-2013
Overview on data privacy
Data Privacy Introduction
Chapter 5
Basics of Information System Security
Data Security - English
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Information Security
Ethics In Information Technology
Information security
Presentation on Information Privacy
Introduction to information security
The CIA Triad - Assurance on Information Security
Ad

Similar to Data protection (20)

PPTX
Data Protection: Transitioning to the GDPR
PPTX
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
PDF
Public sector breakfast club, October 2016, Exeter
PDF
GDPR for your Payroll Bureau
PPTX
Overview of privacy and data protection considerations for DEVELOP
PPTX
GDPR: The Regulator's Perspective, Peter Brown, ICO
PPSX
Gdpr demystified - making sense of the regulation
PPTX
Data protection
PDF
DMA Legal update: autumn 2013 - Tuesday 1 October
PPTX
GDPR training
 
PPT
Auditing your EU entities for data protection compliance 5661651 1
PDF
GDPR 11/1/2017
PPTX
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
PPTX
GDPR Breakfast Briefing for Business Advisors
PPTX
Get you and your business GDPR ready
PDF
Introduction to EU General Data Protection Regulation: Planning, Implementat...
PPTX
3A – DATA PROTECTION: ADVICE
 
PDF
Introduction to EU General Data Protection Regulation: Planning, Implementati...
PDF
Protection des données et de la vie privée : nouvelles obligations pour les e...
PPTX
What does GDPR mean for your business?
Data Protection: Transitioning to the GDPR
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
Public sector breakfast club, October 2016, Exeter
GDPR for your Payroll Bureau
Overview of privacy and data protection considerations for DEVELOP
GDPR: The Regulator's Perspective, Peter Brown, ICO
Gdpr demystified - making sense of the regulation
Data protection
DMA Legal update: autumn 2013 - Tuesday 1 October
GDPR training
 
Auditing your EU entities for data protection compliance 5661651 1
GDPR 11/1/2017
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing for Business Advisors
Get you and your business GDPR ready
Introduction to EU General Data Protection Regulation: Planning, Implementat...
3A – DATA PROTECTION: ADVICE
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Protection des données et de la vie privée : nouvelles obligations pour les e...
What does GDPR mean for your business?
Ad

More from Lewis Silkin (16)

PDF
Gender pay gap reporting
PPT
Developing branded products - A toolkit for agencies
PDF
Lewis silkin Brand Academy 2013 - Building valuable brands presentations
PDF
The Community-Infrastructure-Levy - round table meeting
PDF
FM Forum - Termination & TUPE
PDF
Changes to the EU procurement rules - how will it affect you?
PPT
Discrimination law and family friendly rights
PPTX
Whistleblowing and collective consultation changes
PPTX
Unfair dismissal and employment tribunals
PPTX
PDF
Lewis Silkin's Don't get it wrong #socialmedia Seminar Presentation
PDF
Lewis Silkin Seminar - Warranties and Indemnities - 8th March 2012
PDF
Lewis Silkin Seminar - What's Trending in TUPE - 8th March 2012
PDF
The New Data Protection Regulation and Cookie Compliance
PDF
Lewis Silkin Brand Academy 2011 Supplementary Document
PPTX
Lewis Silkin Brand Academy 2011 Presentation
Gender pay gap reporting
Developing branded products - A toolkit for agencies
Lewis silkin Brand Academy 2013 - Building valuable brands presentations
The Community-Infrastructure-Levy - round table meeting
FM Forum - Termination & TUPE
Changes to the EU procurement rules - how will it affect you?
Discrimination law and family friendly rights
Whistleblowing and collective consultation changes
Unfair dismissal and employment tribunals
Lewis Silkin's Don't get it wrong #socialmedia Seminar Presentation
Lewis Silkin Seminar - Warranties and Indemnities - 8th March 2012
Lewis Silkin Seminar - What's Trending in TUPE - 8th March 2012
The New Data Protection Regulation and Cookie Compliance
Lewis Silkin Brand Academy 2011 Supplementary Document
Lewis Silkin Brand Academy 2011 Presentation

Recently uploaded (20)

PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PPTX
Training Program for knowledge in solar cell and solar industry
PDF
Aug23rd - Mulesoft Community Workshop - Hyd, India.pdf
PDF
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
PPTX
agenticai-neweraofintelligence-250529192801-1b5e6870.pptx
PDF
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
PDF
LMS bot: enhanced learning management systems for improved student learning e...
PPTX
Internet of Everything -Basic concepts details
PDF
A symptom-driven medical diagnosis support model based on machine learning te...
PPTX
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
PPTX
Microsoft User Copilot Training Slide Deck
PDF
INTERSPEECH 2025 「Recent Advances and Future Directions in Voice Conversion」
PDF
Early detection and classification of bone marrow changes in lumbar vertebrae...
PDF
Ensemble model-based arrhythmia classification with local interpretable model...
DOCX
Basics of Cloud Computing - Cloud Ecosystem
PDF
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
PDF
NewMind AI Weekly Chronicles – August ’25 Week IV
PDF
Electrocardiogram sequences data analytics and classification using unsupervi...
PDF
EIS-Webinar-Regulated-Industries-2025-08.pdf
PDF
Lung cancer patients survival prediction using outlier detection and optimize...
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
Training Program for knowledge in solar cell and solar industry
Aug23rd - Mulesoft Community Workshop - Hyd, India.pdf
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
agenticai-neweraofintelligence-250529192801-1b5e6870.pptx
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
LMS bot: enhanced learning management systems for improved student learning e...
Internet of Everything -Basic concepts details
A symptom-driven medical diagnosis support model based on machine learning te...
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
Microsoft User Copilot Training Slide Deck
INTERSPEECH 2025 「Recent Advances and Future Directions in Voice Conversion」
Early detection and classification of bone marrow changes in lumbar vertebrae...
Ensemble model-based arrhythmia classification with local interpretable model...
Basics of Cloud Computing - Cloud Ecosystem
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
NewMind AI Weekly Chronicles – August ’25 Week IV
Electrocardiogram sequences data analytics and classification using unsupervi...
EIS-Webinar-Regulated-Industries-2025-08.pdf
Lung cancer patients survival prediction using outlier detection and optimize...

Data protection

  • 1. Data Protection Regulations James Davies and Steve Lorber 23 April 2013
  • 3. Cheap data • Statistics/visual imagery about how workplace has changed over last 15 years re collection and use of data
  • 4. Data Protection – a brief history Late 1960s First electronic messaging
  • 6. The UK in October 1969
  • 7. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact)
  • 8. 1984 First Data Protection legislation
  • 9. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact) 1998 Data Protection Act
  • 10. 1998 Act – key principles
  • 11. What has this meant over last 15 years? • Data subject requests • Data protection policies - consent • Transfer overseas especially to US • “Light touch” enforcement • Globalisation and other less light touch data protection laws
  • 12. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact) 1998 Data Protection Act 2005 Employment Practices Code
  • 13. Who is this? Christopher Graham, Information Commissioner
  • 14. 2005 ICO employment practices code
  • 15. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact) 1998 Data Protection Act 2005 Employment Practices Code 2007 ICO Personal Data guidance
  • 16. 2007 ICO Personal Data Guidance
  • 17. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact) 1998 Data Protection Act 2005 Employment Practices Code 2010 Sanctions increase to £500k 2007 ICO Personal Data guidance
  • 19. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact) 1998 Data Protection Act 2005 Employment Practices Code 2010 Sanctions increase to £500k 2013 ICO BYOD guidance 2007 ICO Personal Data guidance
  • 20. 2013 ICO BYOD guidance
  • 21. Data Protection – a brief history Late 1960s First electronic messaging 1984 Original Data Protection law (minimal impact) 1998 Data Protection Act TODAY Proposed General Data Protection Regulation 2005 Employment Practices Code 2010 Sanctions increase to £500k 2013 ICO BYOD guidance 2007 ICO Personal Data guidance
  • 23. Data Protection Regulation – introduction • What’s the problem? • Commission solution • Strategy • Particular measures proposed • Practical implications for now?
  • 24. Data protection – the need for change • Change in nature and extent of processing • Globalisation Different rules in different states Cloud • Employment context volume free-form data
  • 25. Commission solution – a Data Protection Regulation • What is a regulation? • Aim one-stop shop greater legal certainty - and consistency throughout EU reduction of administrative burden strengthened data subject rights efficiency of supervision and enforcement • And “it will save money” – not just red tape
  • 26. Strategy proposed • Strategy similar to current rules....but more stricter data protection principles more specific and granular obligations more extensive individual rights...right to be forgotten... Backed up by tougher enforcement – fines of 2% of global turnover
  • 27. Policy, process...and documentation (1) • Internal documentation adopt policies implement measures to ensure compliance with policies be able to demonstrate compliance if appropriate establish an audit
  • 28. Policy, process...and documentation (2) • Documentation for data subjects Extensive information including > purposes of processing > if justified by "legitimate interests" ...what those interests are > data subject rights and how to complain > who gets to see it ....recipients > If data does not come from data subject, who the source is
  • 29. Policy, process...and documentation (3) • Very granular..... underscored by new data protection principle for each processing operation, controller must ensure and demonstrate compliance • Lots of paper .....but does it protect privacy?
  • 30. Right to be forgotten • Right to have personal data erased if no longer necessary in relation to purposes for which collected consent withdrawn expiry of retention period processing is non- compliant
  • 31. Right to be forgotten • If personal data has been made public, controller shall take all reasonable steps to tell third parties • Controller may restrict where issue over accuracy data needed for purposes of proof (evidence of business operations)
  • 32. Data security (1) • Controller and processor must do risk assessment implement technical and organisations measures to ensure security • "Personal data breach" means breach of security .... leading to accidental or unlawful destruction, loss or alteration unauthorised disclosure
  • 33. Data security (2) • Duty to notify • Duty to document breaches • If breach is likely to affect privacy of data subjects, controller must tell data subject of breach and what it is doing
  • 34. Data protection by design • "Data protection by design" ...if developing business in ways that impinge on personal data (e.g. a new HR system) implement to ensure compliance (having regard to cost and technology) ensure that by default system > only processes data necessary for purpose > does not collect too much > does not store too long > controls
  • 35. Data protection officer • Controller and processor must establish a DPO if 250 employees or more • What are the roles/functions of a DPO?
  • 36. Data protection officer • Controller and processor must establish a DPO if 250 employees or more • What are the roles/functions of a DPO?
  • 37. Data protection officer Monitoring data protection breaches Contact point for supervisory authority Informing controller and processor of obligations under DPR (and documenting) Monitoring implementation of policies (including audit and training) Ensuring documentation is maintained Monitoring protection by design and security Monitoring data protection impact assessment
  • 38. Remedies and sanctions • Up to 2% of turnover • Enforcement by "main establishment" regulator In EU - where purposes of processing determined or, if not, where main processing takes place If not established in EU, must appoint a "representative"
  • 39. Special rules on employment • Regulation allows members states to adopt special rules for employment....but upwards only Extra conditions for processing Regulatory consent? Works Council approval? • Defeats "one-stop" shop?
  • 40. What to do now? • Proposals will change............ • Share your thoughts with MoJ? • Processing operations identify and record consider how you comply • Establish extent to which you use "consent" to justify processing...and find other ways