43
What you need to know Basic awareness for Teams March 2018 1 GDPR

What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

What youneed toknow

Basicawarenessfor Teams

March 2018

1

GDPR

Page 2: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPRGENERAL

DATAPROTECTION

REGULATION

2

Page 3: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR DATE

FRIDAY25 MAY 2018

I

3

Page 4: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DISCLAIMER

This slide deck –

• Is INFORMATION

• It is NOT LEGAL ADVICE

• Is a ‘taster’ of GDPR in 30 mins

• Is NOT comprehensive coverage

4

Page 5: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

• A taster in 30 mins ~

GDPR - is a ‘momentous’ change

what do we need to learn ?

what to do NOW ?

want to learn more ?

THIS SLIDE DECK IS

5

Page 6: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

RED TAPE CONSULTING’SGDPR INFOIs acquired through links with -

• Law & Accounting firms

• Tech & Digital firms

By seeking out key items -

• Academic, business, public sector

Through business & training events -

• Observe, learn, test/ evaluate, share

6

Page 7: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

RED TAPE CONSULTING’SAPPROACH

Translate this learning

into

practical tips

for business leaders & teams

7

Page 8: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPRApplies to any company –

• based in the EU

• storing data in the EU

or

• handling the personal data of EUcitizens

• Brexit offers NO escape

8

Page 9: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR BAR ISVERY HIGH

Consider

intent & principles

behind GDPR

“Where is my data?”

Most company execs would struggle toanswer (unlike “Where is my money?” )

9

Page 10: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR BAR ISVERY HIGH

GDPR compliance journey requires -• Commercial awareness• People management• Strategic planning• Effective implementation

GDPR compliance –a journey with no destination…

10

Page 11: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DATA FLOWS

Then - hierarchy Now - network

11

Page 12: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DATA FLOWS –‘OLD’ VS. ‘NEW’

Data – then• held by few• command/ direct

• stays within thefirm

• staff ‘have to’ &are held toaccount

Data – now• used by many• share/ co-work

• can go beyond thefirm

• people engagewhen they ‘want to’

12

Page 13: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DATA

How we

usually think

of data –

• safely stored

• secure

• organised

13

Page 14: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DATA

But information

with personal

identifiers

is ‘data’

for GDPR

14

Page 15: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DATAYour firm needs to know –

• WHAT data do you hold?• WHERE did it come from• HOW is it held?• WHO is it shared with?

GDPR compliance –a journey with no destination…

15

Page 16: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR KEY FEATURES

CONSENT

ACCOUNTABILITY

EVIDENCE

GOVERNANCE

COMMUNICATIONS

TRANSPARENCY

16

Page 17: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

CONSENTHow does your firm

seek, record & manage consent?• Freely given ?• Specific ?• Informed ?• Unambiguous ?

GDPR compliance –a journey with no destination…

17

Page 18: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

CONSENT

THINK:

from whose

point of view?

from whose

perspective?

18

Page 19: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAMETrue or False?

OK to include

consent in

Terms &

Conditions?

19

Page 20: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

False

Giving consentneeds to beexplicitIt can’t be buried inTerms &Conditions

20

Page 21: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

True or False?

data gathered

for 1 purpose

in 1 part of thebusiness

can be used by

another part of thebusiness?

21

Page 22: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

False

data gathered

for 1 purpose

cannot be used foranother purposeor

by another part ofthe business

22

Page 23: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

True or False?

OK to have a

pre- ticked

tick box

to signify

consent?

23

Page 24: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

False

Consent needs tobe explicit &freely given

Pre- ticked

Boxes to signify

consent are

unacceptable

24

Page 25: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

True or False?

If existingconsents meet

GDPR standard,

no need to obtain

fresh consent?

25

Page 26: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

True

If your existingconsents meet

GDPR standard,

there is no needto obtain freshconsent

26

Page 27: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

True or False?Customer

getting your

marketing emailsfor years has

NOTunsubscribed

despitereminders?

27

Page 28: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR GAME

False

Not unsubcribing

to your

marketing emailsdoes NOT signify

consent

28

Page 29: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

DATA PROTECTION –OTHER ISSUESEthos/ style of the leader – supports GDPR

Culture – openness, learning, admitmistakes

Trust – source, authenticity

Resources – physical/ financial, social,intellectual , psychological, spiritual

29

Page 30: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

CHECKRESOURCESPhysical/ financial – adequate?

Social – team energy behind GDPR?

Intellectual – reasoning, thinking through

Psychological – feeling safe, can criticize,admit mistakes (key to high-performingteams, per Google)

Spiritual – higher purpose; want to dowhat’s right

30

Page 31: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

APPLE – “think different”

FACEBOOK – “move fast & break things”

think of a GDPR motto

which will work in YOUR firm

MOTTOS & MANTRAS

31

Page 32: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

Discussion/ social connectionworks

14 x betterthan

- reading about it- following best practice guides- using toolkits

~ NickMilton.com/2014/10/why-knowledge-transfer-through.html

BEST WAY TO SPREADNEW KNOWLEDGE?

32

Page 33: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

GDPR COMPLIANCE

33

Page 34: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

34

REVIEWBUDGET

DECIDE

documentation

network

IT

evidence

negotiate

AUTHORISE

governance

data audit

PERSONNEL

compliance

COMMUNICATE

IMPACT !

governance

GDPR ACTIVITIES(red & blue itemsrarely mentioned)

plan

MONITOR

lead change

communications

motivate

Page 35: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

35

Data mapping

Considerinsurance

Spread awarenessthroughout firm

Re-write policies

Appoint DataProtection Officer &

team

Revise contracts withfirms that process

your data

Renew olddatabases

SUGGESTEDMAIN ACTIONS(usual list has 40+

actions)

Ask customers toreaffirm their consent

Reviewdata

sharing

Simulate breach totest procedures

Create RiskRegister

Page 36: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

too much? can’t cope? … (see next slide)

36

GDPR …

Page 37: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

RED TAPE CONSULTINGHELP

37

Page 38: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

RED TAPE CONSULTING HELP• Awareness –

seminar, overview• Audit –

fact-find, checklists, gather info• Assessment -

findings, gap analysis, report• Aftercare –

compliance support, monitoring

38

Page 39: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

• A taster in 30 mins ~

Data protection - ‘momentous’ change

What’s changing?

How to ACHIEVE and PROVE compliance?

Want more?

THIS SLIDE DECK IS

39

Page 40: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

Remember -

IMPORTANCE

of

CONSENT !

40

IF YOU REMEMBERONLY ONE THING …

Page 41: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

Remember -

CONSUMERMUSTOPT-INONCONSENT !

41

IF YOU REMEMBERONLY ONE THING …

Page 42: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

42

LET’S TALK ?

Page 43: What you need to · 2018-04-29 · 7. GDPR Applies to any company ... marketing emails for years has NOT unsubscribed despite reminders? 27. GDPR GAME False Not unsubcribing to your

Pat Shroff

pat @RedTapeConsulting.co.uk

+44 (0)7855 351 116

www.RedTapeConsulting.co.uk

43

RED TAPE CONSULTING LTD