<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>edisclosure myth or reality? &#187; 2017</title>
	<atom:link href="https://jollyvip.com/edisclosure/category/2017/feed/" rel="self" type="application/rss+xml" />
	<link>https://jollyvip.com/edisclosure</link>
	<description>From litigation to the arbitration regime</description>
	<lastBuildDate>Tue, 01 Jul 2025 10:14:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<item>
		<title>The UK Data Protection Bill [HL]</title>
		<link>https://jollyvip.com/edisclosure/2017/10/06/the-uk-data-protection-bill-hl/</link>
		<comments>https://jollyvip.com/edisclosure/2017/10/06/the-uk-data-protection-bill-hl/#comments</comments>
		<pubDate>Fri, 06 Oct 2017 12:48:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=735</guid>
		<description><![CDATA[The published Bill- 218 pages. Will review the Bill soon&#8230;]]></description>
			<content:encoded><![CDATA[<p>The published <a href="https://publications.parliament.uk/pa/bills/lbill/2017-2019/0066/18066.pdf" title="DP Bill 66" target="_blank">Bill</a>- 218 pages.</p>
<p>Will review the Bill soon&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/10/06/the-uk-data-protection-bill-hl/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>data breach reporting &#8211; 5th, 6th, 7th &amp; 8th busting myths from the ICO</title>
		<link>https://jollyvip.com/edisclosure/2017/09/28/data-breach-reporting-5th-6th-7th-8th-busting-myths-from-the-ico/</link>
		<comments>https://jollyvip.com/edisclosure/2017/09/28/data-breach-reporting-5th-6th-7th-8th-busting-myths-from-the-ico/#comments</comments>
		<pubDate>Thu, 28 Sep 2017 20:20:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=727</guid>
		<description><![CDATA[What is &#8216;high risk&#8217; in the context of data breach reporting or notification under the GDPR? According to the ICO&#8217;s website on breach notification: When do individuals have to be notified? Where a breach is likely to result in a high risk to the rights and freedoms of individuals, you must notify those concerned directly. [...]]]></description>
			<content:encoded><![CDATA[<p>What is &#8216;high risk&#8217; in the context of data breach reporting or notification under the GDPR?<br />
According to the ICO&#8217;s website on <a href="https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/breach-notification/" title="ICO GDPR overview" target="_blank">breach notification:</a></p>
<p><em>When do individuals have to be notified?</p>
<p>Where a breach is likely to result in a <em>high risk</em> to the rights and freedoms of individuals, you must notify those concerned directly.</p>
<p>A ‘high risk’ means the threshold for notifying individuals is higher than for notifying the relevant supervisory authority.<br />
</em><br />
However, note the &#8216;fact&#8217; for &#8216;myth #5&#8242; on the <a href="https://iconewsblog.org.uk/2017/09/05/gdpr-setting-the-record-straight-on-data-breach-reporting/" title="breach reporting blog" target="_blank">breach reporting blog</a>:</p>
<p><em>And organisations need to remember that if there’s the likelihood of a high risk to people’s rights and freedoms, they will also need to report the breach to the individuals who have been affected.</em></p>
<p><strong>So, in essence, organisations will need to assess the &#8216;no risk, risk and high risk&#8217; to people&#8217;s rights and freedoms. This assumes or requires organisations to somehow get to grips with what constitutes &#8216;people&#8217;s rights and freedoms&#8217;. Rights and freedoms (privacy?) are not easy to identify.</strong>.</p>
<p>The ICO acknowledges this by stating in their <a href="https://iconewsblog.org.uk/2017/09/05/gdpr-setting-the-record-straight-on-data-breach-reporting/" title="myth busting blog" target="_blank">blog</a>:<br />
<em>Pan-European guidelines will assist organisations in determining thresholds for reporting, but the best approach will be to start examining the types of incidents your organisation faces and develop a sense of what constitutes a serious incident in the context of your data and your own customers.</em></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/09/28/data-breach-reporting-5th-6th-7th-8th-busting-myths-from-the-ico/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Data Protection Bill</title>
		<link>https://jollyvip.com/edisclosure/2017/09/14/uk-data-protection-bill/</link>
		<comments>https://jollyvip.com/edisclosure/2017/09/14/uk-data-protection-bill/#comments</comments>
		<pubDate>Thu, 14 Sep 2017 16:46:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=720</guid>
		<description><![CDATA[The Data Protection Bill (HL Bill 66) was introduced into the House of Lords on 13 September 2017. The published Bill. The press release from the Department for Digital, Culture, Media &#038; Sport. The Bill implements the EU General Data Protection Regulation (GDPR) and will replace the Data Protection Act 1998.]]></description>
			<content:encoded><![CDATA[<p>The Data Protection Bill (HL Bill 66) was introduced into the House of Lords on 13 September 2017.<br />
The <a href="https://publications.parliament.uk/pa/bills/lbill/2017-2019/0066/lbill_2017-20190066_en_1.htm" title="the published Bill" target="_blank">published Bill</a>.<br />
The <a href="https://www.gov.uk/government/news/data-laws-to-be-made-fit-for-digital-age" title="press release of the Bill" target="_blank">press release</a> from the Department for Digital, Culture, Media &#038; Sport.</p>
<p>The Bill implements the EU General Data Protection Regulation (GDPR) and will replace the Data Protection Act 1998. </p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/09/14/uk-data-protection-bill/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4th busting myths from the ICO</title>
		<link>https://jollyvip.com/edisclosure/2017/09/02/4th-busting-myths-from-the-ico/</link>
		<comments>https://jollyvip.com/edisclosure/2017/09/02/4th-busting-myths-from-the-ico/#comments</comments>
		<pubDate>Sat, 02 Sep 2017 16:49:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=713</guid>
		<description><![CDATA[Here&#8217;s the 4th myths from the ICO. Myth #4 GDPR is an unnecessary burden on organisations. Fact The new regime is an evolution in data protection, not a revolution. Read the ICO blog on GDPR is an evolution in data protection, not a burdensome revolution]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s the 4th myths from the ICO.</p>
<p>Myth #4</p>
<p>GDPR is an unnecessary burden on organisations.</p>
<p>Fact</p>
<p>The new regime is an evolution in data protection, not a revolution.</p>
<p>Read the ICO blog on <a href="https://iconewsblog.org.uk/2017/08/25/gdpr-is-an-evolution-in-data-protection-not-a-burdensome-revolution/" title="myth 4" target="_blank">GDPR is an evolution in data protection, not a burdensome revolution</a></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/09/02/4th-busting-myths-from-the-ico/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Consent for GDPR compliance?</title>
		<link>https://jollyvip.com/edisclosure/2017/09/02/consent-for-gdpr-compliance/</link>
		<comments>https://jollyvip.com/edisclosure/2017/09/02/consent-for-gdpr-compliance/#comments</comments>
		<pubDate>Sat, 02 Sep 2017 16:36:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=710</guid>
		<description><![CDATA[2nd and 3rd busting myths from the ICO Myth #2 You must have consent if you want to process personal data. Fact: The GDPR is raising the bar to a higher standard for consent. Myth #3 I can’t start planning for new consent rules until the ICO’s formal guidance is published. Fact: I know many [...]]]></description>
			<content:encoded><![CDATA[<p><strong>2nd and 3rd busting myths from the ICO</strong></p>
<p>Myth #2</p>
<p>You must have consent if you want to process personal data.</p>
<p>Fact:</p>
<p>The GDPR is raising the bar to a higher standard for consent.</p>
<p>Myth #3</p>
<p>I can’t start planning for new consent rules until the ICO’s formal guidance is published.</p>
<p>Fact:</p>
<p>I know many people are waiting for us to publish our final guidance on consent. Businesses want certainty and assurance of harmonised rules. Waiting until Europe-wide consent guidelines have been agreed before we publish our final guidance is key to ensuring consistency. The current timetable is December.</p>
<p>The ICO&#8217;s blog on <a href="https://iconewsblog.org.uk/2017/08/16/consent-is-not-the-silver-bullet-for-gdpr-compliance/" title="myths 2" target="_blank">consent is not the silver bullet for GDPR compliance</a></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/09/02/consent-for-gdpr-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Busting Myths &amp; Fake (GDPR &amp; data protection &amp; privacy) news &#8211; from ICO</title>
		<link>https://jollyvip.com/edisclosure/2017/08/11/busting-myths-fake-gdpr-data-protection-privacy-news-from-ico/</link>
		<comments>https://jollyvip.com/edisclosure/2017/08/11/busting-myths-fake-gdpr-data-protection-privacy-news-from-ico/#comments</comments>
		<pubDate>Fri, 11 Aug 2017 11:18:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=702</guid>
		<description><![CDATA[Keeping up with ICO&#8217;s activities over the coming weeks, months &#038; years! Shattering the myths about #GDPR &#8211; Read the first in a new series of ICO blogs, this one about fines scaremongering https://t.co/gpJV8P0Zcn pic.twitter.com/oxLZcMkktB &#8212; ICO (@ICOnews) August 9, 2017]]></description>
			<content:encoded><![CDATA[<p>Keeping up with ICO&#8217;s activities over the coming weeks, months &#038; years!</p>
<blockquote class="twitter-tweet" data-lang="en"><p lang="en" dir="ltr">Shattering the myths about <a href="https://twitter.com/hashtag/GDPR?src=hash">#GDPR</a> &#8211; Read the first in a new series of ICO blogs, this one about fines scaremongering <a href="https://t.co/gpJV8P0Zcn">https://t.co/gpJV8P0Zcn</a> <a href="https://t.co/oxLZcMkktB">pic.twitter.com/oxLZcMkktB</a></p>
<p>&mdash; ICO (@ICOnews) <a href="https://twitter.com/ICOnews/status/895317545384673283">August 9, 2017</a></p></blockquote>
<p><script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/08/11/busting-myths-fake-gdpr-data-protection-privacy-news-from-ico/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK DP Bill &#8211; GDPR into UK</title>
		<link>https://jollyvip.com/edisclosure/2017/08/11/uk-dp-bill-gdpr-into-uk/</link>
		<comments>https://jollyvip.com/edisclosure/2017/08/11/uk-dp-bill-gdpr-into-uk/#comments</comments>
		<pubDate>Fri, 11 Aug 2017 11:13:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=699</guid>
		<description><![CDATA[Today&#39;s highlight -just catching up #DPBill UK&#39;s #GDPR Planned Reforms at https://t.co/plYQsJetxk &#8212; cher devey (@datachainrisk) August 7, 2017]]></description>
			<content:encoded><![CDATA[<blockquote class="twitter-tweet" data-lang="en"><p lang="en" dir="ltr">Today&#39;s highlight -just catching up <a href="https://twitter.com/hashtag/DPBill?src=hash">#DPBill</a> UK&#39;s <a href="https://twitter.com/hashtag/GDPR?src=hash">#GDPR</a> Planned Reforms at <a href="https://t.co/plYQsJetxk">https://t.co/plYQsJetxk</a></p>
<p>&mdash; cher devey (@datachainrisk) <a href="https://twitter.com/datachainrisk/status/894690639127904257">August 7, 2017</a></p></blockquote>
<p><script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/08/11/uk-dp-bill-gdpr-into-uk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GDPR fines</title>
		<link>https://jollyvip.com/edisclosure/2017/07/12/gdpr-fines/</link>
		<comments>https://jollyvip.com/edisclosure/2017/07/12/gdpr-fines/#comments</comments>
		<pubDate>Wed, 12 Jul 2017 16:56:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=687</guid>
		<description><![CDATA[I&#8217;ve posted some GDPR stuff on Jyutsu.com My high-level map of GDPR fines (pdf) Although my PhD research is not on GDPR fines, the outcome from my research should help organisations to be better prepared to respond to data breach incidents. Not notifying affected data subjects when ordered by the data authority (ICO) fall under [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve posted some GDPR stuff on <a href="http://jyutsu.com/" title="Jyutsu" target="_blank">Jyutsu.com</a></p>
<p>My high-level map of <a href='http://jollyvip.com/edisclosure/files/2017/07/GDPR-fines.pdf'>GDPR fines</a> (pdf)</p>
<p>Although my PhD research is not on GDPR fines, the outcome from my research should help organisations to be better prepared to respond to data breach incidents. </p>
<p>Not notifying affected data subjects when <strong>ordered</strong> by the data authority (ICO) fall under the high 1st level of fines i.e. 4% or EUR20M. However, failure to notify the <strong>data breach</strong> to the data authority (ICO) and to data subjects exposed organisations to the 2nd level of fines i.e. 2% or EUR10M. In essence be prepared to be fined when you failed to comply with the breach notification requirements, Art 33 and Art 34.</p>
<p>Note that when organisations have a <strong>security breach</strong> i.e. failure to comply with the data processing principles Art 5 (1)(f) (failure to use appropriate technical or organisational measures), this falls under the high 1st level of fines</p>
<p>So..there&#8217;s no way to avoid the fines unless you can totally avoid security breaches or avoid falling foul to the data processing principles.</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/07/12/gdpr-fines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Article 29 Working Party newsroom</title>
		<link>https://jollyvip.com/edisclosure/2017/06/22/article-29-working-party-newsroom/</link>
		<comments>https://jollyvip.com/edisclosure/2017/06/22/article-29-working-party-newsroom/#comments</comments>
		<pubDate>Thu, 22 Jun 2017 15:58:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=675</guid>
		<description><![CDATA[EU&#8217;s newsroom site where various info on &#038; from the Article 20 Working Party. Currently, the guidelines: Guidelines on the right to &#8220;data portability&#8221;, wp242rev.01 pdf Guidelines on Data Protection Officers (&#8216;DPOs&#8217;), wp243rev.01 pdf Guidelines on The Lead Supervisory Authority, wp244rev.01 pdf Guidelines on Data Protection Impact Assessment (DPIA) or Privacy Impact Assessment (PIA), wp248_enpdf [...]]]></description>
			<content:encoded><![CDATA[<p>EU&#8217;s newsroom site where various info on &#038; from the <a href="http://ec.europa.eu/newsroom/just/item-detail.cfm?item_id=50083" title="Article 29 Working Party" target="_blank">Article 20 Working Party</a>.</p>
<p>Currently, the guidelines:</p>
<p>Guidelines on the right to &#8220;data portability&#8221;, <a href="http://ec.europa.eu/newsroom/document.cfm?doc_id=44099" title="data portability" target="_blank">wp242rev.01 pdf</a></p>
<p>Guidelines on Data Protection Officers (&#8216;DPOs&#8217;), <a href="http://ec.europa.eu/newsroom/document.cfm?doc_id=44100" title="DPO" target="_blank">wp243rev.01 pdf</a></p>
<p>Guidelines on The Lead Supervisory Authority, <a href="http://ec.europa.eu/newsroom/document.cfm?doc_id=44102" title="SA" target="_blank">wp244rev.01 pdf</a></p>
<p>Guidelines on Data Protection Impact Assessment (DPIA) or Privacy Impact Assessment (PIA), <a href="http://ec.europa.eu/newsroom/document.cfm?doc_id=44137" title="SA" target="_blank">wp248_enpdf</a></p>
<p>More to add&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/06/22/article-29-working-party-newsroom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EU &#8211; Infographics on Data Protection (GDPR)</title>
		<link>https://jollyvip.com/edisclosure/2017/06/22/eu-infographics-on-data-protection-gdpr/</link>
		<comments>https://jollyvip.com/edisclosure/2017/06/22/eu-infographics-on-data-protection-gdpr/#comments</comments>
		<pubDate>Thu, 22 Jun 2017 15:34:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2017]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=670</guid>
		<description><![CDATA[Warning &#8211; the infographics &#8211; not to be treated as &#8216;legal&#8217; text.]]></description>
			<content:encoded><![CDATA[<p>Warning &#8211; the <a href="http://ec.europa.eu/justice/newsroom/data-protection/infographic/2017/index_en.htm" title="infographics" target="_blank"> infographics </a> &#8211; not to be treated as &#8216;legal&#8217; text.</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2017/06/22/eu-infographics-on-data-protection-gdpr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
