Warwick Conferences, 8 th March 2018 Agency Engagement Committee - - PowerPoint PPT Presentation

warwick conferences 8 th march 2018 agency engagement
SMART_READER_LITE
LIVE PREVIEW

Warwick Conferences, 8 th March 2018 Agency Engagement Committee - - PowerPoint PPT Presentation

Agency Engagement Meeting Warwick Conferences, 8 th March 2018 Agency Engagement Committee Amy Bewley Julie Shorrock (Chair) Prestige Reservations Hotel and Travel Solutions (HTS) Daniel Sweet Graham Upton First Choice Conference &


slide-1
SLIDE 1

Agency Engagement Meeting

Warwick Conferences, 8th March 2018

slide-2
SLIDE 2

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

Agency Engagement Committee

Daniel Sweet First Choice Conference & Events Julie Shorrock (Chair) Hotel and Travel Solutions (HTS) Graham Upton Inspirational Venues Amy Bewley Prestige Reservations

slide-3
SLIDE 3

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

Connect to “Warwick Guest” network If the Warwick Guest Wireless web page does not open automatically open your web browser and attempt to access any online content If you do not have an account, click on the link to create one and select “Attending a Conference” Fill in the requested information and your new login details will be sent to your phone.

Wifi @The_HBAA #HBAA21

slide-4
SLIDE 4

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

  • AE Objectives 2018
  • The Meetings Show HBAA Hosted Buyer Programme
  • GDPR - 3rd Party B2B, Susan Hall of Clarke Willmott LLP
  • Coffee Break
  • Independent Venue Showcase, Sian Sayward, Membership Committee
  • Open Mic

Agenda

slide-5
SLIDE 5

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

  • Agency Engagement Meetings
  • Code of Practice Awareness
  • Recruitment

Agency Engagement Objectives 2018

slide-6
SLIDE 6

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

  • 8th March – Warwick Conferences
  • 18th July – Stratford
  • 8th November - TBC

Agency Engagement Meetings

slide-7
SLIDE 7

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

  • “Application & Use of the Code of Practice”

Code of Practice Awareness

slide-8
SLIDE 8

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

“Survey Agent vs Hotels”

  • Salary Bandings
  • Positions
  • Benefits
  • Perks

Recruitment

slide-9
SLIDE 9

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

Pre-Show Conference – Millennium Gloucester Hotel, London

  • Networking Lunch
  • HBAA Agent Session & TMS Conference Session
  • Hosted Buyer Evening Welcome Reception – London Science Museum
  • Accommodation & Travel & Transfers Included
  • 8 Appointments at The Meetings Show
  • Hosted Buyer Lounge – Refreshments & Lunch
  • 2nd Day Option

The Meetings Show HBAA ‘Red Carpet’ Hosted Buyer Programme

slide-10
SLIDE 10

Susan Hall Clarke Willmott LLP

slide-11
SLIDE 11

clarkewillmott.com

slide-12
SLIDE 12

clarkewillmott.com

25 May 2018

slide-13
SLIDE 13

clarkewillmott.com

Brexit and the GDPR

slide-14
SLIDE 14

clarkewillmott.com

Data Protection Bill

Passed Second Reading 5 March 2018 and is now in Committee Stage “A Bill to make provision for the regulation of the processing of

information relating to individuals; to make provision in connection with the Information Commissioner's functions under certain regulations relating to information; to make provision for a direct marketing code of conduct; and for connected purposes.”

slide-15
SLIDE 15

clarkewillmott.com

GDPR Key concepts

“Data protection by design” “Data protection by default” Transparency – increased rights of data subjects Right of data portability and right of erasure No differentiation between data controllers based on location

slide-16
SLIDE 16

clarkewillmott.com

Core Changes

Penalties up to the higher of 4% global turnover or 20 million euros Non-EEA bodies caught by GDPR in respect of EEA-based activities Enhanced emphasis on demonstrable AND SPECIFIC legal bases for processing and recording them Obligation to notify ICO of data breach in 72 hours, data subject as soon as practicable End to registration of data controllers Increased obligations of data processors and with respect to selection and management of data processors.

slide-17
SLIDE 17

clarkewillmott.com

Key Areas to Concentrate On

Recording legal basis for processing personal data Subject access request changes:

– No specific form of request required – Thirty day turnaround – No fee for initial request

Increased emphasis on data processor/controller relationships (may cause issues with Cloud-based services)

slide-18
SLIDE 18

clarkewillmott.com

ICO Guidance on Data Governance

Record processing purposes, data sharing and retention periods. May have to make the records available to ICO on request. Controllers and processors both have documentation obligations. More restricted obligations for small and medium-sized enterprises (<250 employees) but still have to record regular data processing. Information audits or data-mapping exercises can be valuable. Records must be kept in writing. Most organisations will benefit from maintaining their records electronically. Records must be kept up to date and reflect your current processing activities.

slide-19
SLIDE 19

clarkewillmott.com

Consent

“Any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data…being processed” (old definition) “Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action signifies agreement to the processing of personal data…” (new) CONSENT MAY BE WITHDRAWN AT ANY TIME

slide-20
SLIDE 20

clarkewillmott.com

“Consent is highly unlikely to be a legal basis for data processing at work, unless employees can refuse without adverse consequences.”

Article 29 Working Party Opinion 2/2017 on Data Processing at Work

slide-21
SLIDE 21

clarkewillmott.com

If not consent, then what?

Article 6 GDPR sets out six legal bases for processing, at least one of which must apply: 1. Consent to processing for a specific purpose 2. Necessary for the performance of contract with data subject 3. Necessary for compliance with legal obligation of controller 4. Necessary to protect vital interest of data subject

  • r another

5. Necessary for public interest task or official

  • bligation of controller

6. Necessary for controller’s legitimate interest, subject to data subjects interests, rights and freedoms

slide-22
SLIDE 22

clarkewillmott.com

Key Questions

What is a Data Protection Officer and do we need one? What is a data privacy assessment, when should we carry one out and how? How do we manage document retention and purging under the new system?

slide-23
SLIDE 23

clarkewillmott.com

Contents of an Information Asset Register

Name of asset What does it do Location Owner Volume Personal data Access Shared Format Retention Risks

slide-24
SLIDE 24

clarkewillmott.com

What leads to data disasters?

slide-25
SLIDE 25

clarkewillmott.com

Personal data is about people

Data mistakes in general stem from overlooking or misreading the human element SO Solutions have to be people-driven not technology driven!

slide-26
SLIDE 26

clarkewillmott.com

Dealing with a Data Breach

Type of breach

– “Confidentiality breach” - where there is an unauthorised or accidental disclosure of, or access to, personal data. – “Integrity breach” - where there is an unauthorised or accidental alteration of personal data. – “Availability breach” - where there is an accidental or unauthorised loss of access15 to, or destruction of, personal data.

Notify ICO if “risk to rights and freedoms of data subjects” within 72 hours “Tell it all, tell it fast, tell the truth.” ICO will advise on notifying data subjects but if serious risk to their rights and freedoms need to do so without delay.

http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612052

slide-27
SLIDE 27

clarkewillmott.com

How to do it better?

Informed engagement Policies, checklists, training and peer review Creation and maintenance of an information asset register Clean up data flows

slide-28
SLIDE 28

clarkewillmott.com

Data Management Tools

Information Asset Register Data Flow Measurement and Recording Records of Processing Data Retention Policies – attached at appropriate place in the system.

slide-29
SLIDE 29

clarkewillmott.com

Recommendations

“By design” and “By default” Ownership of data issues Small-scale pilots and soft-launches for new data systems Data protection impact assessment at outset and throughout implementation and post-implementation phases Disaster Planning

slide-30
SLIDE 30

clarkewillmott.com

Contact

Susan Hall Partner t: 0345 209 1498 07712661939 e: susan.hall@clarkewillmott.com

slide-31
SLIDE 31

Coffee Break

slide-32
SLIDE 32

HBAA Independent Venue Show Case Sian Sayward, HBAA Membership Committee

slide-33
SLIDE 33

HBAA Setting the standards for the events and hospitality sector

HBAA @The_HBAA HBAA The_HBAA

Beach Blanket Babylon HBAA Membership, benefits and costs Application & Use of the Code of Practice

Open Mic

slide-34
SLIDE 34

Radcliffe Lounge Drinks 7pm Dinner 7.45pm