What You Need to Know About General Data Protection Regulations (GDPR)

What You Need to Know About General Data Protection Regulations (GDPR)

In less than a year, The General Data Protection Regulations (GDPR) will change how businesses handle the digital information of its customers residing in the European Union. The implications will vary by company but all businesses processing EU residents’ personal data will be impacted. It’s best to start putting an action plan in place before the May 2018 deadline approaches.

General Data Protection Regulations

What is GDPR?  The General Data Protection Regulations (GDPR)  will replace (strengthen) the EU Directive 95/46/EC regarding data protection as of May 25, 2018.

It will not matter if your headquarters are in the U.S.; if you or your vendors process EU residents’ personal data, GDPR will apply to your organization.   The updated regulations will impact both controllers and processors of personal data, as both will have responsibilities and legal implications for complying with the new regulations.

One notable impact of the new regulations will be to provide the “end user” who is giving his/her personal data with consent, more ability to opt in or opt out with more granularity.   Event Planners will be adapting their registration portals and databases to accommodate these consent regulations.  Miller Tanner Associates has already started investing resources to ensure we are preparing in advance of the deadline.

A recent article published by MeetingsNet notes:

“And, in case you are wondering, the scope of personal data covered by the GDPR is more than just name and address; it also covers income information, health information, frequent-flyer and frequent-stay account information, birthdays, age, food preference, allergy notifications, cultural and ethnic background information, and more”. Read more.

Here are key highlights provided from www.eugdpr.org :

Increased Territorial Scope (extra-territorial applicability)

Arguably the biggest change to the regulatory landscape of data privacy comes with the extended jurisdiction of the GDPR, as it applies to all companies processing the personal data of data subjects residing in the Union, regardless of the company’s location. Previously, the territorial applicability of the directive was ambiguous and referred to data process ‘in context of an establishment’. This topic has arisen in a number of high-profile court cases. GPDR makes its applicability very clear – it will apply to the processing of personal data by controllers and processors in the EU, regardless of whether the processing takes place in the EU or not. The GDPR will also apply to the processing of personal data of data subjects in the EU by a controller or processor not established in the EU, where the activities relate to offering goods or services to EU citizens (irrespective of whether payment is required) and the monitoring of behavior that takes place within the EU. Non-EU businesses processing the data of EU citizens will also have to appoint a representative in the EU.

Penalties

Under GDPR organizations in breach of GDPR can be fined up to 4% of annual global turnover or €20 Million (whichever is greater). This is the maximum fine that can be imposed for the most serious infringements e.g.not having sufficient customer consent to process data or violating the core of Privacy by Design concepts. There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order (article 28), not notifying the supervising authority and data subject to a breach or not conducting the impact assessment. It is important to note that these rules apply to both controllers and processors — meaning ‘clouds’ will not be exempt from GDPR enforcement.

Consent

The conditions for consent have been strengthened, and companies will no longer be able to use long illegible terms and conditions full of legalese, as the request for consent must be given in an intelligible and easily accessible form, with the purpose of data processing attached to that consent. Consent must be clear and distinguishable from other matters and provided in an intelligible and easily accessible form, using clear and plain language. It must be as easy to withdraw consent as it is to give it.

Breach Notification

Under the GDPR, breach notification will become mandatory in all member states where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Data processors will also be required to notify their customers, the controllers, “without undue delay” after first becoming aware of a data breach.

Right to Access

Part of the expanded rights of data subjects outlined by the GDPR is the right for data subjects to obtain from the data controller confirmation as to whether or not personal data concerning them is being processed, where and for what purpose. Further, the controller shall provide a copy of the personal data, free of charge, in an electronic format. This change is a dramatic shift to data transparency and empowerment of data subjects.

Right to be Forgotten

Also known as Data Erasure, the right to be forgotten entitles the data subject to have the data controller erase his/her personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data. The conditions for erasure, as outlined in article 17, include the data no longer being relevant to original purposes for processing, or a data subject’s withdrawing consent. It should also be noted that this right requires controllers to compare the subjects’ rights to “the public interest in the availability of the data” when considering such requests.

Data Portability

GDPR introduces data portability – the right for a data subject to receive the personal data concerning them, which they have previously provided in a ‘commonly use and machine-readable format‘ and have the right to transmit that data to another controller.

Privacy by Design

Privacy by design as a concept has existed for years now, but it is only just becoming part of a legal requirement with the GDPR. At its core, privacy by design calls for the inclusion of data protection from the onset of the designing of systems, rather than an addition. More specifically – ‘The controller shall…implement appropriate technical and organizational measures…in an effective way… in order to meet the requirements of this Regulation and protect the rights of data subjects. Article 23 calls for controllers to hold and process only the data absolutely necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing.

Data Protection Officers

Currently, controllers are required to notify their data processing activities with local DPAs, which, for multinationals, can be a bureaucratic nightmare with most Member States having different notification requirements. Under GDPR it will not be necessary to submit notifications/registrations to each local DPA of data processing activities, nor will it be a requirement to notify/obtain approval for transfers based on the Model Contract Clauses (MCCs). Instead, there will be internal recordkeeping requirements, as further explained below, and DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. Importantly, the DPO:

  • Must be appointed on the basis of professional qualities and, in particular, expert knowledge on data protection law and practices
  • May be a staff member or an external service provider
  • Contact details must be provided to the relevant DPA
  • Must be provided with appropriate resources to carry out their tasks and maintain their expert knowledge
  • Must report directly to the highest level of management
  • Must not carry out any other tasks that could result in a conflict of interest.

Sources:

3 Ways to Motivate Your Corporate Teams

Looking for new ideas to make an impact, inspire and motivate corporate teams?

Whether you need to rally your sales force, incentivize your teams, or boost productivity among departments, today on the blog, we share 3 impactful ways that your company can motivate its people!

 

Meet MTA: Krisztina Koncz, Global Event Director

Meet MTA Krisztina K

The Miller Tanner difference is our people. That’s why we want to introduce you to our team of superstars that brings our corporate meetings and events to life for our clients.

Today, we introduce you to Krisztina Koncz, Global Event Director. Krisztina is our associate based in Budapest and is fluent in Hungarian, English, Spanish, and Italian. With her charming charisma and adeptness at client-focused service, Krisztina excels in delivering exceptional quality events and customer service to our clients.

Meet Krisztina Koncz

Tell us about your current role with MTA. What are your primary responsibilities?

My current role with MTA is global event director which, in my opinion, is all about providing comprehensive, client-focused service. On a day-to-day basis, I work closely with the client to understand their needs and, behind the scenes, I try to bring together my team in the best possible way, even if we are working virtually.

How long have you been with MTA?

I have been working for MTA for 9 years. I started as an on-site contractor which means I took part only in the event and I was not involved in the pre-meeting process. Following this, I became a full-time global conference planner, which allowed me to learn and develop my knowledge of the whole process of event directing. Two years ago, I was promoted to my current position.

What did you do before joining MTA?

Prior to working for MTA, I worked in tourism as an international tour guide providing high-quality customer service for Spanish, Italian and English speaking tourists. This involved traveling with groups to mainly the United Kingdom and central Europe.Africa preschool

What’s the best part of your job?

I think the best part of being a global event director is two-fold. First, I get a lot of satisfaction from seeing all the team’s hard work in action as an event runs smoothly and in full flow. The second part is the opportunity to travel and learn about new cultures.

What’s been your favorite event destination as an event planning professional?

I would have to say my favorite event destination was Banjul, Gambia because this was my first time in Africa and the event itself gave me a lot of opportunities to learn about myself and develop professionally. This place also allowed me the chance to fulfill one of my lifelong ambitions to visit and help in a local preschool for underprivileged children.

What’s been your most memorable event to date and why?

The most memorable event for me would have to be my trip in 2013 to Seoul, South Korea. The reason for this is because of what happened when I was there. The event itself was very good and successful with a lot of positive feedback from the participants. However, after the event finished my little adventure started. I awoke as usual, had a nice breakfast, got all my stuff together then checked out from the hotel and asked the very kind receptionist to let me know when the airport bus arrives. I took a seat in the lobby and two minutes later with a huge smile on her face she said, “Ms. Koncz, you just missed your bus”. I could not believe it! First of all, why was she smiling? And secondly, why hadn’t she told me? At this precise moment, I realized how important it is to understand different cultures and to be as clear as you can possibly be in all situations. As a result of this, I decided to create a cross-cultural presentation for MTA documenting the nuances of cultural differences which I have presented several times to my colleagues. By the way, culturally speaking, Korean people like to deliver bad news with a smile. 😊

Do you have a few great travel tips that you could share?

Just one quick travel tip that could save you an uncomfortable situation – I would always recommend packing in your hand luggage an extra set of clothes. You never know if your luggage will arrive on time and, as we always need to be professional, this could be your lifesaver.

What do you do for fun?

Most of my spare time nowadays is taken up with my beautiful 21-month-old son, Daniel. When I am not with him, I like to keep fit by going to the gym and if I can, I sometimes play poker.

You are originally from Hungary? What do you enjoy most about living there? Any favorite spots that you would recommend?

I am originally from Hungary and live in a small suburb of Budapest. It is a really beautiful place right next to the Danube river with lots of recreational space. Basically, I would recommend Budapest as a tourist destination because of its unique geographical position and landscape. In addition, it has some of the most beautiful and varied architectural styles in Europe. Also, Hungary is famous for its thermal waters and if you do visit, you can’t miss them!

What makes Miller Tanner stand out as meeting planning company? 

I think MTA offers a unique level of customer service unmatched in the marketplace. We maintain comprehensive details regarding individual client specifications and requirements which allow us to make events fully tailored to our clients.

Some years ago, we were asked the question at our annual workshop:

“Guys, from where do you think customer service derives?”

I think the answer that we were given by the presenter was very good, and I completely agree with it. She said that excellent customer service comes from within. If you are happy and satisfied with yourself, then you can convey this to the outside and it is both natural and genuine which I am sure people can feel. I hope that my current situation in life allows me to provide this high level of honest and authentic customer service.

Anything else you’d like to add?

I would like to finish by saying a big thank you to MTA for allowing me this amazing opportunity to learn, develop and continually improve myself both on a professional and a personal level.

Innovative Solutions for Clinical and Commercial Meetings

innovative solutions clinical-commercial meetings
Dawn Barnes

Miller Tanner is a global event planning and logistics company that is solution-focused and offers options for worldwide events whether for clinical or commercial teams. We continue to evolve to stay on trend with new meeting requirements and technologic developments.

Solution-Focused Services

We aim to be at the forefront of developing services which resolve the challenges corporate teams experience during clinical development and problem-solve in advance the issues that site attendees may face during their required training. We do this to help drive recruitment into the clinical trial to enhance protocol adherence.  For commercial teams, we can deploy our Paperless App to create multiple rotating mock settings to ensure sales pitch uniformity and sales team’s product knowledge retention during a product launch.

Secure Technology and Software Development

We have made significant investments in our internal technology and software development along with heightening our security to cater to growing meeting requirements, especially for future European personal data security and consent.

Proprietary On-Demand Trainer/Learning Management System

To ensure our worldwide events meet the variety of hospitality guidelines and country codes of conduct that is required of the pharmaceutical industry, we have enhanced our proprietary On-Demand Trainer/Learning Management System (ODT/LMS).  This tool allows us to repurpose your live event whether face-to-face, virtual or hybrid to facilitate consistency in training and provide trackability to help achieve 100% training completion even if everyone cannot be in the same room on the original day of training.  We can conduct a demonstration of this service to showcase how this supports 21 CFR part 11 for electronic signature and reporting.

Miller Tanner is always happy to assist you with mitigating your training challenges and can provide creative and innovative solutions for reaching your company’s overall training goals.

Sincerely,

Dawn Barnes, Director, Global Sales
Miller Tanner Associates

18 Smart Reasons to Use Our On-Demand Training/Learning Management System

18 Reasons to try ODT/LMS

If you haven’t tried virtual training solutions, then there is no better time than now! Train on-demand, anytime, anywhere. What’s not to like about that? We’ve got 18 smart reasons why you should stop wasting your time on redundant, ineffective training methods and start training effortlessly with our VALTs on-demand training. Work smarter not harder. Continue reading “18 Smart Reasons to Use Our On-Demand Training/Learning Management System”

Meet MTA: Mandy Sanderson, Global Event Director

Meet MTA Mandy Sanderson

The Miller Tanner difference is our people. That’s why we want to introduce you to our team of superstars that brings our corporate meetings and events to life for our clients.

Today, we introduce you to Mandy Sanderson, Global Event Director. Mandy is fluent in both Spanish and German and her excellent organizational capabilities help keep our clients’ events on track and running smoothly from start to finish. Continue reading “Meet MTA: Mandy Sanderson, Global Event Director”

Our On-Demand Trainer/Learning Management System Just Got Smarter

We’ve pushed our on-demand training product to a new level and it’s now smarter than ever! Miller Tanner Associates has just released the latest version of our proprietary On-Demand Trainer/Learning Management System and we can’t wait to share its capabilities with you.

We’ve completely redesigned our system and added new features for a more intuitive user experience. We’ve included all the bells and whistles to make our system easy to use with full training functionality within a mobile browser. Continue reading “Our On-Demand Trainer/Learning Management System Just Got Smarter”

Miller Tanner Associates’ Superlatives Awards

Superlatives Awards

Superlatives Awards 2016-2017

We are pleased to announce our “Superlatives Awards” for the 2016-2017 year! At our recent Miller Tanner Global Workshop, we recognized and awarded distinguished team members for their outstanding contribution to Miller Tanner throughout the year. Their special talents and skills contribute to the “Miller Tanner Difference”. We thank them for their dedication and hard work this year.  Continue reading “Miller Tanner Associates’ Superlatives Awards”