SlideShare a Scribd company logo
1 of 41
Download to read offline
Wil Brown
@DeveloperWil
zeropointdevelopment.com for WordPress Sydney
Guidance on complying with the
new EU regulation
General Data Protection Regulation
Privacy law from European Commission protecting
rights of all EU citizens (28 member states) and
their personal data.
Approved April 2016.
Becomes effective May 25, 2018.
@DeveloperWil #wpsyd
Replaces 95/46/EC Directive of Data Protection
(1995) and is more extensive than 2011 Cookie
Law which is being replaced by EU ePrivacy
Regulation (EUePR/EUPR) soon after May 2018.
GDPR and EUPR will compliment each other.
Ref: GDPR Regulation and official PDF
@DeveloperWil #wpsyd
Probably the biggest shake up and most
important change in data privacy in the
last 20 years.
This is a BIG DEAL
@DeveloperWil #wpsyd
The EU GDPR is a law.
Use the information here as guidance.
Seek your own legal advice for modifying your
business operating policies and procedures.
@DeveloperWil #wpsyd
Facebook and Google already hit with $8.8 billion
in lawsuits on day one of GDPR.
“.. accusing the companies of coercing users into
sharing personal data.”
Ref: https://www.theverge.com/2018/5/25/17393766/facebook-
google-gdpr-lawsuit-max-schrems-europe
@DeveloperWil #wpsyd
Designed to protect the rights of EU citizens
Essentially impacts everyone with web access
unless you
– Actively block all 28 EU states IP addresses
Highly Impractical
– Actively track and block all EU citizens on the web
Highly Ilegal …unless you work for the NSA :-P
@DeveloperWil #wpsyd
“I am an Australian citizen with a WordPress
website – does GDPR affect me?”
Most likely yes it does.
1. If any EU citizen can interact with your website
2. Have establishment in the EU
3. Offer Goods and Services to EU
– EU language translation, offer shipping to an EU
state, using AdWords targeting EU audience
@DeveloperWil #wpsyd
• WP community site allowing users to create a
user profile (login); name, email, website
• An eCommerce (WooCommerce, EDD) store that
sells products; virtual = email, physical = address
• WP site that uses analytics software (Google
Analytics, Gtmetrix); IP address, cookies
• WP blog with newsletter subscription and
comments; name, email, IP address
• Firewall plugins; IP address (hacker unlikely to sue!)
@DeveloperWil #wpsyd
Data Controller
A business that controls personal data. If you have
collected and now possess personal data, and you
determine how that data is now dealt with
(including giving it to a 3rd party), you are likely
considered a controller under the regulations.
e.g. You, CRM systems, Facebook/Google
@DeveloperWil #wpsyd
Data Processor
A 3rd party company that you might give your data
to, who will use or manipulate your data in some
way.
e.g. Mailchimp, Campaign Monitor, Stripe, Paypal
@DeveloperWil #wpsyd
Consent
• Freely given: can I refuse/rescind my consent?
• Specific: what is my data being collected for?
• Informed: what are my rights?
• Unambiguous: how is my data being used?
• Statement or clear affirmative action
– Silence, pre-ticked checkbox or inaction does not
equal consent
@DeveloperWil #wpsyd
Establishment in the EU
Where you have any real and effective activity, no
matter if it is minimal or substantial, through a
stable arrangement in the EU, you are likely to be
‘established’ under the regulations.
e.g. permanent representation (a person), office.
@DeveloperWil #wpsyd
Processing
Any operation which is performed on personal
data, whether or not by automated means, such
as collection, recording, organisation, structuring,
storage, adaptation or alteration, retrieval,
consultation, use, disclosure by transmission,
dissemination or otherwise making available,
alignment or combination, restriction, erasure or
destruction;
@DeveloperWil #wpsyd
Data Protection Officer (DPO)
A data protection officer (DPO) is an enterprise
security leadership role required by the GDPR.
Data protection officers are responsible for
overseeing data protection strategy and
implementation to ensure compliance with GDPR.
@DeveloperWil #wpsyd
Applies to personal data (Art. 4)
Personally identifiable data (of a natural person –
think a Human Being), identified directly or
indirectly;
name, ID #, location, physical, psychological,
genetic, mental, economic, cultural or social
identity.
@DeveloperWil #wpsyd
Applies to any sensitive data (Art. 9)
Processing is prohibited for personal data
revealing racial or ethnic origin, political opinions,
religious or philosophical beliefs, trade union
membership, genetic data, biometric data, health
data, data concerning person’s sex life or sexual
orientation.
Exclusions apply; legal, medical, national security ..
@DeveloperWil #wpsyd
Requires that consent is given (Art. 7)
People must be given a true voluntary choice
whether or not they consent to give you their
data.
Need to add checkbox to all data collection forms
[✔]* I give consent to store and process my data
* = required
@DeveloperWil #wpsyd
Gives right to be forgotten (Art. 17)
Data controller must securely erase all personal
data they hold on requester without undue delay
When specific criteria are met – see Regulation.
– Data is no longer needed
– Purpose for collection has expired
– Data unlawfully processed …
@DeveloperWil #wpsyd
Privacy by design and default (Art. 25)
New “systems” collecting and processing data
must be inherently secure from concept.
You must build privacy and security into any new
apps, programs, websites, procedures etc.
@DeveloperWil #wpsyd
Gives right to know what info is being stored
You need to specify what data you will be
collecting and for what purposes up front and
before it has been collected.
Privacy Policy, Cookie Statement, T&C’s
@DeveloperWil #wpsyd
Gives right to access held info and data
portability (Art. 20)
You will need to provide all data held on requester
and supply that in a machine readable format for
importing into another system.
CSV, JSON, XSL file.
@DeveloperWil #wpsyd
• Notify authorities within 72 hours of data
breach and people whose data was accessed
• Data only used for reasons given at time of
collection and securely deleted after no longer
needed
• Parental consent required to process personal
data of children under 16 (Art. 8)
• Allows national authorities to impose fines on
companies breaching regulation
@DeveloperWil #wpsyd
If your business doesn’t comply with GPDR
• Get sanctioned up to 4% of the annual
worldwide turnover or fined up to €20 million
(the higher of the two), per infringement.
• Tiered approach to fines.
e.g. a company can be fined 2% for not having
their records in order, not notifying the
supervising authority and data subject about a
breach, or not conducting an impact
assessment. (Art. 83)
@DeveloperWil #wpsyd
Hire a good lawyer
A lawyer will provide you with tailored advice for
your business.
Ask friends and colleagues for recommendations
of lawyer contacts they have had a good
experience with.
Through Sydney Business Chambers
https://www.thechamber.com.au/
@DeveloperWil #wpsyd
Step 1
Review all data collection and processing
workflows
Work through entire WP site, document where
data is collected, processed and stored as well as
how long stored for:
– eCommerce check out page
– Payment gateways: Stripe/PayPal
– Email marketing: Mailchimp
– All forms on site: consent check box
– All generated cookies https://www.cookiebot.com/en/cookie-consent/
@DeveloperWil #wpsyd
Step 2
Update all legal documents
– Privacy Policy
– Terms & Conditions
– Cookie Statement
– Affiliate Terms
– NDA
– Project Contracts
– Contractor Agreements
@DeveloperWil #wpsyd
Step 3
Offer data portability
Ability to export all personal data in a transferrable
and importable document. e.g. csv, xml
Update to WordPress 4.9.6 to take advantage of
new data export feature.
@DeveloperWil #wpsyd
Step 4
Encrypt your data
1. Encrypt your transferred data (web traffic)
using HTTPS
Going HTTPS has other advantages too.
2. Encrypt your stored data
Not legally required to comply with GDPR but
highly recommended.
@DeveloperWil #wpsyd
Step 5
Self-Certify Under Privacy Shield Framework
Consider certifying under the EU-U.S. and Swiss-
U.S. Privacy Shield Frameworks if you are US
Established.
Provides companies on both sides of the Atlantic
with a mechanism to comply with data protection
requirements when transferring personal data
from the European Union and Switzerland to the
United States.
@DeveloperWil #wpsyd
Step 6
Check WP themes, plugins, services & APIs
• Contact Forms
– Gravity Forms, NinjaForms, WPForms
• Comment & Marketing Services
– Disqus, Jetpack, Mailchimp, Active Campaign, AWeber
• Analytics, Tracking & Remarketing
– Google Analytics, Hotjar, AdRoll
• eCommerce & Payment Processors
– WooCommerce, Easy Digital Downloads, Stripe, PayPal
• Community Plugins
– LearnDash, bbPress, BuddyPress
• All third-party APIs e.g. Is Google Fonts GDPR compliant?
@DeveloperWil #wpsyd
Step 7
v4.9.6 Privacy & Maintenance Release
– Logged out commenters given choice to store data in
a cookie
@DeveloperWil #wpsyd
v4.9.6 Privacy & Maintenance Release
– Privacy Policy Page
@DeveloperWil #wpsyd
v4.9.6 Privacy & Maintenance Release
– Data Export
@DeveloperWil #wpsyd
This plugin is meant to assist a Controller, Data
Processor, and Data Protection Officer (DPO) with
efforts to meet the obligations and rights enacted
under the GDPR.
GDPR https://wordpress.org/plugins/gdpr/
@DeveloperWil #wpsyd
With Stream, you’re never left in the dark about
WordPress Admin activity.
Every logged-in user action is displayed in an
activity stream and organized for easy filtering by
User, Role, Context, Action or IP address.
Stream https://en-au.wordpress.org/plugins/stream/
@DeveloperWil #wpsyd
WordPress’ most comprehensive real time user
activity and monitoring log plugin. It helps
thousands of WordPress administrators and
security professionals keep an eye on what is
happening on their websites.
WP Security Audit Log https://wordpress.org/plugins/wp-security-audit-log/
@DeveloperWil #wpsyd
http://eur-lex.europa.eu/legal-
content/EN/TXT/?qid=1517578296944&uri=CELEX%3A52018DC004
3
https://ec.europa.eu/commission/priorities/justice-and-
fundamental-rights/data-protection/2018-reform-eu-data-
protection-rules_en
https://kinsta.com/blog/gdpr-compliance/
https://codeable.io/gdpr-wordpress-woocommerce-starter-guide/
https://alphadigital.com.au/blog/gdpr-australian-retailers/
https://uploads-
ssl.webflow.com/596f08725f724769d8514755/5ad83ce924849422
c9707f76_Australian%20Privacy%20And%20Data.pdf
@DeveloperWil #wpsyd
[Front Cover] wordpress.org
[32] wordpress.org
[33] wordpress.org
[34] wordpress.org
[35] wordpress.org
[36] wordpress.org
[37] wordpress.org
[Back Cover] zeropointdevelopment.com
@DeveloperWil #wpsyd
▪ 20+ years in IT: Dev & SysOps
▪ WordPress Developer since 2008
▪ Plugins, APIs, Security & Systems Integrations
▪ Organiser WPSyd & WordCamp Sydney
zeropointdevelopment.com
@DeveloperWil
♥ Pizza & Craft Beer
@DeveloperWil #wpsyd
@DeveloperWil #wpsyd
@DeveloperWil

More Related Content

What's hot

Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
IBB Law
 

What's hot (20)

GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
IoT - Attacks and Solutions
IoT - Attacks and SolutionsIoT - Attacks and Solutions
IoT - Attacks and Solutions
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
The European Union’s 
General Data Protection Regulation
The European Union’s 
General Data Protection Regulation The European Union’s 
General Data Protection Regulation
The European Union’s 
General Data Protection Regulation
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliant
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...
 

Similar to GDPR - General Data Protection Regulation

skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
RahulGarg294918
 

Similar to GDPR - General Data Protection Regulation (20)

Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It Webinar
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR, WordPress and You.
GDPR, WordPress and You.GDPR, WordPress and You.
GDPR, WordPress and You.
 
GPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-RightGPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-Right
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
GDPR 101
GDPR 101GDPR 101
GDPR 101
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with Confidence
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 
ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
What Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRWhat Marketers Need To Know About GDPR
What Marketers Need To Know About GDPR
 

Recently uploaded

VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 

Recently uploaded (20)

Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
 
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 

GDPR - General Data Protection Regulation

  • 1. Wil Brown @DeveloperWil zeropointdevelopment.com for WordPress Sydney Guidance on complying with the new EU regulation
  • 2. General Data Protection Regulation Privacy law from European Commission protecting rights of all EU citizens (28 member states) and their personal data. Approved April 2016. Becomes effective May 25, 2018. @DeveloperWil #wpsyd
  • 3. Replaces 95/46/EC Directive of Data Protection (1995) and is more extensive than 2011 Cookie Law which is being replaced by EU ePrivacy Regulation (EUePR/EUPR) soon after May 2018. GDPR and EUPR will compliment each other. Ref: GDPR Regulation and official PDF @DeveloperWil #wpsyd
  • 4. Probably the biggest shake up and most important change in data privacy in the last 20 years. This is a BIG DEAL @DeveloperWil #wpsyd
  • 5. The EU GDPR is a law. Use the information here as guidance. Seek your own legal advice for modifying your business operating policies and procedures. @DeveloperWil #wpsyd
  • 6. Facebook and Google already hit with $8.8 billion in lawsuits on day one of GDPR. “.. accusing the companies of coercing users into sharing personal data.” Ref: https://www.theverge.com/2018/5/25/17393766/facebook- google-gdpr-lawsuit-max-schrems-europe @DeveloperWil #wpsyd
  • 7. Designed to protect the rights of EU citizens Essentially impacts everyone with web access unless you – Actively block all 28 EU states IP addresses Highly Impractical – Actively track and block all EU citizens on the web Highly Ilegal …unless you work for the NSA :-P @DeveloperWil #wpsyd
  • 8. “I am an Australian citizen with a WordPress website – does GDPR affect me?” Most likely yes it does. 1. If any EU citizen can interact with your website 2. Have establishment in the EU 3. Offer Goods and Services to EU – EU language translation, offer shipping to an EU state, using AdWords targeting EU audience @DeveloperWil #wpsyd
  • 9. • WP community site allowing users to create a user profile (login); name, email, website • An eCommerce (WooCommerce, EDD) store that sells products; virtual = email, physical = address • WP site that uses analytics software (Google Analytics, Gtmetrix); IP address, cookies • WP blog with newsletter subscription and comments; name, email, IP address • Firewall plugins; IP address (hacker unlikely to sue!) @DeveloperWil #wpsyd
  • 10. Data Controller A business that controls personal data. If you have collected and now possess personal data, and you determine how that data is now dealt with (including giving it to a 3rd party), you are likely considered a controller under the regulations. e.g. You, CRM systems, Facebook/Google @DeveloperWil #wpsyd
  • 11. Data Processor A 3rd party company that you might give your data to, who will use or manipulate your data in some way. e.g. Mailchimp, Campaign Monitor, Stripe, Paypal @DeveloperWil #wpsyd
  • 12. Consent • Freely given: can I refuse/rescind my consent? • Specific: what is my data being collected for? • Informed: what are my rights? • Unambiguous: how is my data being used? • Statement or clear affirmative action – Silence, pre-ticked checkbox or inaction does not equal consent @DeveloperWil #wpsyd
  • 13. Establishment in the EU Where you have any real and effective activity, no matter if it is minimal or substantial, through a stable arrangement in the EU, you are likely to be ‘established’ under the regulations. e.g. permanent representation (a person), office. @DeveloperWil #wpsyd
  • 14. Processing Any operation which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; @DeveloperWil #wpsyd
  • 15. Data Protection Officer (DPO) A data protection officer (DPO) is an enterprise security leadership role required by the GDPR. Data protection officers are responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR. @DeveloperWil #wpsyd
  • 16. Applies to personal data (Art. 4) Personally identifiable data (of a natural person – think a Human Being), identified directly or indirectly; name, ID #, location, physical, psychological, genetic, mental, economic, cultural or social identity. @DeveloperWil #wpsyd
  • 17. Applies to any sensitive data (Art. 9) Processing is prohibited for personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning person’s sex life or sexual orientation. Exclusions apply; legal, medical, national security .. @DeveloperWil #wpsyd
  • 18. Requires that consent is given (Art. 7) People must be given a true voluntary choice whether or not they consent to give you their data. Need to add checkbox to all data collection forms [✔]* I give consent to store and process my data * = required @DeveloperWil #wpsyd
  • 19. Gives right to be forgotten (Art. 17) Data controller must securely erase all personal data they hold on requester without undue delay When specific criteria are met – see Regulation. – Data is no longer needed – Purpose for collection has expired – Data unlawfully processed … @DeveloperWil #wpsyd
  • 20. Privacy by design and default (Art. 25) New “systems” collecting and processing data must be inherently secure from concept. You must build privacy and security into any new apps, programs, websites, procedures etc. @DeveloperWil #wpsyd
  • 21. Gives right to know what info is being stored You need to specify what data you will be collecting and for what purposes up front and before it has been collected. Privacy Policy, Cookie Statement, T&C’s @DeveloperWil #wpsyd
  • 22. Gives right to access held info and data portability (Art. 20) You will need to provide all data held on requester and supply that in a machine readable format for importing into another system. CSV, JSON, XSL file. @DeveloperWil #wpsyd
  • 23. • Notify authorities within 72 hours of data breach and people whose data was accessed • Data only used for reasons given at time of collection and securely deleted after no longer needed • Parental consent required to process personal data of children under 16 (Art. 8) • Allows national authorities to impose fines on companies breaching regulation @DeveloperWil #wpsyd
  • 24. If your business doesn’t comply with GPDR • Get sanctioned up to 4% of the annual worldwide turnover or fined up to €20 million (the higher of the two), per infringement. • Tiered approach to fines. e.g. a company can be fined 2% for not having their records in order, not notifying the supervising authority and data subject about a breach, or not conducting an impact assessment. (Art. 83) @DeveloperWil #wpsyd
  • 25. Hire a good lawyer A lawyer will provide you with tailored advice for your business. Ask friends and colleagues for recommendations of lawyer contacts they have had a good experience with. Through Sydney Business Chambers https://www.thechamber.com.au/ @DeveloperWil #wpsyd Step 1
  • 26. Review all data collection and processing workflows Work through entire WP site, document where data is collected, processed and stored as well as how long stored for: – eCommerce check out page – Payment gateways: Stripe/PayPal – Email marketing: Mailchimp – All forms on site: consent check box – All generated cookies https://www.cookiebot.com/en/cookie-consent/ @DeveloperWil #wpsyd Step 2
  • 27. Update all legal documents – Privacy Policy – Terms & Conditions – Cookie Statement – Affiliate Terms – NDA – Project Contracts – Contractor Agreements @DeveloperWil #wpsyd Step 3
  • 28. Offer data portability Ability to export all personal data in a transferrable and importable document. e.g. csv, xml Update to WordPress 4.9.6 to take advantage of new data export feature. @DeveloperWil #wpsyd Step 4
  • 29. Encrypt your data 1. Encrypt your transferred data (web traffic) using HTTPS Going HTTPS has other advantages too. 2. Encrypt your stored data Not legally required to comply with GDPR but highly recommended. @DeveloperWil #wpsyd Step 5
  • 30. Self-Certify Under Privacy Shield Framework Consider certifying under the EU-U.S. and Swiss- U.S. Privacy Shield Frameworks if you are US Established. Provides companies on both sides of the Atlantic with a mechanism to comply with data protection requirements when transferring personal data from the European Union and Switzerland to the United States. @DeveloperWil #wpsyd Step 6
  • 31. Check WP themes, plugins, services & APIs • Contact Forms – Gravity Forms, NinjaForms, WPForms • Comment & Marketing Services – Disqus, Jetpack, Mailchimp, Active Campaign, AWeber • Analytics, Tracking & Remarketing – Google Analytics, Hotjar, AdRoll • eCommerce & Payment Processors – WooCommerce, Easy Digital Downloads, Stripe, PayPal • Community Plugins – LearnDash, bbPress, BuddyPress • All third-party APIs e.g. Is Google Fonts GDPR compliant? @DeveloperWil #wpsyd Step 7
  • 32. v4.9.6 Privacy & Maintenance Release – Logged out commenters given choice to store data in a cookie @DeveloperWil #wpsyd
  • 33. v4.9.6 Privacy & Maintenance Release – Privacy Policy Page @DeveloperWil #wpsyd
  • 34. v4.9.6 Privacy & Maintenance Release – Data Export @DeveloperWil #wpsyd
  • 35. This plugin is meant to assist a Controller, Data Processor, and Data Protection Officer (DPO) with efforts to meet the obligations and rights enacted under the GDPR. GDPR https://wordpress.org/plugins/gdpr/ @DeveloperWil #wpsyd
  • 36. With Stream, you’re never left in the dark about WordPress Admin activity. Every logged-in user action is displayed in an activity stream and organized for easy filtering by User, Role, Context, Action or IP address. Stream https://en-au.wordpress.org/plugins/stream/ @DeveloperWil #wpsyd
  • 37. WordPress’ most comprehensive real time user activity and monitoring log plugin. It helps thousands of WordPress administrators and security professionals keep an eye on what is happening on their websites. WP Security Audit Log https://wordpress.org/plugins/wp-security-audit-log/ @DeveloperWil #wpsyd
  • 39. [Front Cover] wordpress.org [32] wordpress.org [33] wordpress.org [34] wordpress.org [35] wordpress.org [36] wordpress.org [37] wordpress.org [Back Cover] zeropointdevelopment.com @DeveloperWil #wpsyd
  • 40. ▪ 20+ years in IT: Dev & SysOps ▪ WordPress Developer since 2008 ▪ Plugins, APIs, Security & Systems Integrations ▪ Organiser WPSyd & WordCamp Sydney zeropointdevelopment.com @DeveloperWil ♥ Pizza & Craft Beer @DeveloperWil #wpsyd