90 likes | 117 Views
Learn why GDPR is crucial for Incentive Marketing Association members, its impact, key concepts, implications, and best practices to ensure compliance and mitigate risks.
E N D
PLEASE PAY ATTENTION – GDPR IS A STONKINGLY IMPORTANT SUBJECT FOR THE IMA
Here’s why GDPR matters to IMA members • It’s New: Data Protection Directive > Data Protection Bill (last week) > In force in May 2018. • It’s Brexit Proof: ICO has confirmed this. • The time for preparing is now: Contracts = money • Fines can be huge: £20m (i.e. Euros) or 4% turnover
Some essential concepts (and Audience Participation) • Data Controllers are… • Data Processors are… • Data Subjects are… • Definitions are broad e.g. “processing” and can have ET Effect • Data Processors can be fined (big time) for the first time • Underlying principle is CONSENT • Fall-back position is a “legitimate interest.”
Contract Negotiation: “Who wears the trousers?” • Data Controllers • Are demanding indemnities from DPs re: liabilities • Are demanding warranties from DPs that they are GDPR compliant • Asking Data Processors to sign up to “model clauses” for data transfers • It’s all about: “who owns the risk?” • Data Processors • Demand confirmation of CONSENT from DCs vis a vis workforces. • Some DPs get CONSENT direct from workforces. • A “legitimate interest” can be a 2nd line of defence, absent consent. • Data Subjects can now pursue remedies against DPs and DCs
Hacking and Mitigation • Hacking a massive risk • All the more so because ICO can now impose massive fines on DPs • Breaches to be reported to ICO within 72 hours, unless “de minimis” • “Appropriate technical and organisational measure in place to ensure the security of data.” • Reputational damage.
Top 5 “take-aways”… Create your own GDRP Plan: what do you use data for? Who uses it? Where are the risks/holes? Get someone to own the issue IT Security: Are you fit for purpose? (a) BYO? (b) retention? Commercial Contracts (a) with commercial partners – warranties, indemnities etc; (b) with data subjects – consent? Internal Procedures: For (a) policies/protocols; (b) reporting breaches Record a “legitimate interest:” another defence to “consent.”
My Contact Details • John Hayes, Principal, Constantine Law • 07769-137176; john.hayes@constantinelaw.co.uk • Link In with me • @JohnHayesCLaw