{"id":2682,"date":"2018-08-02T10:04:49","date_gmt":"2018-08-01T22:04:49","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=2682"},"modified":"2018-08-02T10:04:49","modified_gmt":"2018-08-01T22:04:49","slug":"were-going-to-be-hearing-about-data-privacy-for-a-lot-longer-yet","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=2682","title":{"rendered":"We&#8217;re going to be hearing about data privacy for a lot longer yet!"},"content":{"rendered":"<p>I don&#8217;t know about you, but every day I open emails and articles about data security and our obligations in business. \u00a0 It&#8217;s feeling a little overwhelming, but on closer inspection, most of the conversation is pretty sensible.<\/p>\n<p>The headlines have been\u00a0 the data breach legislation in Australia and the GDPR in the European Union.\u00a0 That resulted in a swath of updates to business terms and conditions, and its something we will all have to think about as well.\u00a0 It&#8217;s not an IT issue, it is a business issue.\u00a0 I can&#8217;t think of any businesses that don&#8217;t hold some personal data about people that needs to be respected.\u00a0 At the least it would be names and phone numbers of staff, suppliers and frequent customers.\u00a0 Many businesses have more, subject to what they do.<\/p>\n<p>We all have a responsibility to manage this respectfully. While most of us do, there will be a few businesses that are dismissive of their obligations.\u00a0 That could be very expensive!\u00a0Under GDPR, in the EU, business can&#8217;t afford to be dismissive.\u00a0 The penalties are horrendous : up to $20,000,000 euros or 4% of global turnover.<\/p>\n<p><span style=\"display: inline !important; float: none; background-color: transparent; color: #333333; cursor: text; font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;\">[header2 text=&#8221;So, what do you do?&#8221; align=&#8221;left&#8221; color=&#8221;#336A40&#8243; margintop=&#8221;&#8221;]<\/span><\/p>\n<p><strong>1. Audit<\/strong> &#8211; Check : do you what personal information do you hold, and why?\u00a0 This can range anywhere from names and addresses to financial and medical records. If you hold information you don&#8217;t need, then stop keeping it!<\/p>\n<p><strong>2. Permission<\/strong> &#8211; do you have permission to hold it?\u00a0 If you need to hold data to undertake a service for the client, make sure you have their permission and make sure you only use it for the stated purpose. \u00a0 The individual has the right to ask to see the data you hold about them and to correct it.<\/p>\n<p><strong>3. Right to be forgotten<\/strong> &#8211; this is difficult.\u00a0 It reflects the idea that once you no longer need someone&#8217;s data, as the purpose that you gathered it for no longer requires it, then the person can ask you to &#8216;forget&#8217; them.\u00a0 Essentially, they revoke their consent for you to hold their information. \u00a0 You are obliged to erase this as soon as possible!\u00a0 If you need their data for your own compliance &#8211; tax records being a good example &#8211; then you can anonymise it.\u00a0 In theory this extends to deleting their data from your backups as well, but we know of no practical means to do this.<\/p>\n<p><strong>4. In the event of a breach<\/strong> &#8211; you have to notify the authorities and affected parties &#8216;without delay&#8217;.\u00a0 Unfortunately, despite our combined best efforts, this is probably more a question of when not if. To help make that less likely Kinetics is currently introducing a new enhanced security service.<\/p>\n<p>This is intended to be an ongoing compliance obligation &#8211; like ISO9000 was and health and safety is.\u00a0 In fact that&#8217;s a great comparison. Just as we need to keep people physically safe, we also need to keep their data safe &#8211; these are intertwined ideas.<\/p>\n<p>By and large, this seems sensible and much of it has been law in NZ since the Privacy Act 1993. \u00a0 There is a bill currently before parliament that updates this. It proposes adding mandatory data breach notifications and strengthening the power of the Privacy Commissioner.\u00a0 The objectives and principles seem sensible, and it is a handy reminder of our collective responsibility.<\/p>\n<p>[header2 text=&#8221;How can we help you comply?&#8221; align=&#8221;left&#8221; color=&#8221;#336A40&#8243; margintop=&#8221;&#8221;]<\/p>\n<p>The <a href=\"http:\/\/kinetics.co.nz\/flightplan\/\" target=\"_blank\" rel=\"noopener\">[wow_colorme]Kinetics &#8220;FlightPlan&#8221; toolkit<\/a><a href=\"http:\/\/kinetics.co.nz\/were-going-to-be-hearing-about-data-privacy-for-a-lot-longer-yet\/\" target=\"_blank\" rel=\"noopener\">[\/wow_colorme]<\/a> has been updated to add a data privacy section that works through these items with you.\u00a0 Call your account manager or <a href=\"http:\/\/kinetics.co.nz\/contactus\/\">get in contact<\/a> to make an appointment<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I don&#8217;t know about you, but every day I open emails and articles about data security and our obligations in business. \u00a0 It&#8217;s feeling a little overwhelming, but on closer inspection, most of the conversation is pretty sensible. The headlines have been\u00a0 the data breach legislation in Australia and the GDPR in the European Union.\u00a0 [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":2689,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-2682","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/2682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2682"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/2682\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}