Introducing 

Prezi AI.

Your new presentation assistant.

Refine, enhance, and tailor your content, source relevant images, and edit visuals quicker than ever before.

Loading…
Transcript

RGPD

European Regulation

Regulation (UE) 2016/679 of the European Parliament and the Council of April, 2016: GENERAL DATA PROTECTION

  • Direct application from May 25,2018

  • Changes of nomenclature:
  • affected -> interested
  • high level data -> special category data

  • The tacit consent no longer exists

  • The rights of the interested parties are extended (right to be forgotten, portability...)

To what applien ?

What are personal data?

Any information about an identified or identificable individual (the interested part).

Numeric, alphabetical, graphic, photographic, acoustic or any other information, including the development of profiles.

What does your treatment involve?

Any operation carried out on these personal data.

Types of operations: collection, registration, organization, structuring, conservation, adaptation, modification, extraction, consultation, use, communication by transmission, dissemination, limitation, deletion or destruction.

Who is responsible for the treatment?

Individual or legal entity that determines the purposes and means of treatment.

Rights

RIGHTS OF INTERESTED PERSONS

Right to the informatiom: at the time of collecting the data of the interested part, it will be necessary to inform.

Access right: Right to obtain confirmation of whether or not your personal data are being processed and, in such case, obtain the right of access to information about the data in the tratment and obtain a copy.

Right to rectify: Modify the data without delay.

Right of suppression (right to be forgotten): right to suppress the data of the files without undue delay (if legally this is possible).

Right to data portability: right to receive a structured treatment file to be able to take it to another data controller. Right that is made directly.

Right of limitation or right of opposition: Right to limit the treatment when the data are inaccurate, unlawful, or that the responsible does not need.

Principles

PRINCIPLES OF DATA PROTECTION

  • Lawfunless, loyalty and transparency.
  • Minimization of data.
  • Accuracy.
  • Limitation of the conservation period.
  • Integrity and confidentiality..

To the Treatment Manager must be able to demonstrate that it complies with the previous points (proactive responsability)

Type of data

TREATMENT OF SPECIAL CATEGORIES OF PERSONAL DATA

Personal data of special category are considered:

• Ethnic or racial origin

• Political opinions

• Religious or philosophical convictions.

• Union affiliation

• Genetic or biometric data to identify a person.

• Health data

• Data related to sexual life or sexual orientation.

Consent

SPECIFIC ENABLING

The treatment will only be legal if it meets at least ONE of the following conditions:

• The interested party has given his consent for the treatment/treatments (all):

- Free

- Specific

- Informed

- Inequivocal

• It is necessary for the execution of a contract or pre-contract in which the interested part is a part.

• It is necessary for compliance with a legal obligation applicable to the person Responsible for processing.

Responsible for the treatment

What should the person responsible do ?

  • Guarantee and be able to demonstrate that it complies at all times with the Regulation.

  • Apply technical and organizational measures taking into accountthe nature, scope, context, purpose of the treatment, risks of varying probability and severity.

These measures will be reviewed and updated as necessary.

Breach notification

NOTIFICATION OF SECURITY VIOLATIONS

  • Detection of the incident and communicate it to the person in charge within the company.

  • Study of the scope of the risk that implies for the interested persons.

  • Communication to the control authority (Spanish Data Protection Agency) with a maximum of 72 hours.

Practical issues

ISSUES TO BE TAKEN INTO ACCOUNT

  • Personal data is always the owner's..

  • Always respect the duty of condfidentiality of the data.

  • Avoid recording of photographs of colleagues, customers or suppliers without their authorization.

  • The data must be used only for the purpose for which they were collected.

  • Avoid data leakage or access to illegitimate third parties and in case of prompt notification.

  • Do not throw documents with personal data into the trash. Use the paper shredder.

Documentation to sign today

  • Assistance to the training session and information of the protocols to G&You.
  • New update of personal data information.

Responsible for Girbau Data Protection:

CRISTINA BOVER

Email: dataprotection@girbau.com

Learn more about creating dynamic, engaging presentations with Prezi