De impact van de GDPR op de reissector

23
Sirius Legal The Conference 1 December 2016

Transcript of De impact van de GDPR op de reissector

Page 1: De impact van de GDPR op de reissector

Sirius LegalThe Conference 1 December 2016

Page 2: De impact van de GDPR op de reissector

Travel 360 The Conference1 December 2016

Page 3: De impact van de GDPR op de reissector

New “Privacy Law” coming your way…

General Data Protection Regulation 2016/679 (GDPR/AVGB)Regulation instead of Directive – 1 law for 28 statesAgreement reached last December 2015

Enters into force on 1 May 2018 (without grace period!)

New rules are MUCH stricter than current law and impact EVERYONE present here today

Travel 360 The Conference1 December 2016

Page 4: De impact van de GDPR op de reissector

General Data Protection Regulation

Heavily influenced by consumer protection activists in EPResult:Consumer friendly, but serious restraints for direct marketing, e-commerce and especially personalisation, profiling, real time marketing and big data

Applicable on ALL data processing, except personal (private) contact lists (e.g. private Outlook account)

Travel 360 The Conference1 December 2016

Page 5: De impact van de GDPR op de reissector

Don’t be this guy, be prepared…

All e-commerce and online marketing run on personal data

This is no different in today’s digital travel industry

GDPR applies to ALL databases (clients, marketing, sales, HR, purchasing, accounting, …)

In the words of the European Commission: “data has become a currency” (cfr. Draft Directive 2015/0287 on digital content delivery contracts)

Fines up to 4% of annual turnover or 20 mio euro

Travel 360 The Conference1 December 2016

Page 6: De impact van de GDPR op de reissector

Security & internal processes

1. Working with subcontractors that process data

Obligation to work only with subcontractors that guarantee sufficient data securityObligation to have written contracts wth all subcontractorsList of mandatory clauses in such contracts

Booking engine, TO/agency, external marketeer, …

= Need to audit/map all existing subcontracting/service contracts

Travel 360 The Conference1 December 2016

Page 7: De impact van de GDPR op de reissector

Security & internal processes

2. Record of processing activities

Obligation to maintain a “record of processing activities”Holding ID of processor, processed data, categories, transfers, time limits, security measures In writing at the seat of your company

Bookings, mailings, transfers to third parties, opt-outs, …

Travel 360 The Conference1 December 2016

Page 8: De impact van de GDPR op de reissector

Security & internal processes

3. Data security measures

“Processor shall implement appropriate technical and organizational measures, to ensure an appropriate level of security”Pseudonymisation where possible, confidentiality, security, back ups in place, security testing protocols, …

= Need to audit/map data within company

Travel 360 The Conference1 December 2016

Page 9: De impact van de GDPR op de reissector

Security & internal processes

4. Data Protection Impact Assessment

If possible high impact on data subject privacy rightsObligation to run prior (documented) impact assessmentAdvice of DPO required if DPO is present in the organizationShould be used as basis to ensure adequate security levelsPrivacy Commission to specify when DPIA is requiredIf DPIA shows high risk: obtain Prior Assessment from Privacy Commission

Travel 360 The Conference1 December 2016

Page 10: De impact van de GDPR op de reissector

Security & internal processes

5. Data breach notification

Obligation to notify any data security breach to the Privacy CommissionAsap or at least within 72 hoursNature of breach, possible consequences, measures taken, etc… (= obligation to document data breach)= Need to have data breach procedure in place

If possible consequences for data subjects: obligation to notify them in person!

Travel 360 The Conference1 December 2016

Page 11: De impact van de GDPR op de reissector

Security & internal processes

5. Data Protection Officer

If core activity of processorRequires large scale data monitoringConsists of large scale data monitoring

Series of requirements and conditionsDetails to be specified

Inform & advise, monitor compliance, SPOC for authorities

Travel 360 The Conference1 December 2016

Page 12: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

1. Lawfulness of processing (“on which grounds can I proces data?”) (art. 6 GDPR)

Prior opt-in remains the basic rule (+ proof required)“Processing is required for the execution of a contract”“Legitimate grounds”DM “may be considered” legitimate, but “Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means”If existing client relationship: OK, otherwise not so evidently OK

Travel 360 The Conference1 December 2016

Page 13: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

2. Processing of data belonging to minor (-13 Y/O, -16 Y/O) (art. 8 GDPR)

Always requires explicit authorisation by parents!

“Reasonable efforts” to check age and obtain authorisation

eID?, Facebook login?, credit card data?, live chat, …?

Travel 360 The Conference1 December 2016

Page 14: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

3. Information obligations

Obligation to notify data subject of the fact that his data is being / has been collected (or transferred) without his explicit consent (art. 14 GDPR)

Within 30 days or upon first contact

= Data obtained from booking tools, travel agency, affiliate, data brokers, partner organisations, online collection…

Travel 360 The Conference1 December 2016

Page 15: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

3. Information obligations (art. 14 GDPR)

Obligation falls if

Data subject already knows (= online booking engine or affiliate, travel agency, …)orInformation provision requires disproportionate effort (= open door to creativity…)

Travel 360 The Conference1 December 2016

Page 16: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

4. Right not to be submitted to profiling (art. 21 GDPR)

If the person has a legitimate interest to do so, he has a right to object against processing/profiling

Objection against processing/profiling for direct marketing purposes is always possible

Remarketing, trigger based marketing, …

Travel 360 The Conference1 December 2016

Page 17: De impact van de GDPR op de reissector

Information obligations & rights of data subjects5. Right to object to automatic decision taking (art. 22 GDPR)

RightNot to be subject to a decision Producing legal effects / significantly affects Solely based on automated processing of dataIntended to evaluate certain personal aspects

ExamplesCreditworthiness, reliability and conductAlso applies to DM “decisions” (e.g. send offer or not)

Travel 360 The Conference1 December 2016

Page 18: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

6. Right to be forgotten (art. 17)

Upon request by data subject, processor has to take all reasonable measures to permantently delete data

+ to ensure that third parties that have copies of or links to data are warned of the request and are asked to do the same

Travel 360 The Conference1 December 2016

Page 19: De impact van de GDPR op de reissector

Information obligations & rights of data subjects

7. “Pseudonymous data”

8. “Privacy by design”

9. “privacy by default” (cfr. recent Telenet “personalized advertising…”)

10. …

Travel 360 The Conference1 December 2016

Page 20: De impact van de GDPR op de reissector

Helping handCode of Conduct

= “ethical code” of associationsContain rules on how to handle data for their membersCan be approved by authoritiesAssociation has to provide control/supervision

Advantage: once approved can create presumption of compliance with series of obligations for association members

ABTO / VVR / …?

Travel 360 The Conference1 December 2016

Page 21: De impact van de GDPR op de reissector

Be prepared…

Follow up on discussion (e.g. through our website www.siriuslegal.be)Start audit om data use within your organisationStart review vendor contracts (in view of data security obligation) Start to prepare for full update of policies, contracts, business processesPut in place data breach notification procedureAppoint (temporary) data security officerPut in place impact assessment and/or risk analyses policyCreate compliance statements for annual business reportsTrain staffSit back and wait for final text of regulation for final details…

Travel 360 The Conference1 December 2016

Page 22: De impact van de GDPR op de reissector

Be prepared…

Those who are not prepared face trouble…

Provisions of highest importance (cfr. profiling = high risk processing)Fines up to 20 million euroFines up to 4% of worldwide annual turnover (for undertakings)

Reform of Privacy Commission will lead to actual enforcement…

+ Remedies for data subject

Travel 360 The Conference1 December 2016

Page 23: De impact van de GDPR op de reissector

Sirius LegalMedia & advertisement lawIP lawInternet & e-commercePrivacy & cookiesGambling lawTravel & consumer protectionCommercial & contractsCorporate - tax - labour - immo

[email protected]@BartVdBrandeLinkedin.com/in/bartvdb