INTRO
- One of the most noticeable changes that organisations will see in their day-to-day handling of personal data is the new requirement to provide ‘privacy notices’.
- Where the data controller obtains the personal data directly from the data subject, the data controller will need to provide the notice at the time the personal data is collected, which in most cases will be at the start of the relationship, be it an employment or commercial relationship.
- Where the personal data are not obtained from the data subject, special rules as to the timing of the provision of the specific information apply.
WHAT INFO
- Privacy notices need to set out a range of information, including (but not limited to)
- the purposes and bases for the processing,
- details on transfers outside the jurisdiction, and
- certain details about the data protection officer (if any) and data controller as applicable.
- Other information to be provided include
- the right to make complaints,
- the ability to withdraw consents provided, and
- information about how long the data is to be stored or the criteria to determine storage periods.
- The required content for the notices is likely to vary slightly across jurisdictions so organisations will need to ensure that they consider all relevant legislation.
EXISTING INFO
- Given that the new legislation will commence in the context of existing employment and commercial relationships, an immediate question is what to do about existing employees, customers and suppliers, etc.
- There is potential to rely on transitional provisions in Jersey (valid to May 2019) where specified information was provided under the existing Data Protection Law.
- However, it would be prudent for controllers to check whether the specified information has been provided and, if not, ensure that existing data subjects are provided with a privacy notice to take effect on or around the implementation of GDPR.
TO DO KEY ACTIONS
- Prepare a privacy notice that complies with the GDPR requirements, considering the purpose and basis for processing personal data in your organisation. Ensure the notice is tailored for particular groups of recipients as appropriate, depending on how the data is to be used.
- Determine the method by which the privacy notice will be brought to the attention of relevant data subjects and consider how existing individuals should receive the notice on commencement of GDPR.
- Check the respective requirements for privacy notices in your applicable jurisdiction(s) and tailor the notice accordingly.