GDPR with ISPAH
The video is time-stamped so you can jump to various sections. You can also view the text version of each section below:
1. What is GDPR?
GDPR is a European Union regulation that requires organisations to protect the personal data and privacy of EU citizens for transactions that occur within EU member states. And non-compliance could cost organisations dearly, both financially and also their professional reputation.
Breaches in GDPR can see financial fines of up to 500,000 euros imposed, per incident, on organisations who breach these regulations, regardless of where they are based globally.
2. Why does it exist?
The short answer to that question is public concern over privacy. Europe in general has long had more stringent rules around how companies use the personal data of its citizens. The GDPR replaces the EU’s Data Protection Directive, which went into effect in 1995. This was well before the internet became the online business hub that it is today. Consequently, the directive is outdated and does not address many ways in which data is stored, collected and transferred today.
3. What data does it protect?
- Basic identity information such as name, address and ID numbers
- Web data such as location, IP address, cookie data and RFID tags
- Health and genetic data
- Biometric data
- Racial or ethnic data
- Political opinions
- Sexual orientation
4. Which organisations does it affect?
It affects organisations that meet the following criteria:
- A presence in an EU country.
- No presence in the EU, but it processes the personal data of European residents.
ISPAH, as an international organisation, has a large presence in Europe, including members, suppliers, and partners, and is therefore legally obligated to follow these regulations.
5. Who within ISPAH is responsible for this compliance?
Everyone within ISPAH is responsible for GDPR compliance, including you. To explain this a little further, there are defined roles within the organisation:
Data Controller: This role sits with the IT department at ISPAH. The data controller defines how personal data is processed and the purposes for which it is processed. The controller is also responsible for making sure that outside contractors comply.
Data Processor: The data processor is someone who may process personal information on behalf of the data controller. This is your role as during your tenure at ISPAH, you may have to process personal information in order to carry out your role. This is the key reason why ISPAH invests in insuring you have completed GDPR training and have an awareness of what this additional layer of data protection involves.
Data Protection Officer (DPO): Due to the structure of ISPAH this role is not applicable
6. Q & A
Can I use my work (university) or personal email for communication-related to ISPAH activities?
Yes, you can send emails from your personal or work email account to ISPAH or members of ISPAH, just like a member of the public, however, these emails cannot contain any personally identifiable information about other ISPAH members, board members, suppliers, partners or anyone associated with the organisation. These emails would really be for enquiries about your own membership or for general information.
If you have been allocated an ISPAH email account we would always recommend you use this for any email communications in relation to your role at ISPAH. In many cases, you may acquire information through your time with ISPAH and indirectly breach GDPR by using a personal email account for communications. It is always better to keep this communication separate which is the key reason why ISPAH provides Microsoft email accounts for approved members.
In what situations am I allowed to download ISPAH data (files, photos, lists containing Personally Identifying information)?
Short answer, never, unless you have been approved by both the executive leadership team and the ISPAH IT team there is no situation where you are allowed to download ISPAH data that contains personally sensitive information.
To explain a little further, when you download this information from an ISPAH system, such as one of the websites or your ISPAH Microsoft account the data is transferred from ISPAH’s systems to your computer. The data has effectively left ISPAH without consent which is a direct breach of your obligations within ISPAH. The organisation uses real-time data security monitoring systems which identify when information has been downloaded without consent. In situations where this occurs, your ISPAH accounts will be suspended pending an investigation by the ISPAH IT department and executive team.
Can I send PID internally to other ISPAH board, council or network members?
Yes, it is fine to do so. If in doubt, contact the IT department first who can advise on this. This information should only ever be sent via your ISPAH email account or via Microsoft Teams or Sharepoint.
Who should I contact if I need an ISPAH membership report, or information on a specific member’s registration status?
Please contact the IT team for any membership reports. The IT team are the only individuals who have enhanced systems permissions to access to this information.
Under what circumstances am I able to send a mass email to ISPAH members at-large, or special interest groups (i.e., councils/networks; ECN, LMIC, SBC etc)
ISPAH has a dedicated communications committee. Within this team, there are designated individuals who can create mass mailers and have been trained to use ISPAH’s marketing systems to do so. Please contact the Head of the Communications Committee, who will advise you on who to contact within the team.
Can I attend an ISPAH related meeting (on Teams) using my personal/work M365 account?
Yes, you can attend an ISPAH-related meeting on your work or personal 365 account, however, as you are doing this from an account which is external from ISPAH you will have limited access to some of the meeting features. In this scenario, you are attending the meeting as a guest. As documents and information may be shared within the meeting, We would always recommend you sign in to your ISPAH account using a web browser and you can attend the meeting using your ISPAH account online.
Can I integrate my ISPAH calendar with my work calendar?
Yes, there are a few ways you can do this. The easiest way to do this is by sharing the calendar with your work or personal email account and then you will have visibility over this calendar. – Please refer to video above.
