Top Banner
/ Legal minds GDPR and webshops Safeshops e-legal day 10 March 2017
27

GDPR and Webshops

Apr 06, 2017

Download

Law

SafeShops.be
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: GDPR and Webshops

/

Legal mindsFirm results

GDPR and webshopsSafeshops e-legal day10 March 2017

Page 2: GDPR and Webshops

/

DENIAL IGNORANCERECKLESSNESS

2

Page 3: GDPR and Webshops

/

Myth #1Nobody cares about data protection.

3

Page 4: GDPR and Webshops

/

HTTP://EC.EUROPA.EU/JUSTICE/DATA-PROTECTION/FILES/DATA-PROTECTION-BIG-DATA_FACTSHEET_WEB_EN.PDF 4

Page 5: GDPR and Webshops

/

5

Page 6: GDPR and Webshops

/

6

4% total annual worldwide turnover

Page 7: GDPR and Webshops

/

Myth #2I am not processing personal data.

7

Page 8: GDPR and Webshops

/

8

Personaldata

Anonymousdata

• any information, • directly or indirectly,• relating to, • an identified or

identifiable, • natural person

• non-personal data

Pseudo-nomyzeddata

• personal data that can no longer be attributed

• without the use of additional information,

• that is kept separately, • subject to technical and

organisational measures

Page 9: GDPR and Webshops

/Myth #3I outsourced so data protection concerns are not mine

9

Page 10: GDPR and Webshops

/

10

ACTORS

Controller Processor Sub-processor

Sub-subprocessor Datasubject

Page 11: GDPR and Webshops

/

Myth #4I have consent so I am content.

11

Page 12: GDPR and Webshops

/

Ceci n’est pas un consentement .

12

Page 13: GDPR and Webshops

/

13

Processingshallbe

lawfulonlyifandtotheextent…

Consent

Performanceofa

contract

Pre-contractual

steps

Legalobligation

Protectionofvitalinterests

Publicinterest/official

authority

Legitimateinterests

PROCESSING GROUNDS NORMAL PERSONAL DATA

Page 14: GDPR and Webshops

/

Myth #5 Once I have an opt-in, I can do what I want

14

Page 15: GDPR and Webshops

/

15

Page 16: GDPR and Webshops

/Myth #6We’ll ask our lawyers to draft some opaque privacy policy

16

Page 17: GDPR and Webshops

/NEW OBLIGATIONS

• Extended data subject rights• Records keeping obligation• Data protection impact assessment• Data protection by design• Data protection by default• Demonstrate compliance

DocumentationProceduresPolicies etc.

17

Page 18: GDPR and Webshops

/

18

Page 19: GDPR and Webshops

/Myth #7We all have to appoint a data protection officer (DPO)

19

Page 20: GDPR and Webshops

/DPO

• Public authorities• Core activities

Require large scale monitoring = large scale processing of sensitive data

• Belgian or EU law

20

Page 21: GDPR and Webshops

/Myth #8We all have to conduct a data protection impact assessment (DPIA)

21

Page 22: GDPR and Webshops

/

22

Likely to result inahighriskfor natural persons

Evaluationofpersonalaspects

basedonautomatedprocessing,

includingprofiling,withlegalorsimilareffects

Largescaleprocessingofsensitive orcriminal data

Monitoringpubliclyavailable places on

alargescale

Page 23: GDPR and Webshops

/Myth #9Data breach notification duty only applies in the event of hacking

23

Page 24: GDPR and Webshops

/

24

Page 25: GDPR and Webshops

/

Myth #10May 2018? I still have plenty of time!

25

Page 26: GDPR and Webshops

/

26

Page 27: GDPR and Webshops

/CONTACT

27

Gerrit [email protected]

Tour&Taxis BuildingAvenue du Port 86C, B4141000 Brusselswww.altius.com