SlideShare a Scribd company logo
1 of 83
Download to read offline
Data protection 2013
Friday 8 February
#dmadata
Supported by
DMA Scotland legal update
Wednesday 28 May 2014, Standard Life House
#dmascotland
8.30am Registration and breakfast
9.00am Welcome from the chair
Lynsey Fusco, CCRM manager, Visit Scotland
9.05am EU draft Data Protection Regulation – the current position, potential changes and
Impact on the industry
James Milligan, Solicitor, DMA
9.45am Information Commissioner’s Office – trends and issues
Maureen Falconer, Senior policy officer, ICO
10.25am Current legal issues affecting the direct marketing industry
James Milligan, Solicitor, DMA
11.10am Questions
11.30am Closing comments from the chair
Lynsey Fusco, CCRM manager, Visit Scotland
Agenda
Welcome from chair
Lynsey Fusco, CCRM manager, VisitScotland & Chair of
DMA Scotland council
#dmascotland
EU Draft Data Protection Regulation –
the current position, potential changes
and impact on the industry
James Milligan, Solicitor, DMA
#dmascotland
Impact of the new Data Protection
Regulation – Why now?
• Data Protection Directive 95/46/EC ("Directive") (implemented
in UK by 1998 Data Protection Act) showing its age
• New technologies and more complex information networks
• Lack of common European law and differences in national
implementation
• Consumer concern over privacy
• Data protection now a fundamental right under EU Charter of
Fundamental Rights
5
EU data protection reform timeline
• Jan 2012 -first draft Data Protection Regulation ("DPR")
• December 2012-amendments suggested by the
Rapporteur of EC Committee on Civil Liberties, Justice and
Home Affairs ("LIBE Report")
• February – May 2013 – Reported that 4000 amendments
tabled
• May 2013- partial "compromise" draft from Justice and
Home Affairs Ministers ( "CD" )
• October 2013 -LIBE voted on amendments
• October 2013 – Heads of Government meeting
• December 2013 – Inconclusive Justice and Home Affairs
Ministers meeting
6
EU data protection reform timeline
• Jan 2014 Civil servants working group meetings
continue
• Mar 2014 Inconclusive Justice and Home Affairs
Ministers meeting
• Mar 2014 MEPs adopted LIBE report
• May 2014 European Parliament elections
• June 2014 Next Justice and Home Affairs Ministers
Meeting
• Nov 2014 New European Justice Commissioner and
other Commissioners take office
• Dec 2014 Justice and Home Affairs Ministers agree
position
• 2015 Regulation is passed in Brussels
• 2017 Implemented into UK law
8
8
• LIBE report adopted by all MEPs March 2014
• Proposes a number of changes to European Commission
original text
• Majority of changes favour consumer rather than businesses
Changes proposed by the European
Parliament to the draft Data Protection
Regulation (LIBE Report)
The "compromise draft" agreed by
EU Justice Ministers 31 May 2013
• "More business friendly" compromise draft ("CD") is only
partial: Chapters I-IV
• More changes to Chapters I-IV may be needed once the
remainder has been updated
• Regulation or Directive? – wording proposed allows for
Regulation to be transformed into a Directive (supported by
8 member states)
• June 2014 Chapter V may be added to draft
9
Headline proposed changes
• Expanded definitions: “personal data” and “data subject”
• Explicit consent required
• Right to be forgotten
• Greater emphasis on accountability
• Notification of data security breaches
• More onerous sanctions for breach
• Data processors directly covered
10
Consent
Consent: Current Position Consent: Proposed Position
- Freely given, specific,
informed indication of the
data subject’s wishes
- Explicit consent required
for sensitive personal data
only
-Freely given, specific, informed and
explicit indication of data subject’s
wishes
-Given either by a statement or a
clear affirmative action
- Data controller / data subject
relationship to be taken into
account
- Burden of proof on controller to
demonstrate consent
11
Introduction of opt-in/explicit consent
• Review language used at point of data collection to ensure
that consent is explicit /opt-in
• Do people understand what they are agreeing to? – nation
of liars
• Think about how you will update legacy databases
• Children – consent wording for under 13’s if offering them
an information society service
12
Key points in the draft Regulation
IP addresses and cookies
• Definition of personal data extended so could cover some
IP addresses and cookies as “online identifiers”
• But IP addresses identify a device not an individual + some
IPs are general
• Huge implications for digital marketers
• Web analytics & profiling made much more difficult, if not
impossible
• Interaction with new cookie rules problematic
13
IP addresses and cookies
• Think about how you will deal with extension to Include
location data, IP addresses, cookies, online identifiers
• Pseudonymous/annonymous data – will you be able to
take advantage of exceptions?
14
• Right for individuals to request organisations to delete any
information held on them
• Drafted with social media in mind – but goes beyond this
• Problem of information that has already been passed on to
third parties
• Possibility of misleading consumers by raising unrealistic
expectations
• Changes to current text likely
• European Court of Justice Google Spain case
15
Key points in the draft Regulation
The right to be forgotten
The right to be forgotten
• Prepare to respond to requests
• Deletion/ suppression
• Other legal requirements to keep information e.g.
accounting, tax, money-laundering
16
Key points in the draft Regulation
Data Breach notification
• Any data security breach to be notified to ICO and the
individuals concerned within 24 hours
• Report to cover:
• nature of breach
• number of data subjects
• categories of data
• proposed mitigation
• Not always obvious if there has been a breach or how
extensive it is
• Problem of notification fatigue
• No threshold level specified
17
Data security breach notification
• Introduce breach notification detection procedures
• Think about how you will notify data protection authorities
and affected individuals within whatever timescale is
agreed
• Develop/review your data breach response plan
18
Key points in the draft Regulation
Subject Access Requests (SARs)
• Data subjects to be able to request full information on data
held on them free of any charge
• Currently can levy a £10 fee – doesn’t cover cost but deters
time-wasters, frivolous or vexatious requests
• Costs organisations £50 million p.a. now to meet SARs
• Proposal that can provide data in electronic form if data
subject agrees to this
• Particular problem for financial services with mis-selling
issues and claims management firms
19
Subject Access Rights
• New Regulation may lead to increased public awareness of
rights e.g., right to request information ( Data Subject Access
Requests, Right to be forgotten)
• Plan ahead for increase in queries from clients/public
• Training for client/customer service teams
• Amend wording on privacy policies/data collection notices to
take account of new rules on profiling.
20
Key points in the draft Regulation
Compliance obligations
• Data protection obligations now shared between agencies and
clients, for example if holding client’s database
• Privacy by Design/Privacy by Default
• Appointment of DP officer (250+ employees)
- 2 year appointment
- Independent reporting to board
- Information and training
- Maintenance of documentation
- Data protection impact reports
• International transfers of data outside EEA – law would
apply to any processing of data or EU citizens
21
Compliance obligations
• Review amount of data being processed, erasure policies
and data retention policies
• Requirement to demonstrate compliance will mean more
documentation in respect of policies and procedures
• Contact centres, mailing houses, email/SMS broadcasters
will also be subject to these new obligations, especially in
respect of data security
• Review staff training in data protection.
• Appointment of a data protection officer?
• Risk- based approach to compliance and data protection
impact assessments
22
Key points in the draft Regulation
Proposed enhanced sanctions
• Up to €500k or 1% annual worldwide turnover intentional or
negligent failure to respond to subject access requests in
accordance with Regulation
• Up to €1m or 2% of annual worldwide turnover for other
compliance failures
• Depends on:-
- size of organisation involved
- nature and gravity of breach
- whether intentional or negligent
- technical and organisational measures
- previous breaches
- co-operation with ICO
23
Enhanced sanctions/fines
• Watch out if you get it wrong!
• Increase focus on compliance – board level issue
• Review internal policies and procedures
24
Key Points in the draft Regulation
Delegated Acts
• Many details to be implemented through additional delegated
legislation – some 45 Delegated Acts mentioned.
• Details will not be clear until Regulation is passed
• These areas of secondary legislation will include:
- powers to specify further procedures
- technical standards for Privacy by Design/Default
- specification of lawful processing condition
- additional responsibilities for national data protection
authorities; etc.
• European Commission taking significant powers to itself away
from the national authorities - raises serious issues of
subsidiarity and accountability
• National governments and Data Protection Authorities are
concerned
25
• Main establishment/ one- stop shop provisions
• Think about which country’s national data protection
authority will be lead regulator
• Possibility of changing country where head office is located
• Review arrangements for transfers of data outside EEA (28
Member States of EU + Iceland ,Liechtenstein, Norway)
• Global group – application to EU citizens’ personal data.
• European Court of Justice Google Spain right to be forgotten
case - link between Google Spain and Google USA
26
Key Points in the draft Regulation
Cross – border issues
Impact on direct marketing
• Existing databases may not be usable: could decimate
prospect lists. Legacy data?
• No tracking data, profiling or segmentation without explicit
consent – less targeted and more generic communication?
• List broking severely restricted
• New information requirements and rights of the data
subject, e.g Right to be Forgotten
• Increased costs - £76,000 per business to comply +
possible £47 billion of lost sales in UK
27
Draft Regulation - DMA View
• DMA welcomes the Commission’s aim to reduce red tape
and simplify bureaucracy – but proposals do not achieve
that: overly strict, bureaucratic and unworkable
• Needs to be a fair balance between privacy and
legitimate business interests
• Current proposals will stifle innovation, add considerably
to business costs and place unnecessary obstacles to e-
commerce jobs growth
• Will be particularly harmful to SMEs – MoJ says
demonstrating compliance will cost £10m p.a.
• Hard to say how Commission’s estimate of 2.3 billion
euro saving to businesses was calculated
28
Ministry of Justice
• Disagrees with Commission’s 2.3bn Euro savings – burdens
imposed will far outweigh net benefits: in UK cost @ £100-
360 million
• Many unintended consequences, esp for SMEs
• Changes to consent, profiling & definition of personal data
particularly costly to industry
• Likely knock-on effects for growth in technological sector and
internet economy
• Regulatory Impact Assessment quotes DMA’s figures &
examples
• Impact on behavioural advertising
• Creates unrealistic expectations for consumers – R2BF
proposal is “unworkable”
29
Key lobbying messages
• Data is essential for economic growth
- UK has leading role in EU digital economy
- SMEs particularly affected
• Transparent and responsible use of data is a vital business
practice
- In industry’s interests to handle data with care
- Self-regulation has valid role to play
- Regulation will not stop bad players
• The proposed regulation is bad for consumers
- Would damage users’ online experience
- Danger of tick-box culture & unrealistic expectations
• Need a proportionate data regime that recognises that not all
data is the same
- Personal data, sensitive data, anonymous/pseudonymous
data
- Different levels of protection required 30
Lobbying activity
• In Brussels with key individuals in Council, Commission &
Parliament, e.g. MEPs & advisers; party groups
• In UK, Ministers in MoJ, DCMS, BIS, HM Treasury + Opposition
spokesmen
• Alliance of interests – UK Data Group, FEDMA, CBI, etc. - for
collective lobbying of Council and Parliament & lobbying directly
where there is no national DMA
• Position papers on priorities for industry + draft amendments to
text
• Research on consumer attitudes to privacy and on economic
value of the dm industry
31
DMA lobbying toolkit
www.dma.org.uk
32
Contacts
James Milligan, Solicitor, DMA
T - 020 7291 3347
james.milligan@dma.org.uk
Legal Advice Helpline
T - 020 7291 3360
legaladvice@dma.org.uk
33
Information Commissioner’s Office
- Trends & issues
Maureen Falconer, Senior policy officer, ICO
#dmascotland
Information
Commissioner’s Office
Trends & Issues
Maureen H Falconer
Senior Policy Officer
Key statistics - DPA
Key statistics - DPA
Key statistics - DPA
Key statistics - PECR
Key statistics - PECR
Key statistics - PECR
Key statistics - Enforcement
Key statistics - Enforcement
Trends - what goes wrong?
Lack of training, both DPA and job specific eg data ‘hidden’
in spreadsheets;
Inadequate, outdated or poorly communicated policies eg
homeworking;
Insufficient procedures eg checking documents before
posting;
Failure to implement appropriate technical solutions eg
encryption & updates;
Absent, inadequate or unclear contracts with data
processors eg what to do with data at contract
end/termination.
All of the above have featured in CMPs issued by the ICO
Wheel of data ‘misfortune’
*Adapted from David O’Hare (2000) the ‘Wheel of Misfortune’; a taxonomic approach to
human factors in accident analysis in aviation and other complex systems. Ergonomics, 2000,
vol 43 No 12 2011-2019
External Stakeholders External Pressures
Tertiary Layer of
Cause
Secondary Layer of
Cause
Task
(policies &
procedures)
Equipment / means
(Failure to secure
appropriately)
Management
(lack of commitment to
DPA)
Technical weakness
(failure to encrypt)
Training
&
EducationThe
Human Factors
(distractions, missed
steps etc.)
Regulatory action options
Closed – compliance likely Closed – compliance unlikely:
No further action taken
Remedial action taken
Referred to Enforcement – Civil investigation team:
Information Notice
Undertaking
Enforcement Notice
Civil Monetary Penalty
Framework for CMPs
Step 1
• Seriousness of the contravention
Step 2
• Aggravating and mitigating factors
Step 3
• Financial impact on the data controller
Step 4
• Underlying objective
Step 5
• Final determination
Factors for consideration:
the nature of the contravention or breach;
the scope of the potential harm caused; and
consideration of what is reasonable and proportionate.
Rating bands:
Serious = £40,000 to £100,000;
Very serious = more than £100,000 but less than £250,000;
Most serious = £250,000 up to the maximum of £500,000.
Step 1
• Seriousness of the contravention
Factors for consideration:
The behaviour of the data controller following the breach;
Whether the data controller had previously declined to
submit to an audit;
The general record of the data controller; and
Any other factors taken into account that were not
considered at Step 1.
Step 1
• Aggravating and mitigating factors
Factors for consideration:
Any proof of genuine financial hardship which has been
supplied.
The Information Commissioner will not impose a CMP that
would cause a business to cease trading!
Step 1
• Financial impact on the data controller
Factors for consideration:
Is the level consistent with comparable cases?
Is the level sufficient to promote compliance with the Act?
It is important that there is consistency in the monetary
penalties set by the ICO.
Step 1
• Underlying objective
Factors for consideration:
Is the level reasonable and proportionate?
Is the level consistent with similar cases?
Is the level sufficient to promote compliance with the Act?
Final sign-off is undertaken by the Information Commissioner
or his Deputy.
Step 1
• Final determination
Amber UPVC Fabrications Ltd:
CMP - £50,000
June 2006 - First complaints about unsolicited marketing calls received.
May 2011 - April 2013 - 513 complaints to TPS from registered individuals
who had received unsolicited direct marketing calls from Amber Windows.
On 377 occasions Amber Windows failed to respond to the TPS. When it did,
the following excuses were made:
On 67 occasions Amber Windows said it was a “programming error”.
On 37 occasions Amber Windows said “we use Telephone Europe Ltd for
outbound calling”.
On 24 occasions Amber Windows said it was “human error”.
On 3 occasions no reason was given.
On 3 occasions Amber Windows claimed that “there is no record of the call being
made by us”.
On 1 occasion Amber Windows claimed “we had prior consent to call this
number”.
On 1 occasion Amber Windows stated that “they need more information”.
First Financial (UK) Limited:
CMP - £175,000
February - March 2013 First Financial instigated the sending of or sent
4,031 unsolicited direct marketing texts to mobile phone subscribers who
had not consented to receive them.
It used unregistered SIM cards for the campaign to avoid detection by the
mobile telephone networks’ spam detectors.
The texts were sent at inconvenient and unsociable hours of the
morning and evening and at weekends e.g. 01:00 hours;
The texts interrupted people’s sleep;
The texts caused particular problems for vulnerable recipients;
People texted ‘stop’ only to receive the same message minutes later;
The texts, especially when sent at unsociable times, caused
unnecessary alarm and fears for the welfare of relatives particularly
where the recipient’s number was used only for contact with a sick,
elderly or otherwise vulnerable relative or close friend;
The texts were designed to appear as if they were from a friend and
were deceptive;
Tameside Energy Services Ltd:
CMP - £175,000
May 2011 - January 2013 TPS received 1,062 complaints from persons
registered with them who had received unsolicited direct marketing calls.
612 of these were during the time when Tameside was engaged in
correspondence with the Commissioner about the contraventions.
Tameside have held a TPS licence since March 2006, and, in spite of
assurances to the contrary, did not start downloading the list until January
2013.
The number of complaints against Tameside increased during the period
when the correspondence referred to was entered into, rather than
decreased.
Better Together Campaign
Sent out 100,000 text messages promoting the Better
Together Campaign.
Complaints made to ICO by rival political campaigners and
members of the public who received the texts.
Extensive investigation by ICO discovered some permissions
given as long ago as 2006 and from unrelated sources.
Better Together Marketing Campaign – data sources (2006-2013)
Better
Together
Marketing
Company
Data Company
Marketing
Company
Marketing
Company
Data
Company
Data
Company
Media
Company
Insurance
Company
Data
Company
Marketing
Company
Price
Comparator
Data
Company
Data
Company
Loan
Company
Catalogue
Company
Marketing
Company
Car
Company
Data
Company
Finance
Company
Loan
Company
Telephone
Marketing
Sales
Company
Insurance
Company
Media
Company
Loan
Company
Marketing
Company
Marketing
Company
Marketing
Company
Finance
Company
Car
Insurance
Bank
Car
Insurance
Price
Comparator
Car Loans
Data
Company
Marketing
Company
Graphics
Company
Travel
Company
Insurance
Company
Price
Comparator
Media
Company
Media
Company
Instigator Sender
List
broker
Data
collector
www.twitter.com/iconews
Keep in touch
Scotland Office:
45 Melville Street
Edinburgh
EH3 7HL
T: 0131 244 9001 E: Scotland@ico.org.uk
Subscribe to our e-newsletter at www.ico.org.uk
or find us on…
Current legal issues affecting
the direct marketing industry
James Milligan, Solicitor, DMA
#dmascotland
What we are going to look at
Current UK ICO Issues
Changes to UK Consumer law
Nuisance calls
Financial services
Other Issues – electoral roll, employment, environment and
postal
New DMA website
60
Current UK ICO issues
Direct marketing guidance
Privacy impact assessments
Annonymisation code
New approach to data protection concerns
ICO 2020 Strategic Vision
CCTV Code of Practice
Protecting Personal Information in online services
61
Direct marketing guidance
• ICO interpretation does not change law
• Issued 9 September2013
• Retrospective , transitional period
• Respect consumer expectations and preferences
• Tightening up of third party consent for digital marketing
• Time limits for consent
• Proof of consent
• DMA clarified issues with ICO
• Supplementary DMA guidance issued May 2014
62
Privacy Impact Assessment Code of
Practice
• Published 25 Feb 2014
• Annex 1 – PIA screening questions
• Annex 2 – PIA template
• Annex 3 – PIA and data protection principles
• Relevance to draft Regulation
63
Anonymisation Code of Practice
• Issued 20 November 2012
• Re-identification – "motivated intruder" test and risk
assessment of future identification
• Big Data – does it make annoymisation of data impossible?
• Consent – "legitimate interests“
• Pseudonymous and annoymous data may be included in
draft Regulation
• Currently ICO asking for comments prior to review
64
ICO- How we deal with complaints and
concerns- A guide for data controllers
• ICO wants organisations to handle their own data protection
complaints and concerns in the first instance
• ICO will direct members of public to contact organisation in
first instance
• If public not satisfied then may follow up with ICO
• ICO will then use explanation you gave them to make it’s
decision about your organisation's compliance with DPA
• Need for your organisation to demonstrate to its customers
and to ICO that you understand your information rights
obligations
• Link to ICO’s plan – more for less
65
ICO 2020 Strategic vision
• Challenges
• What and how the ICO expects to do over next 5 years
66
CCTV Code of Practice Consultation
• Revision of existing code of practice to take account of new
technologies, including drones
• Consultation closes 1 July 2014
67
Protecting personal data in online
services: learning from the mistakes of
others
• ICO has identified eight important areas of computer
security that have arisen during investigations of online
breaches, Examples of problems and best practice
• Areas are:
• Software updates
• SQL injection
• Unnecessary services
• Decommissioning of software or services
• Password storage
• Configuration of SSl and TLS
• Inappropriate locations for processing data
• Default credentials
68
Changes to Consumer Law
Consumer Protection Amendment Regulations
Consumer Contracts Regulations
Consumer Rights Bill
69
Consumer Protection Amendment
Regulations
• Come into force 1 October 2014
• Rights for consumers for redress in respect of aggressive
and misleading practices
• Aggressive and misleading practices defined in Consumer
(Protection from Unfair Trading) Regulations
• Redress includes:
• Right to end the contract and get a full refund
• Right to a discount depending on seriousness of practice
• Right to seek damages
70
Consumer Rights Bill
• Now delayed until later in 2014
• Will be carried over into 2014-15 Parliamentary Session
• Updating and reform of UK based consumer law
• Increase consumer confidence
• Improve enforcement powers
71
Nuisance Calls
72
Nuisance Calls
• 2013 2 parliamentary inquiries
• All Party Parliamentary Group on Nuisance Calls
• Commons Select Committee on Culture Media and Sport
• 2014 Government Published Nuisance Call Action Plan
• Which? Taskforce on Consent
• ICO raided a SIM card ‘farm’ last week
• Make sure you are compliant with legal requirements in this
area
73
Financial Services
Financial Conduct Authority and Consumer Credit
Regulation
Mortgage Credit Directive
74
FCA replaces FSA
• New Vision – “To make relevant markets work well so
consumers get a fair deal”
• Consumers get financial services and products that meet
their needs from firms they can trust
• Markets and financial systems are sound and stable and
resilient with transparent pricing information
• Firms compete effectively with the interests of their
consumers and the integrity of the market at the heart of
how they run their business
75
Other issues
Electoral register
Employment
Environment
Postal
76
Other issues
• Electoral register
– Electoral Registration & Administration Bill – introduction
of individual electoral registration and system opened up
for digital application.
– Edited version of register will be kept but issue on opt-
outs.
• Employment
– TUPE – Government consultation – outcome no changes
• Environment
– Unaddressed mail preference service - awaiting DEFRA
input
77
Other issues
• Postal
– Postcode address file – new changes.
– Simplify licensing process
– Change payment structure
78
New DMA Website
79
A central hub for 1 to 1 to Millions
Communication
Contacts
James Milligan, Solicitor, DMA
T - 020 7291 3347
james.milligan@dma.org.uk
Legal Advice Helpline
T - 020 7291 3360
legaladvice@dma.org.uk
81
Questions
#dmascotland
Closing comments from chair
Lynsey Fusco, CCRM manager, VisitScotland & Chair of
DMA Scotland council
#dmascotland

More Related Content

What's hot

The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowSophos Benelux
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...TrustArc
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1CMSLondon
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
CEE CMS Data Protection webinar series - Part 2
CEE CMS Data Protection webinar series - Part 2CEE CMS Data Protection webinar series - Part 2
CEE CMS Data Protection webinar series - Part 2CMSLondon
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoKeithBudden3
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 

What's hot (16)

GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
 
Legal update
Legal updateLegal update
Legal update
 
Legal update - 1 July
Legal update - 1 JulyLegal update - 1 July
Legal update - 1 July
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
CEE CMS Data Protection webinar series - Part 2
CEE CMS Data Protection webinar series - Part 2CEE CMS Data Protection webinar series - Part 2
CEE CMS Data Protection webinar series - Part 2
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 

Viewers also liked

Channelling the power of print communications in a digital-by-default world
Channelling the power of print communications in a digital-by-default worldChannelling the power of print communications in a digital-by-default world
Channelling the power of print communications in a digital-by-default worldRachel Aldighieri
 
Uncle harris
Uncle harrisUncle harris
Uncle harrisfujii57
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterRachel Aldighieri
 
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Rachel Aldighieri
 
Simon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiSimon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiRachel Aldighieri
 
Star power point_presentations[1]
Star power point_presentations[1]Star power point_presentations[1]
Star power point_presentations[1]lesliegvasquez
 
[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)
[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)
[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)DyanaCD
 
History of Development AL in Australia
History of Development AL in  AustraliaHistory of Development AL in  Australia
History of Development AL in AustraliaMatahati Mahbol
 
Take control of big data equifax - updated
Take control of big data   equifax - updatedTake control of big data   equifax - updated
Take control of big data equifax - updatedRachel Aldighieri
 
Awesome things
Awesome thingsAwesome things
Awesome thingswcedward
 
Who Am I?
Who Am I?Who Am I?
Who Am I?meduff7
 
Technology plan for blog
Technology plan for blogTechnology plan for blog
Technology plan for bloglesliegvasquez
 
Au Psy492 M7 A2 P Point Wilczynksi V
Au Psy492 M7 A2 P Point Wilczynksi VAu Psy492 M7 A2 P Point Wilczynksi V
Au Psy492 M7 A2 P Point Wilczynksi VVwilczynski
 
DMA Go integrated, wednesday 28 march 2012
DMA Go integrated, wednesday 28 march 2012 DMA Go integrated, wednesday 28 march 2012
DMA Go integrated, wednesday 28 march 2012 Rachel Aldighieri
 

Viewers also liked (20)

Channelling the power of print communications in a digital-by-default world
Channelling the power of print communications in a digital-by-default worldChannelling the power of print communications in a digital-by-default world
Channelling the power of print communications in a digital-by-default world
 
Uncle harris
Uncle harrisUncle harris
Uncle harris
 
In search of the perfect customer journey - Manchester
In search of the perfect customer journey - ManchesterIn search of the perfect customer journey - Manchester
In search of the perfect customer journey - Manchester
 
Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...Mark Hancock, Planning Director, The Real Adventure Unlimited...
Mark Hancock, Planning Director, The Real Adventure Unlimited...
 
Simon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBiSimon Gill, Chief Creative Officer, DigitasLBi
Simon Gill, Chief Creative Officer, DigitasLBi
 
Star power point_presentations[1]
Star power point_presentations[1]Star power point_presentations[1]
Star power point_presentations[1]
 
[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)
[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)
[Topik 6] Mata Wang di Dalam Sorotan Ringkas (Abdullah Zaidi Hassan)
 
History of Development AL in Australia
History of Development AL in  AustraliaHistory of Development AL in  Australia
History of Development AL in Australia
 
Lookbook
LookbookLookbook
Lookbook
 
Take control of big data equifax - updated
Take control of big data   equifax - updatedTake control of big data   equifax - updated
Take control of big data equifax - updated
 
Who am i (1)
Who am i (1)Who am i (1)
Who am i (1)
 
Awesome things
Awesome thingsAwesome things
Awesome things
 
Swing
Swing Swing
Swing
 
Senw prgm1[1]
Senw prgm1[1]Senw prgm1[1]
Senw prgm1[1]
 
Who Am I?
Who Am I?Who Am I?
Who Am I?
 
Desch SGP
Desch SGPDesch SGP
Desch SGP
 
Mallorca
MallorcaMallorca
Mallorca
 
Technology plan for blog
Technology plan for blogTechnology plan for blog
Technology plan for blog
 
Au Psy492 M7 A2 P Point Wilczynksi V
Au Psy492 M7 A2 P Point Wilczynksi VAu Psy492 M7 A2 P Point Wilczynksi V
Au Psy492 M7 A2 P Point Wilczynksi V
 
DMA Go integrated, wednesday 28 march 2012
DMA Go integrated, wednesday 28 march 2012 DMA Go integrated, wednesday 28 march 2012
DMA Go integrated, wednesday 28 march 2012
 

Similar to Data protection legal update

Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data OpportunityiCrossing
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...m-hance
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Brian Miller, Solicitor
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protectionMRS
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
CIO Summit talk: EU GDPR
CIO Summit talk: EU GDPRCIO Summit talk: EU GDPR
CIO Summit talk: EU GDPRJohn Culkin
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudGurbir Singh
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterBigDataExpo
 
Mind Your Business: Why Privacy Matters to the Successful Enterprise
 Mind Your Business: Why Privacy Matters to the Successful Enterprise Mind Your Business: Why Privacy Matters to the Successful Enterprise
Mind Your Business: Why Privacy Matters to the Successful EnterpriseEric Kavanagh
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRBartLieben
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminarBrowne Jacobson LLP
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15Rachel Aldighieri
 
Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...
Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...
Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...Decision CAMP
 

Similar to Data protection legal update (20)

Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data Opportunity
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
CIO Summit talk: EU GDPR
CIO Summit talk: EU GDPRCIO Summit talk: EU GDPR
CIO Summit talk: EU GDPR
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de Poorter
 
Mind Your Business: Why Privacy Matters to the Successful Enterprise
 Mind Your Business: Why Privacy Matters to the Successful Enterprise Mind Your Business: Why Privacy Matters to the Successful Enterprise
Mind Your Business: Why Privacy Matters to the Successful Enterprise
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15
 
Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...
Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...
Decision CAMP 2014 - Tobias Vigmostad - Digitalizing Business and Legislative...
 

More from Rachel Aldighieri

Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Rachel Aldighieri
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowRachel Aldighieri
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skillsRachel Aldighieri
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Rachel Aldighieri
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormRachel Aldighieri
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMARachel Aldighieri
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustRachel Aldighieri
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015Rachel Aldighieri
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterRachel Aldighieri
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Rachel Aldighieri
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Rachel Aldighieri
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015Rachel Aldighieri
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Rachel Aldighieri
 
Tim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADTim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADRachel Aldighieri
 
David Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltDavid Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltRachel Aldighieri
 
Thinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberThinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberRachel Aldighieri
 
Thinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 NovemberThinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 NovemberRachel Aldighieri
 

More from Rachel Aldighieri (20)

Navigating B2B marketing
Navigating B2B marketingNavigating B2B marketing
Navigating B2B marketing
 
Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015Taking the lead: customer acquisition barometer 2015
Taking the lead: customer acquisition barometer 2015
 
The value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to knowThe value of mail: what planners and marketers need to know
The value of mail: what planners and marketers need to know
 
Sharpen your social media skills
Sharpen your social media skillsSharpen your social media skills
Sharpen your social media skills
 
Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...Stop selling and start serving: how to bring data, creativity and technology ...
Stop selling and start serving: how to bring data, creativity and technology ...
 
FEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order FormFEDMA - Legal Fact Pack Summary and Pre-order Form
FEDMA - Legal Fact Pack Summary and Pre-order Form
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
 
DMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 AugustDMA Awards unplugged: a practical workshop - Thursday 13 August
DMA Awards unplugged: a practical workshop - Thursday 13 August
 
DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015DMA Awards unplugged - 30 July 2015
DMA Awards unplugged - 30 July 2015
 
DMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - ManchesterDMA Copywriting census reveal - Manchester
DMA Copywriting census reveal - Manchester
 
Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015Data detailed: how to buy and sell information responsibly - 08.07.2015
Data detailed: how to buy and sell information responsibly - 08.07.2015
 
Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015Data privacy: what the consumer really thinks - 30.06.2015
Data privacy: what the consumer really thinks - 30.06.2015
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
 
ZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROIZEDTalk 3: Creativity & ROI
ZEDTalk 3: Creativity & ROI
 
Tim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&ADTim Lindsay, Chief Executive Officer, D&AD
Tim Lindsay, Chief Executive Officer, D&AD
 
David Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, RedsaltDavid Meikle, Founding Partner, Redsalt
David Meikle, Founding Partner, Redsalt
 
Thinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 NovemberThinking inside the box data permission strategies - Wednesday 18 November
Thinking inside the box data permission strategies - Wednesday 18 November
 
Thinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 NovemberThinking inside the box: data permission strategies - 18 November
Thinking inside the box: data permission strategies - 18 November
 
Festival of Marketing
Festival of MarketingFestival of Marketing
Festival of Marketing
 

Recently uploaded

The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024CIO Business World
 
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCRCall Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCRlizamodels9
 
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdfDigital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdfDemandbase
 
Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresLisa M. Masiello
 
Master the Art of Digital Recruitment in Asia.pdf
Master the Art of Digital Recruitment in Asia.pdfMaster the Art of Digital Recruitment in Asia.pdf
Master the Art of Digital Recruitment in Asia.pdfHigher Education Marketing
 
ASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationAli Raza
 
Red bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxxRed bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxx216310017
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfEastern Online-iSURVEY
 
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdfDGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdfDemandbase
 
VIP Call Girls In Green Park 9654467111 Escorts Service
VIP Call Girls In Green Park 9654467111 Escorts ServiceVIP Call Girls In Green Park 9654467111 Escorts Service
VIP Call Girls In Green Park 9654467111 Escorts ServiceSapana Sha
 
Common Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic CreativityCommon Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic CreativityMonishka Adhikari
 
Talent Management for mba 3rd sem useful
Talent Management for mba 3rd sem usefulTalent Management for mba 3rd sem useful
Talent Management for mba 3rd sem usefulAtifaArbar
 
2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local Leads2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local LeadsSearch Engine Journal
 
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...Hugues Rey
 
What are the 4 characteristics of CTAs that convert?
What are the 4 characteristics of CTAs that convert?What are the 4 characteristics of CTAs that convert?
What are the 4 characteristics of CTAs that convert?Juan Pineda
 
The Impact of Digital Technologies
The Impact of Digital Technologies The Impact of Digital Technologies
The Impact of Digital Technologies bruguardarib
 
Michael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysisMichael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysisjunaid794917
 
Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guidekiva6
 
Research and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdf
Research and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdfResearch and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdf
Research and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdfVWO
 
2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)Jomer Gregorio
 

Recently uploaded (20)

The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
The 10 Most Inspirational Leaders LEADING THE WAY TO SUCCESS, 2024
 
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCRCall Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
Call Girls In Aerocity Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delhi NCR
 
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdfDigital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
 
Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample Genres
 
Master the Art of Digital Recruitment in Asia.pdf
Master the Art of Digital Recruitment in Asia.pdfMaster the Art of Digital Recruitment in Asia.pdf
Master the Art of Digital Recruitment in Asia.pdf
 
ASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationASO Process: What is App Store Optimization
ASO Process: What is App Store Optimization
 
Red bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxxRed bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxx
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
 
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdfDGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
DGR_Digital Advertising Strategies for a Cookieless World_Presentation.pdf
 
VIP Call Girls In Green Park 9654467111 Escorts Service
VIP Call Girls In Green Park 9654467111 Escorts ServiceVIP Call Girls In Green Park 9654467111 Escorts Service
VIP Call Girls In Green Park 9654467111 Escorts Service
 
Common Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic CreativityCommon Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic Creativity
 
Talent Management for mba 3rd sem useful
Talent Management for mba 3rd sem usefulTalent Management for mba 3rd sem useful
Talent Management for mba 3rd sem useful
 
2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local Leads2024's Top PPC Tactics: Triple Your Google Ads Local Leads
2024's Top PPC Tactics: Triple Your Google Ads Local Leads
 
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
 
What are the 4 characteristics of CTAs that convert?
What are the 4 characteristics of CTAs that convert?What are the 4 characteristics of CTAs that convert?
What are the 4 characteristics of CTAs that convert?
 
The Impact of Digital Technologies
The Impact of Digital Technologies The Impact of Digital Technologies
The Impact of Digital Technologies
 
Michael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysisMichael Kors marketing assignment swot analysis
Michael Kors marketing assignment swot analysis
 
Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guide
 
Research and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdf
Research and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdfResearch and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdf
Research and Discovery Tools for Experimentation - 17 Apr 2024 - v 2.3 (1).pdf
 
2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)2024 SEO Trends for Business Success (WSA)
2024 SEO Trends for Business Success (WSA)
 

Data protection legal update

  • 1. Data protection 2013 Friday 8 February #dmadata Supported by DMA Scotland legal update Wednesday 28 May 2014, Standard Life House #dmascotland
  • 2. 8.30am Registration and breakfast 9.00am Welcome from the chair Lynsey Fusco, CCRM manager, Visit Scotland 9.05am EU draft Data Protection Regulation – the current position, potential changes and Impact on the industry James Milligan, Solicitor, DMA 9.45am Information Commissioner’s Office – trends and issues Maureen Falconer, Senior policy officer, ICO 10.25am Current legal issues affecting the direct marketing industry James Milligan, Solicitor, DMA 11.10am Questions 11.30am Closing comments from the chair Lynsey Fusco, CCRM manager, Visit Scotland Agenda
  • 3. Welcome from chair Lynsey Fusco, CCRM manager, VisitScotland & Chair of DMA Scotland council #dmascotland
  • 4. EU Draft Data Protection Regulation – the current position, potential changes and impact on the industry James Milligan, Solicitor, DMA #dmascotland
  • 5. Impact of the new Data Protection Regulation – Why now? • Data Protection Directive 95/46/EC ("Directive") (implemented in UK by 1998 Data Protection Act) showing its age • New technologies and more complex information networks • Lack of common European law and differences in national implementation • Consumer concern over privacy • Data protection now a fundamental right under EU Charter of Fundamental Rights 5
  • 6. EU data protection reform timeline • Jan 2012 -first draft Data Protection Regulation ("DPR") • December 2012-amendments suggested by the Rapporteur of EC Committee on Civil Liberties, Justice and Home Affairs ("LIBE Report") • February – May 2013 – Reported that 4000 amendments tabled • May 2013- partial "compromise" draft from Justice and Home Affairs Ministers ( "CD" ) • October 2013 -LIBE voted on amendments • October 2013 – Heads of Government meeting • December 2013 – Inconclusive Justice and Home Affairs Ministers meeting 6
  • 7. EU data protection reform timeline • Jan 2014 Civil servants working group meetings continue • Mar 2014 Inconclusive Justice and Home Affairs Ministers meeting • Mar 2014 MEPs adopted LIBE report • May 2014 European Parliament elections • June 2014 Next Justice and Home Affairs Ministers Meeting • Nov 2014 New European Justice Commissioner and other Commissioners take office • Dec 2014 Justice and Home Affairs Ministers agree position • 2015 Regulation is passed in Brussels • 2017 Implemented into UK law
  • 8. 8 8 • LIBE report adopted by all MEPs March 2014 • Proposes a number of changes to European Commission original text • Majority of changes favour consumer rather than businesses Changes proposed by the European Parliament to the draft Data Protection Regulation (LIBE Report)
  • 9. The "compromise draft" agreed by EU Justice Ministers 31 May 2013 • "More business friendly" compromise draft ("CD") is only partial: Chapters I-IV • More changes to Chapters I-IV may be needed once the remainder has been updated • Regulation or Directive? – wording proposed allows for Regulation to be transformed into a Directive (supported by 8 member states) • June 2014 Chapter V may be added to draft 9
  • 10. Headline proposed changes • Expanded definitions: “personal data” and “data subject” • Explicit consent required • Right to be forgotten • Greater emphasis on accountability • Notification of data security breaches • More onerous sanctions for breach • Data processors directly covered 10
  • 11. Consent Consent: Current Position Consent: Proposed Position - Freely given, specific, informed indication of the data subject’s wishes - Explicit consent required for sensitive personal data only -Freely given, specific, informed and explicit indication of data subject’s wishes -Given either by a statement or a clear affirmative action - Data controller / data subject relationship to be taken into account - Burden of proof on controller to demonstrate consent 11
  • 12. Introduction of opt-in/explicit consent • Review language used at point of data collection to ensure that consent is explicit /opt-in • Do people understand what they are agreeing to? – nation of liars • Think about how you will update legacy databases • Children – consent wording for under 13’s if offering them an information society service 12
  • 13. Key points in the draft Regulation IP addresses and cookies • Definition of personal data extended so could cover some IP addresses and cookies as “online identifiers” • But IP addresses identify a device not an individual + some IPs are general • Huge implications for digital marketers • Web analytics & profiling made much more difficult, if not impossible • Interaction with new cookie rules problematic 13
  • 14. IP addresses and cookies • Think about how you will deal with extension to Include location data, IP addresses, cookies, online identifiers • Pseudonymous/annonymous data – will you be able to take advantage of exceptions? 14
  • 15. • Right for individuals to request organisations to delete any information held on them • Drafted with social media in mind – but goes beyond this • Problem of information that has already been passed on to third parties • Possibility of misleading consumers by raising unrealistic expectations • Changes to current text likely • European Court of Justice Google Spain case 15 Key points in the draft Regulation The right to be forgotten
  • 16. The right to be forgotten • Prepare to respond to requests • Deletion/ suppression • Other legal requirements to keep information e.g. accounting, tax, money-laundering 16
  • 17. Key points in the draft Regulation Data Breach notification • Any data security breach to be notified to ICO and the individuals concerned within 24 hours • Report to cover: • nature of breach • number of data subjects • categories of data • proposed mitigation • Not always obvious if there has been a breach or how extensive it is • Problem of notification fatigue • No threshold level specified 17
  • 18. Data security breach notification • Introduce breach notification detection procedures • Think about how you will notify data protection authorities and affected individuals within whatever timescale is agreed • Develop/review your data breach response plan 18
  • 19. Key points in the draft Regulation Subject Access Requests (SARs) • Data subjects to be able to request full information on data held on them free of any charge • Currently can levy a £10 fee – doesn’t cover cost but deters time-wasters, frivolous or vexatious requests • Costs organisations £50 million p.a. now to meet SARs • Proposal that can provide data in electronic form if data subject agrees to this • Particular problem for financial services with mis-selling issues and claims management firms 19
  • 20. Subject Access Rights • New Regulation may lead to increased public awareness of rights e.g., right to request information ( Data Subject Access Requests, Right to be forgotten) • Plan ahead for increase in queries from clients/public • Training for client/customer service teams • Amend wording on privacy policies/data collection notices to take account of new rules on profiling. 20
  • 21. Key points in the draft Regulation Compliance obligations • Data protection obligations now shared between agencies and clients, for example if holding client’s database • Privacy by Design/Privacy by Default • Appointment of DP officer (250+ employees) - 2 year appointment - Independent reporting to board - Information and training - Maintenance of documentation - Data protection impact reports • International transfers of data outside EEA – law would apply to any processing of data or EU citizens 21
  • 22. Compliance obligations • Review amount of data being processed, erasure policies and data retention policies • Requirement to demonstrate compliance will mean more documentation in respect of policies and procedures • Contact centres, mailing houses, email/SMS broadcasters will also be subject to these new obligations, especially in respect of data security • Review staff training in data protection. • Appointment of a data protection officer? • Risk- based approach to compliance and data protection impact assessments 22
  • 23. Key points in the draft Regulation Proposed enhanced sanctions • Up to €500k or 1% annual worldwide turnover intentional or negligent failure to respond to subject access requests in accordance with Regulation • Up to €1m or 2% of annual worldwide turnover for other compliance failures • Depends on:- - size of organisation involved - nature and gravity of breach - whether intentional or negligent - technical and organisational measures - previous breaches - co-operation with ICO 23
  • 24. Enhanced sanctions/fines • Watch out if you get it wrong! • Increase focus on compliance – board level issue • Review internal policies and procedures 24
  • 25. Key Points in the draft Regulation Delegated Acts • Many details to be implemented through additional delegated legislation – some 45 Delegated Acts mentioned. • Details will not be clear until Regulation is passed • These areas of secondary legislation will include: - powers to specify further procedures - technical standards for Privacy by Design/Default - specification of lawful processing condition - additional responsibilities for national data protection authorities; etc. • European Commission taking significant powers to itself away from the national authorities - raises serious issues of subsidiarity and accountability • National governments and Data Protection Authorities are concerned 25
  • 26. • Main establishment/ one- stop shop provisions • Think about which country’s national data protection authority will be lead regulator • Possibility of changing country where head office is located • Review arrangements for transfers of data outside EEA (28 Member States of EU + Iceland ,Liechtenstein, Norway) • Global group – application to EU citizens’ personal data. • European Court of Justice Google Spain right to be forgotten case - link between Google Spain and Google USA 26 Key Points in the draft Regulation Cross – border issues
  • 27. Impact on direct marketing • Existing databases may not be usable: could decimate prospect lists. Legacy data? • No tracking data, profiling or segmentation without explicit consent – less targeted and more generic communication? • List broking severely restricted • New information requirements and rights of the data subject, e.g Right to be Forgotten • Increased costs - £76,000 per business to comply + possible £47 billion of lost sales in UK 27
  • 28. Draft Regulation - DMA View • DMA welcomes the Commission’s aim to reduce red tape and simplify bureaucracy – but proposals do not achieve that: overly strict, bureaucratic and unworkable • Needs to be a fair balance between privacy and legitimate business interests • Current proposals will stifle innovation, add considerably to business costs and place unnecessary obstacles to e- commerce jobs growth • Will be particularly harmful to SMEs – MoJ says demonstrating compliance will cost £10m p.a. • Hard to say how Commission’s estimate of 2.3 billion euro saving to businesses was calculated 28
  • 29. Ministry of Justice • Disagrees with Commission’s 2.3bn Euro savings – burdens imposed will far outweigh net benefits: in UK cost @ £100- 360 million • Many unintended consequences, esp for SMEs • Changes to consent, profiling & definition of personal data particularly costly to industry • Likely knock-on effects for growth in technological sector and internet economy • Regulatory Impact Assessment quotes DMA’s figures & examples • Impact on behavioural advertising • Creates unrealistic expectations for consumers – R2BF proposal is “unworkable” 29
  • 30. Key lobbying messages • Data is essential for economic growth - UK has leading role in EU digital economy - SMEs particularly affected • Transparent and responsible use of data is a vital business practice - In industry’s interests to handle data with care - Self-regulation has valid role to play - Regulation will not stop bad players • The proposed regulation is bad for consumers - Would damage users’ online experience - Danger of tick-box culture & unrealistic expectations • Need a proportionate data regime that recognises that not all data is the same - Personal data, sensitive data, anonymous/pseudonymous data - Different levels of protection required 30
  • 31. Lobbying activity • In Brussels with key individuals in Council, Commission & Parliament, e.g. MEPs & advisers; party groups • In UK, Ministers in MoJ, DCMS, BIS, HM Treasury + Opposition spokesmen • Alliance of interests – UK Data Group, FEDMA, CBI, etc. - for collective lobbying of Council and Parliament & lobbying directly where there is no national DMA • Position papers on priorities for industry + draft amendments to text • Research on consumer attitudes to privacy and on economic value of the dm industry 31
  • 33. Contacts James Milligan, Solicitor, DMA T - 020 7291 3347 james.milligan@dma.org.uk Legal Advice Helpline T - 020 7291 3360 legaladvice@dma.org.uk 33
  • 34. Information Commissioner’s Office - Trends & issues Maureen Falconer, Senior policy officer, ICO #dmascotland
  • 35. Information Commissioner’s Office Trends & Issues Maureen H Falconer Senior Policy Officer
  • 42. Key statistics - Enforcement
  • 43. Key statistics - Enforcement
  • 44. Trends - what goes wrong? Lack of training, both DPA and job specific eg data ‘hidden’ in spreadsheets; Inadequate, outdated or poorly communicated policies eg homeworking; Insufficient procedures eg checking documents before posting; Failure to implement appropriate technical solutions eg encryption & updates; Absent, inadequate or unclear contracts with data processors eg what to do with data at contract end/termination. All of the above have featured in CMPs issued by the ICO
  • 45. Wheel of data ‘misfortune’ *Adapted from David O’Hare (2000) the ‘Wheel of Misfortune’; a taxonomic approach to human factors in accident analysis in aviation and other complex systems. Ergonomics, 2000, vol 43 No 12 2011-2019 External Stakeholders External Pressures Tertiary Layer of Cause Secondary Layer of Cause Task (policies & procedures) Equipment / means (Failure to secure appropriately) Management (lack of commitment to DPA) Technical weakness (failure to encrypt) Training & EducationThe Human Factors (distractions, missed steps etc.)
  • 46. Regulatory action options Closed – compliance likely Closed – compliance unlikely: No further action taken Remedial action taken Referred to Enforcement – Civil investigation team: Information Notice Undertaking Enforcement Notice Civil Monetary Penalty
  • 47. Framework for CMPs Step 1 • Seriousness of the contravention Step 2 • Aggravating and mitigating factors Step 3 • Financial impact on the data controller Step 4 • Underlying objective Step 5 • Final determination
  • 48. Factors for consideration: the nature of the contravention or breach; the scope of the potential harm caused; and consideration of what is reasonable and proportionate. Rating bands: Serious = £40,000 to £100,000; Very serious = more than £100,000 but less than £250,000; Most serious = £250,000 up to the maximum of £500,000. Step 1 • Seriousness of the contravention
  • 49. Factors for consideration: The behaviour of the data controller following the breach; Whether the data controller had previously declined to submit to an audit; The general record of the data controller; and Any other factors taken into account that were not considered at Step 1. Step 1 • Aggravating and mitigating factors
  • 50. Factors for consideration: Any proof of genuine financial hardship which has been supplied. The Information Commissioner will not impose a CMP that would cause a business to cease trading! Step 1 • Financial impact on the data controller
  • 51. Factors for consideration: Is the level consistent with comparable cases? Is the level sufficient to promote compliance with the Act? It is important that there is consistency in the monetary penalties set by the ICO. Step 1 • Underlying objective
  • 52. Factors for consideration: Is the level reasonable and proportionate? Is the level consistent with similar cases? Is the level sufficient to promote compliance with the Act? Final sign-off is undertaken by the Information Commissioner or his Deputy. Step 1 • Final determination
  • 53. Amber UPVC Fabrications Ltd: CMP - £50,000 June 2006 - First complaints about unsolicited marketing calls received. May 2011 - April 2013 - 513 complaints to TPS from registered individuals who had received unsolicited direct marketing calls from Amber Windows. On 377 occasions Amber Windows failed to respond to the TPS. When it did, the following excuses were made: On 67 occasions Amber Windows said it was a “programming error”. On 37 occasions Amber Windows said “we use Telephone Europe Ltd for outbound calling”. On 24 occasions Amber Windows said it was “human error”. On 3 occasions no reason was given. On 3 occasions Amber Windows claimed that “there is no record of the call being made by us”. On 1 occasion Amber Windows claimed “we had prior consent to call this number”. On 1 occasion Amber Windows stated that “they need more information”.
  • 54. First Financial (UK) Limited: CMP - £175,000 February - March 2013 First Financial instigated the sending of or sent 4,031 unsolicited direct marketing texts to mobile phone subscribers who had not consented to receive them. It used unregistered SIM cards for the campaign to avoid detection by the mobile telephone networks’ spam detectors. The texts were sent at inconvenient and unsociable hours of the morning and evening and at weekends e.g. 01:00 hours; The texts interrupted people’s sleep; The texts caused particular problems for vulnerable recipients; People texted ‘stop’ only to receive the same message minutes later; The texts, especially when sent at unsociable times, caused unnecessary alarm and fears for the welfare of relatives particularly where the recipient’s number was used only for contact with a sick, elderly or otherwise vulnerable relative or close friend; The texts were designed to appear as if they were from a friend and were deceptive;
  • 55. Tameside Energy Services Ltd: CMP - £175,000 May 2011 - January 2013 TPS received 1,062 complaints from persons registered with them who had received unsolicited direct marketing calls. 612 of these were during the time when Tameside was engaged in correspondence with the Commissioner about the contraventions. Tameside have held a TPS licence since March 2006, and, in spite of assurances to the contrary, did not start downloading the list until January 2013. The number of complaints against Tameside increased during the period when the correspondence referred to was entered into, rather than decreased.
  • 56. Better Together Campaign Sent out 100,000 text messages promoting the Better Together Campaign. Complaints made to ICO by rival political campaigners and members of the public who received the texts. Extensive investigation by ICO discovered some permissions given as long ago as 2006 and from unrelated sources.
  • 57. Better Together Marketing Campaign – data sources (2006-2013) Better Together Marketing Company Data Company Marketing Company Marketing Company Data Company Data Company Media Company Insurance Company Data Company Marketing Company Price Comparator Data Company Data Company Loan Company Catalogue Company Marketing Company Car Company Data Company Finance Company Loan Company Telephone Marketing Sales Company Insurance Company Media Company Loan Company Marketing Company Marketing Company Marketing Company Finance Company Car Insurance Bank Car Insurance Price Comparator Car Loans Data Company Marketing Company Graphics Company Travel Company Insurance Company Price Comparator Media Company Media Company Instigator Sender List broker Data collector
  • 58. www.twitter.com/iconews Keep in touch Scotland Office: 45 Melville Street Edinburgh EH3 7HL T: 0131 244 9001 E: Scotland@ico.org.uk Subscribe to our e-newsletter at www.ico.org.uk or find us on…
  • 59. Current legal issues affecting the direct marketing industry James Milligan, Solicitor, DMA #dmascotland
  • 60. What we are going to look at Current UK ICO Issues Changes to UK Consumer law Nuisance calls Financial services Other Issues – electoral roll, employment, environment and postal New DMA website 60
  • 61. Current UK ICO issues Direct marketing guidance Privacy impact assessments Annonymisation code New approach to data protection concerns ICO 2020 Strategic Vision CCTV Code of Practice Protecting Personal Information in online services 61
  • 62. Direct marketing guidance • ICO interpretation does not change law • Issued 9 September2013 • Retrospective , transitional period • Respect consumer expectations and preferences • Tightening up of third party consent for digital marketing • Time limits for consent • Proof of consent • DMA clarified issues with ICO • Supplementary DMA guidance issued May 2014 62
  • 63. Privacy Impact Assessment Code of Practice • Published 25 Feb 2014 • Annex 1 – PIA screening questions • Annex 2 – PIA template • Annex 3 – PIA and data protection principles • Relevance to draft Regulation 63
  • 64. Anonymisation Code of Practice • Issued 20 November 2012 • Re-identification – "motivated intruder" test and risk assessment of future identification • Big Data – does it make annoymisation of data impossible? • Consent – "legitimate interests“ • Pseudonymous and annoymous data may be included in draft Regulation • Currently ICO asking for comments prior to review 64
  • 65. ICO- How we deal with complaints and concerns- A guide for data controllers • ICO wants organisations to handle their own data protection complaints and concerns in the first instance • ICO will direct members of public to contact organisation in first instance • If public not satisfied then may follow up with ICO • ICO will then use explanation you gave them to make it’s decision about your organisation's compliance with DPA • Need for your organisation to demonstrate to its customers and to ICO that you understand your information rights obligations • Link to ICO’s plan – more for less 65
  • 66. ICO 2020 Strategic vision • Challenges • What and how the ICO expects to do over next 5 years 66
  • 67. CCTV Code of Practice Consultation • Revision of existing code of practice to take account of new technologies, including drones • Consultation closes 1 July 2014 67
  • 68. Protecting personal data in online services: learning from the mistakes of others • ICO has identified eight important areas of computer security that have arisen during investigations of online breaches, Examples of problems and best practice • Areas are: • Software updates • SQL injection • Unnecessary services • Decommissioning of software or services • Password storage • Configuration of SSl and TLS • Inappropriate locations for processing data • Default credentials 68
  • 69. Changes to Consumer Law Consumer Protection Amendment Regulations Consumer Contracts Regulations Consumer Rights Bill 69
  • 70. Consumer Protection Amendment Regulations • Come into force 1 October 2014 • Rights for consumers for redress in respect of aggressive and misleading practices • Aggressive and misleading practices defined in Consumer (Protection from Unfair Trading) Regulations • Redress includes: • Right to end the contract and get a full refund • Right to a discount depending on seriousness of practice • Right to seek damages 70
  • 71. Consumer Rights Bill • Now delayed until later in 2014 • Will be carried over into 2014-15 Parliamentary Session • Updating and reform of UK based consumer law • Increase consumer confidence • Improve enforcement powers 71
  • 73. Nuisance Calls • 2013 2 parliamentary inquiries • All Party Parliamentary Group on Nuisance Calls • Commons Select Committee on Culture Media and Sport • 2014 Government Published Nuisance Call Action Plan • Which? Taskforce on Consent • ICO raided a SIM card ‘farm’ last week • Make sure you are compliant with legal requirements in this area 73
  • 74. Financial Services Financial Conduct Authority and Consumer Credit Regulation Mortgage Credit Directive 74
  • 75. FCA replaces FSA • New Vision – “To make relevant markets work well so consumers get a fair deal” • Consumers get financial services and products that meet their needs from firms they can trust • Markets and financial systems are sound and stable and resilient with transparent pricing information • Firms compete effectively with the interests of their consumers and the integrity of the market at the heart of how they run their business 75
  • 77. Other issues • Electoral register – Electoral Registration & Administration Bill – introduction of individual electoral registration and system opened up for digital application. – Edited version of register will be kept but issue on opt- outs. • Employment – TUPE – Government consultation – outcome no changes • Environment – Unaddressed mail preference service - awaiting DEFRA input 77
  • 78. Other issues • Postal – Postcode address file – new changes. – Simplify licensing process – Change payment structure 78
  • 80. A central hub for 1 to 1 to Millions Communication
  • 81. Contacts James Milligan, Solicitor, DMA T - 020 7291 3347 james.milligan@dma.org.uk Legal Advice Helpline T - 020 7291 3360 legaladvice@dma.org.uk 81
  • 83. Closing comments from chair Lynsey Fusco, CCRM manager, VisitScotland & Chair of DMA Scotland council #dmascotland