PCS Speaker profile: Gabriel Voisin on the impact of GDPR
- 21 November 2017
Gabriel Voisin, partner at Bird and Bird LLPās international privacy and data protection branch, will be speaking about the impact of the General Data Protection Regulation (GDPR) and what it means for the health sector at the first Public Cyber Security conference next month. Voisin spoke to reporter Hannah Crouch about how GDPR differs from current data laws and how regulators will enforce it on 25 May.Ā Ā
Voisin, who provides advice on GDPR andĀ guarding against potential cyber intrusions, told Digital Health News that the main focus of his talk onĀ Thursday, 7 December will be how GDPR is linked to cyber security.
The impact of GDPR on the health sector
The introduction of GDPR in 2018 will seeĀ tougher fines dished out to organisations if they breach data regulations in a bid to encourage transparency andĀ put more control in the hands of citizens.
For the health sector, which handles sensitive files such as patient records, this could meanĀ data privacy impact assessments becoming mandatory at the start of any relevant activity.
Voisin said the new rules will make it compulsory for organisations, including the NHS, to notify the Information Commissionerās Office (ICO) if there is a breach of data regulations.
The breach must be reported within 72 hours or organisations could face a £8.8 million (10 million Euros) fine.
Voisin said the challenge will be for NHS hospital trusts to make sure a plan is in place of what to do if there is a breach to ensure they meet the new deadlines.
Right to know
The second part of the new rules is less automatic according to Voisin as organisations also have an obligation to notify individuals where there is a ‘high risk’ that their information has been breached.
However he said that working out what constitutes as ‘high risk’ will be another challenge for NHS trusts.
ICO’s involvement in enforcing GDPR
Voisin will be joined by Peter Brown, ICO group manager at the Cyber event’s Policy and Skills workshop.
HeĀ predicts Brown will be āput on the spotā about how the ICO will deal with those organisations who fail to have a plan in place by May 2018.
āSome are going to miss the deadline and there is going to be cracks,ā Voisin said.
āThe question is going to be what is the enforcement?
āIt will be interesting at the conference to hear from the regulator on how it plans to do that.
āThe ICO has made it clear there will be no grace period and have been very strong.ā
Current laws
Currently the UK complies with the Data Protection Act 1998 which protects peopleās personal data.
Voisin said data protection laws are due for a renewal as it came into force ābefore Google arrivedā.
āGDPR provides legislation which is appropriate for this new environment,ā Voisin said.
You can catch Voisin between 11.55am and 12.40pmĀ at the ICC Birmingham.
A newĀ peer-to-peer cyber security warning alerting system is also due to be launched at the Public Cyber SecurityĀ conference.
The āNHS Cyber Security Batsignal’ has beenĀ designed to provide immediate alerts of future cyber security incidents and enable sharing of information on how to respond, ensuring digital leaders across the NHS can remain in contact even if official channels are out of action.
The Public Cyber Security conference is free to attend for public sector information security, IT and IG professionals.
You can register by visiting the eventās website.