The Era of GDPR Data Privacy, Two Months In: Do you have a Data Transfer Agreement handy? July 31, 2018

Similar documents
Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty. Overview of the EU General Data Protection Regulation (GDPR)

The GDPR how to prepare MiFID II where are we now? Wednesday 21 February 2018

Cover option 2. The Interplay of HIPAA, Privacy and Data Security Principles, and Health Information Interoperability. Subtitle or Company Name

EU General Data Protection Regulation vs. Swiss Data Protection Act (in the Private Sector 1 )

Guidance: The new EU General Data Protection Regulation: Implications for Australia

States of Guernsey EU General Data Protection Regulation (GDPR) - High-level impact assessment

DATA SUBJECT ACCESS REQUEST POLICY AND PROCEDURE

Aegon Asset Management Europe ICAV ( the Fund ) Data Protection Policy

International data transfers and Schrems White & Case. Aqeel Kadri and Tim Hickman

All Sorts UK Limited Data Protection Policy 17 th May 2018

DATA PROCESSING ADDENDUM

Data Processing Addendum

DATA PROTECTION LAWS OF THE WORLD. Czech Republic

Processing under the GDPR: risk and liability shifts

The New EU General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR): action plan for pension scheme trustees

General Data Protection Regulations Briefing (the presentation you ve all been waiting for)

Member Circular March Implementation of the EU General Data Protection Regulation 2016/679 General Guidance to Members

CHARITY & NFP LAW BULLETIN NO. 419

Pension Trustees. Final Countdown to the GDPR

GDPR FOR PRIVATE EQUITY AND REAL ESTATE

Building a Program to Manage the Vendor Management Lifecycle

European Union General Data Protection Regulation

Pension Trustees Final Countdown To GDPR

Data protection legislation back to the drawing board?

Amgen Binding Corporate Rules (BCRs) Public Document

The GDPR Possible Impact on the Life Sciences and Healthcare Sectors

Banks Sheridan Limited Data Protection Privacy Policy 19 May 2018

Your Right Hand Finance Ltd (YRH) Subject Request Policy

The contract is important so that both parties understand their responsibilities and liabilities.

What does GDPR and the new Data Protection Act mean to Brokers/Intermediaries?

Data Processing Appendix

WHAT DOES THE GDPR MEAN FOR PENSIONS? HANDY GUIDE

LAMP Services Limited Privacy Notice v1.2 4 th March Controller

BINDING CORPORATE RULES

The Pension and Life Assurance Plan of NG Bailey (Scheme) Privacy notice

The EU-US Privacy Shield: A How-To Guide

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software

Personal Data. Protection Policy

Data Processing Addendum

Data Processing Addendum

ON24 DATA PROCESSING ADDENDUM

Brexit Essentials: an update on data protection and privacy

Data Processing Addendum

RBI GDPR DATA PROCESSING ADDENDUM

EU Data Processing Addendum

Data Protection Post-Brexit

GDPR: The future of marketing and commercialisation of data. Alexander Brown & Matt Dyer, Simmons & Simmons

DATA PROCESSING ADDENDUM

ARE YOU READY FOR THE NEW DATA PROTECTION LAWS?

Man and Machine - Data Protection Policy

DATA PROTECTION LAWS OF THE WORLD. Angola vs Czech Republic

Data Protection & Brexit

GDPR Essentials. To Meet the May 25th Deadline. FIA Webinar March 1, 2018

PREPARING FOR THE EU GDPR IN RESEARCH SETTINGS

Revising policies and procedures under the new EU GDPR

Impact of the European General Data Protection Regulation on U.S. M&A

General Data Protection Regulation (GDPR) Data Protection Notice

Data Privacy Group Client Alert: The UK Votes for Brexit Data Protection Implications

Data Protection Notice pursuant to the General Data Protection Regulation (GDPR)

DATA PROCESSING AGREEMENT

Institutional Investment Advisors Limited

2. TASK OF DPO IN INTERNATIONAL DATA TRANSFERS

The General Data Protection Regulation s Impact on M&A

PRIVACY NOTICE issued by DALE Accounting and Tax Services Ltd

WHAT DOES THE GDPR MEAN FOR PENSIONS?

General Data Protection Regulation (GDPR)

Hillgate Travel GDPR Response. Privacy Policy

Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST. Featured Speakers. Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M.

Moxtra, Inc. DATA PROCESSING ADDENDUM

British Bankers Association submission to the consultation on the legal framework for the fundamental right to protection of personal data

2018 Australian privacy outlook

DATA PROCESSING ADDENDUM (v1.0)

DATA PROCESSING ADDENDUM

DATA PROCESSING ADENDUM

Creating a Big Data Strategy: Managing Risk and Enabling Innovation

Information on the Collection and Processing of your personal data

New legislation brings changes to how data is handled

DATA PROCESSING ANNEX

Alert Franchise & Distribution/ Cybersecurity, Privacy & Crisis Management

The General Data Protection Regulation (GDPR) Personal data in SOS International

GDPR update and its impact on accountancy practices

DATA PROCESSING ADDENDUM

Capital Dynamics Privacy Policy

THE IMPORTANCE AND STATUS OF THE GENERAL DATA PROTECTION REGULATION (GDPR)

CNPD Course: Data Protection Basics

The BVRLA Guide to. The General Data Protection Regulation British Vehicle Rental and Leasing Association

HOW TO EXECUTE THIS DPA:

GDPR Data Processing Addendum

Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018)

A guide for the insurance industry

WHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA?

EU PRIVACY REFORM UPDATE ON CANADA S EU ADEQUACY STATUS

PRIVACY NOTICE Use of Information Data Controller and Data Processor

IRIS Group of Companies Customer Data Processing Terms

BREXIT AND DATA PROTECTION Q & A

ASTRAZENECA GLOBAL POLICY DATA PRIVACY

URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses. (Revised September 2017)

PERSONAL DATA PROCESSOR AGREEMENT

Management of Personal Information Policy (Privacy Policy)

Transcription:

The Era of GDPR Data Privacy, Two Months In: Do you have a Data Transfer Agreement handy? July 31, 2018

Upcoming Events: Sign up on our web site Associate Safety Professional (ASP) Examination Preparation, August 28th Luke Timmerman: Recap of Mount Everest Summit to Support Oncology Research, September 4 th -- Early Evening Reception State and Federal Governments Response to High Priced Therapies in Medicaid, September 12th Implementing Equal Pay for Women in Your Organization, September 25th Creating Powerful Brands from Preclinical -> Commercialization Through Omnichannel Marketing Part 1 of 4, September 19th Phase I Clinical Trial Experience in Australia, October 9th

Luke Timmerman: Recap of Mount Everest Summit to Support Oncology Research, September 4 th -- Early Evening Reception

Thanks to our Legal Forum Working Group! Legal Co-Chairs: Lana Gladstein, Vice President and General Counsel, Brammer Bio Konstantin Linnik, PhD, JD, Partner, Nutter McClennen & Fish LLP John Harre, Founder, L.G.L Consulting

Speakers: The Era of GDPR Data Privacy, Two Months In: Do you have a Data Transfer Agreement handy? Naomi Leach Senior Associate, Data Protection, Stephenson Harwood Colin J. Zick is a partner with the Boston-based law firm, Foley Hoag LLP, where he serves as Chair of its Privacy and Data Security practice group. Moderator: John Harre, Founder, L.G.L. Consulting

Key GDPR considerations MassBio 31 July 2018 Naomi Leach Senior Associate, Life Science Transactions

Context How the GDPR came to be EU Data Protection Directive 95/46/EC Implemented in the UK by Data Protection Act 1998 (affects all organisations which process personal data in the UK as a data controller) Variations in implementation across EU General Data Protection Regulation 2016/679 came into direct effect on 25 May 2018

Key Terms in GDPR Personal Data Sensitive personal data / Special Categories Controller Processing Processor Data Subject

Key areas of change in GDPR from the previous laws Increased fines (up to greater of 4% of worldwide turnover or 20m Euro) Legal Grounds and Fair notice provisions tightened Direct obligations for data processors Accountability principle and DPOs Data breach notification and other rights of data subjects

The GDPR has greater Extra-territorial effect than the Directive Existing DP Directive only applies to non-eu entities if use a means of processing (e.g. equipment or processors) in the EU Regulation applies to entities based outside the EU if it: Extraterritoriality (i) or (i) Offers goods or services to EU residents Monitors the behaviour of EU residents Obligation to appoint a Representative in an EU member state and all the provisions of the Regulation apply Potential de minimus exemption for occasional/ small scale processing

Transferring data outside the EEA under GDPR Same restrictions apply as under the Directive and largely the same existing toolkit for compliance BUT Adequacy decisions subject to periodic review (query status of Channel islands pending reform of law adequacy grandfathered in short term) BCRs specifically referenced for first time (including BCRs for processors) October 2017 Irish courts refer standard contractual clauses to CJEU to opine on adequacy Privacy Shield became effective 1 August 2016 - may be challenged also

Lawful grounds for processing personal data GDPR does not change lawful grounds materially BUT increases burden on controllers to demonstrate it has satisfied lawful grounds Also greater right to challenge (e.g. when using legitimate interests) AND emphasis on transparency greatly increases detail to be included in privacy notices (e.g. websites/ Ts&Cs)

Using consent as your lawful ground Consent just one lawful ground for processing Must be specific, freely given & capable of being withdrawn Imbalance in bargaining power can mean invalid

Consent in the context of Clinical Trials Challenges Withdrawal of consent Specificity of consent Alternative Legal Grounds Comply with a legal obligation Legitimate interest In the public interest Necessary for Scientific Research Purposes Consent under Clinical Trials Regulation Still applicable and must be considered separately to GDPR requirements

New direct obligations for processors under GDPR Same (if enhanced) requirements apply to controllers Same requirements as to guarantees and contracts in writing (but with added detail as to content of contract) BUT certain provisions also apply directly to processors, e.g.: Record keeping requirements (Article 30(2)) Cooperation with regulators (Article 31) Security measures (Article 32) Notification of breach (to controller) (Article 33) International Transfers (Article 40-42)

Contracts with Processors (Article 28) Review for compliance with Article 28 update to include extra information including: Details of processing (e.g. subject matter, nature of data, duration) Security measures Audit rights No sub-processing without specific or general authorisation - Whose responsibility? Controller or processor?

Accountability General Principle of accountability runs through GDPR (Article 5(2)) Manifests itself as (eg): Express requirement on controller to demonstrate compliance with principles Requirements to keep record of processing Designation of data protection officers (in some instances) Data Protection by design and default Where relying on consent, evidence of such consent Failure to demonstrate compliance is itself a breach

Data Breach Data Breaches to be notified to regulator within 72 hrs after a controller is aware Where high-risk, data subjects may also need to be informed Consider interplay between processor and controller awareness

Data Subject Rights Right to object Right to be forgotten Wider scope/grounds to object (burden of proof on controller) Right to require erasure of data where no legal basis remaining

Data Subjects Rights Subject Access Requests Right of portability Same principles but time period reduced to 1 month Right to obtain a copy of data in an electronic and structured format which is commonly used requests which are manifestly unfounded or excessive can be charged for or refused Right to require transmission from one controller to another

Checklist to assist with GDPR compliance Audit What personal data is collected and where? Why is it held/used? With whom is it shared? Review lawful grounds for processing Consent? Legitimate interests? Necessary for contract? Review terms and notices What purposes are notified? What changes need to be made?

Checklist to assist with GDPR compliance Policies Review procedures for reporting breaches and contracts with key suppliers Consider updates to data retention, deletion and other policies (e.g. Subject Access) Contracts Review and amend contracts with processors Consider arrangements for data transfers overseas (model clause agreements?)

Key concerns for companies when acting as controllers or processors under the GDPR Accountability Prove compliance (Article 5) Obligation to carry out privacy impact assessments (Article 35) Liability ICO fines (max 4% turnover, or Euros 20 million) for both controllers and processors A triple threat of liability for processors Regulator fines plus claims from data subjects (including joint liability with controller) plus contractual claims from controller Breach notification Security requirements Controller must notify regulators within 72 hours, where feasible, (Article 33) and data subjects without undue delay (Article 34) Processor must notify the controller of any breach without undue delay (Article 33) Go beyond mere encryption and include the integrity of systems, back-ups and regular penetration testing (Article 32) Contracting ARTICLE 28 prescriptive about content of contracts No subprocessing without consent of controller (Art 28(2)) Subject matter clearly set out Audit rights permitted.

Contact Naomi Leach Senior Associate T: +44 20780922960 M: +44 7769 143 367 E: naomi.leach@shlegal.com

Thank you for attending!