SlideShare a Scribd company logo
1 of 38
Download to read offline
Hans Demeyer
Supplier of Optimism & Inspiration
On GDPR
The General Data Protection Regulation
and how to maximize compliancy
• Post-world war II
• 1950 - European Declaration of Rights
• 1992 – Belgian law on personal privacy
• 1995 – European Privacy directives
• 2000-2010 – Telecommunications law, e-
commerce, additional Local directives, CLAs
• May 2016 – General Data Protection Regulation
• Grace period
• May 2018 – binding law
history
11
12
20
78
42
3
GDPR - content
General and principles
Data Subject rights
Controller responsibilities
Sending data outside the EU
Remedies
Administration
Security
Hans Demeyer
Supplier of Optimism & Inspiration
• Linkedin.com/in/hansdemeyer
• Hans@thedataprotectionoffice.eu
April 2015
“your aproach is disruptive and far better
then what the average SME delivers. Don’t
let that value get lost.”
“Finally a pragmatic and clear session on
GDPR. Thank you.”
“inspiring and ready to put into action”
“no fear, just optimism and concrete
action outlines”
B2B, B2C, Staff
What data?
Personal data (Active opt-in*)
- Name : Sophie D
- Address : street, N°,city, country
- Mail address : Sophie@Hotmail.com
- Photo
- Biometric info: fingerprints, face reco, …
- Ip-address, Mac-Address
- IQ info
- Profiling info
- Online behaviour
- Location data
- Aliases (twitter, FB, …)
- Combinations leading to potential
identification of a natural person
Sensitive data (Explicit consent)
- Sexual preferences
- Medical info
- Union choice
- Political, religious prefs
- Memberships
- National ID number
*Unless < 16
Company data, info@,
sales@, … are not GDPR
sensitive
Understanding the
impact
Data subjects
Controllers & Processors
The GDPR journey
Your
organisation
destination
Your mission
Your value prop
Value
proposition
ActivitiesPartners Customers
Cost Revenue
Resources
CRM
Channel
Marketing &
Sales
entry processing exit
Your
organisation
Your mission
Your value prop
marketing
destination
GDPR rights for citizens
How are you
processing my
data?
What personal
data do you
have?
Please correct
or add
incomplete
data
Please remove
my data
Please stop
using my data
for marketing
Opt me out for
1 specific part
of the
processing
Can I get a
copy of my
data?
I object to a
presumed
automated
decision
What do you
need my data
for?
How long do
you keep my
data
Where do you
store my
personal data?
Your
organisation
Privacy declaration
Cookies & trackers
• 1st party
• 3rd party
Only what is needed
Digital & Analogue
Your
organisation
Your mission
Your value prop
marketing
destination
Data processing – 6 grounds
1 CONSENT
• Communicated
upfront
• Clear
• Fragmented
• Recorded
• Procedure
• Motivated
• Relevant
2 CONTRACT
• All processing and
data transfert
required to fullfil
the agreement
• No additional
consent required
3 LAW
• All processing and
data transfert
required by law
• No additional
consent required
4 HEALTH
• All processing and
data transfert to
assure the health
of an individual or
group
• No additional
consent required
5 COMMON
INTEREST
• All processing and
data transfert to
assure the
common interest,
security, .. Of a
group
• No additional
consent required
6 LEGITIMATE CAUSE
• All processing and
data transfert
pondered and
motivated that
serves the
interests of the
subject and the
controller without
conflicts
When processing personal data, always
check if 1 of the 6 answers aside is
applicable
https://privacycommission.be/(nl-fr)
functionele omschrijving verwerking gebruikte gegevens en betrokkenen verwerker gegevensuitwisseling technologie risico & beveiligingsmaatregelen rechten betrokkenen status opmerking
identificatieen informatieover de verwerking
nummer, functionele omschrijving, finaliteit,
verwerkingsgrond, type verwerking en
functionelebeschrijving
details over de gegevens die verwerkt worden
en de betrokkenen van wie gegevens verwerkt
worden
functionelecategorie, gevoeligecategorie
gegevensverwerking, categoriebetrokken,
classificatieniveau, bewaartermijn, authentieke
bron
identificatievan de verwerker (extern aan
organisatie) die betrokken is bij de verwerking
naam, nr gegevensverwerkingscontract
informatieover eventuele gegevensuitwisseling
met derde partijen
categorie(ĂŤn)gegevens,categorie(ĂŤn)
ontvangers, derde land/internationale
organisatie, documenten passende waarborgen
beschrijving van de gebruikte technologie,
applicaties, software bij de verwerking
informatie over het risico en de
beveiligingsmaatregelen van de
gegevensverwerking
risico, beschrijving
beveiligingsmaatregelen, documentatie
beveiligingsmaatregelen, GEB (DPIA)
verwijzing naar de documenten die de
procedures ter respectering van de rechten van
de betrokkenen bepalen
informatieover de status van de verwerking: startdatum,
einddatum en plaatsvervangendeverwerking
noteer eventuele opmerkingen/aandachtspunten mbt de
verwerkingsactiviteit
Process
Purpose (why)
Data processed (what)
Retention (how long)
Data processor (who)
Legal ground
What technology is used?
What is the risk?
What rights could be exercised?
Status
Remarks
Be accountable – document your processes
News letter sharing
Send updates via newsletter
Name, mail address
till opt-out by customer
Marketing dpt
Consent (legitimate interest ?)
Mail chimp
low
Correct, get, opt-out, forget
Checking software & process
Ready for May 25
Job Applications & Staff
Existing
CLA’s
(61,81,82,89,…)
Check your
HR Agency
Add GDPR
‘NDA’ to
contract
GDPR processor
agreements
Your
organisation
Madrid
Your mission
Your value prop
marketing
What about security?
unlikely low medium high certain
Probability of leaks
negligableminimalsignificanthighcritical
Impactofleaks
• Respect for private and
family life, home and
communications
• Physical and mental
integrity
• Liberty and security
• Freedom of thought
• Data protection
• Freedom to work and
choose an occupation
ÂŤ Risk assessment Âť
Incidents must be reported within 72hrs
On premise
Outside (! Outside Europe)
Fixed Mobile
Security = where, what, who, when, how?
List
- devices
- software
- apps
- other?
As you see
them inside the
company and
outside the
company both
fixed and
mobile
On premise
Outside
Fixed Mobile
prints
cupboard
Who?
How?
What?
High impact
Low impact
Easy Complex
Next move
citizen Mediator
Reconcile
complaint
YES
NO
chamber
Inspection
warn
fine
classify
appeal
court
complaint
GDPR - escalation
Your
organisation Madrid
Your mission
Your value prop
marketing
Steps toward GDPR compliancy for self-employed and Small & Medium size businesses
Thank you
http://Thedataprotectionoffice.eu
hans@thedataprotectionoffice.eu
Lees onze
welkomstbrochure
The Data Protection Office
Mosseveldstraat 34 a
9290 Overmere
+32 496 16 33 01
GDPR begeleiding voor
Zelfstandigen en KMO’s
Reserveer uw
begeleiding hier
The Data Protection Office is een handelsmerk van
CT-Interactive bvba – BE0462541827
GDPR Compliance for SMEs Maximized
GDPR Compliance for SMEs Maximized
GDPR Compliance for SMEs Maximized

More Related Content

What's hot

Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR readyHarrison Clark Rickerbys
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparationPromapp Solutions
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role HackerOne
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Jean-Michel Franco
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRHans Demeyer
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersSpain-Holiday.com
 

What's hot (20)

Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 

Similar to GDPR Compliance for SMEs Maximized

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
CBC GDPR The Physics
CBC GDPR The PhysicsCBC GDPR The Physics
CBC GDPR The PhysicsJason Chapman
 
DPA seminar presentation
DPA seminar presentationDPA seminar presentation
DPA seminar presentationRodonoghue72
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital MarketersOne North
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR ComplianceAndreas Batsis
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRRichard Veryard
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR ComplianceGabor Farkas
 
Are you GDPR compliant?
Are you GDPR compliant? Are you GDPR compliant?
Are you GDPR compliant? TrekkSoft
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxTimBee1
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxTimBee1
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018Human Capital Department
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantEsendex
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceObservePoint
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Bart Van Den Brande
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticheramy_hatton
 

Similar to GDPR Compliance for SMEs Maximized (20)

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
CBC GDPR The Physics
CBC GDPR The PhysicsCBC GDPR The Physics
CBC GDPR The Physics
 
DPA seminar presentation
DPA seminar presentationDPA seminar presentation
DPA seminar presentation
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance
 
Are you GDPR compliant?
Are you GDPR compliant? Are you GDPR compliant?
Are you GDPR compliant?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticher
 

More from Hans Demeyer

Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Hans Demeyer
 
Discovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainDiscovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainHans Demeyer
 
De verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinDe verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinHans Demeyer
 
Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Hans Demeyer
 
Je brein houdt je voor de gek
Je brein houdt je voor de gekJe brein houdt je voor de gek
Je brein houdt je voor de gekHans Demeyer
 
Infographic - gdpr and smb
Infographic -  gdpr and smbInfographic -  gdpr and smb
Infographic - gdpr and smbHans Demeyer
 
Speed dating with GDPR
Speed dating with GDPRSpeed dating with GDPR
Speed dating with GDPRHans Demeyer
 
Communicate effectively
Communicate effectivelyCommunicate effectively
Communicate effectivelyHans Demeyer
 
Sustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologySustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologyHans Demeyer
 
Conversation styling
Conversation stylingConversation styling
Conversation stylingHans Demeyer
 
Conversation styling
Conversation stylingConversation styling
Conversation stylingHans Demeyer
 
Stuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProStuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProHans Demeyer
 
Challenger sales
Challenger salesChallenger sales
Challenger salesHans Demeyer
 
Vox entrepreneurs_nl
Vox entrepreneurs_nlVox entrepreneurs_nl
Vox entrepreneurs_nlHans Demeyer
 
Meer verkopen, minder babbelen
Meer verkopen, minder babbelenMeer verkopen, minder babbelen
Meer verkopen, minder babbelenHans Demeyer
 
From Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessFrom Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessHans Demeyer
 
Sales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourSales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourHans Demeyer
 
Sales training (focus on telesales)
Sales training (focus on telesales)Sales training (focus on telesales)
Sales training (focus on telesales)Hans Demeyer
 
Public speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audiencePublic speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audienceHans Demeyer
 

More from Hans Demeyer (20)

Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Shiny goals keynote (1hr)
Shiny goals keynote (1hr)
 
Discovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainDiscovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brain
 
De verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinDe verborgen schat van het piratenbrein
De verborgen schat van het piratenbrein
 
Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?
 
Je brein houdt je voor de gek
Je brein houdt je voor de gekJe brein houdt je voor de gek
Je brein houdt je voor de gek
 
Infographic - gdpr and smb
Infographic -  gdpr and smbInfographic -  gdpr and smb
Infographic - gdpr and smb
 
Speed dating with GDPR
Speed dating with GDPRSpeed dating with GDPR
Speed dating with GDPR
 
Communicate effectively
Communicate effectivelyCommunicate effectively
Communicate effectively
 
Sustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologySustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable Technology
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
 
Stuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProStuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales Pro
 
Challenger sales
Challenger salesChallenger sales
Challenger sales
 
Happiness
HappinessHappiness
Happiness
 
Vox entrepreneurs_nl
Vox entrepreneurs_nlVox entrepreneurs_nl
Vox entrepreneurs_nl
 
Meer verkopen, minder babbelen
Meer verkopen, minder babbelenMeer verkopen, minder babbelen
Meer verkopen, minder babbelen
 
From Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessFrom Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying Process
 
Sales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourSales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch Tour
 
Sales training (focus on telesales)
Sales training (focus on telesales)Sales training (focus on telesales)
Sales training (focus on telesales)
 
Public speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audiencePublic speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audience
 

Recently uploaded

Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Trucks in Minnesota
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfmuskan1121w
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
 

Recently uploaded (20)

Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdf
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 

GDPR Compliance for SMEs Maximized

  • 1. Hans Demeyer Supplier of Optimism & Inspiration On GDPR The General Data Protection Regulation and how to maximize compliancy
  • 2. • Post-world war II • 1950 - European Declaration of Rights • 1992 – Belgian law on personal privacy • 1995 – European Privacy directives • 2000-2010 – Telecommunications law, e- commerce, additional Local directives, CLAs • May 2016 – General Data Protection Regulation • Grace period • May 2018 – binding law history
  • 3. 11 12 20 78 42 3 GDPR - content General and principles Data Subject rights Controller responsibilities Sending data outside the EU Remedies Administration Security
  • 4.
  • 5.
  • 6. Hans Demeyer Supplier of Optimism & Inspiration • Linkedin.com/in/hansdemeyer • Hans@thedataprotectionoffice.eu
  • 8. “your aproach is disruptive and far better then what the average SME delivers. Don’t let that value get lost.” “Finally a pragmatic and clear session on GDPR. Thank you.” “inspiring and ready to put into action” “no fear, just optimism and concrete action outlines”
  • 9.
  • 11. What data? Personal data (Active opt-in*) - Name : Sophie D - Address : street, N°,city, country - Mail address : Sophie@Hotmail.com - Photo - Biometric info: fingerprints, face reco, … - Ip-address, Mac-Address - IQ info - Profiling info - Online behaviour - Location data - Aliases (twitter, FB, …) - Combinations leading to potential identification of a natural person Sensitive data (Explicit consent) - Sexual preferences - Medical info - Union choice - Political, religious prefs - Memberships - National ID number *Unless < 16 Company data, info@, sales@, … are not GDPR sensitive
  • 13. Data subjects Controllers & Processors The GDPR journey
  • 16. Your organisation Your mission Your value prop marketing destination
  • 17. GDPR rights for citizens How are you processing my data? What personal data do you have? Please correct or add incomplete data Please remove my data Please stop using my data for marketing Opt me out for 1 specific part of the processing Can I get a copy of my data? I object to a presumed automated decision What do you need my data for? How long do you keep my data Where do you store my personal data? Your organisation
  • 19. Cookies & trackers • 1st party • 3rd party
  • 20. Only what is needed
  • 22. Your organisation Your mission Your value prop marketing destination
  • 23. Data processing – 6 grounds 1 CONSENT • Communicated upfront • Clear • Fragmented • Recorded • Procedure • Motivated • Relevant 2 CONTRACT • All processing and data transfert required to fullfil the agreement • No additional consent required 3 LAW • All processing and data transfert required by law • No additional consent required 4 HEALTH • All processing and data transfert to assure the health of an individual or group • No additional consent required 5 COMMON INTEREST • All processing and data transfert to assure the common interest, security, .. Of a group • No additional consent required 6 LEGITIMATE CAUSE • All processing and data transfert pondered and motivated that serves the interests of the subject and the controller without conflicts When processing personal data, always check if 1 of the 6 answers aside is applicable
  • 25. functionele omschrijving verwerking gebruikte gegevens en betrokkenen verwerker gegevensuitwisseling technologie risico & beveiligingsmaatregelen rechten betrokkenen status opmerking identificatieen informatieover de verwerking nummer, functionele omschrijving, finaliteit, verwerkingsgrond, type verwerking en functionelebeschrijving details over de gegevens die verwerkt worden en de betrokkenen van wie gegevens verwerkt worden functionelecategorie, gevoeligecategorie gegevensverwerking, categoriebetrokken, classificatieniveau, bewaartermijn, authentieke bron identificatievan de verwerker (extern aan organisatie) die betrokken is bij de verwerking naam, nr gegevensverwerkingscontract informatieover eventuele gegevensuitwisseling met derde partijen categorie(ĂŤn)gegevens,categorie(ĂŤn) ontvangers, derde land/internationale organisatie, documenten passende waarborgen beschrijving van de gebruikte technologie, applicaties, software bij de verwerking informatie over het risico en de beveiligingsmaatregelen van de gegevensverwerking risico, beschrijving beveiligingsmaatregelen, documentatie beveiligingsmaatregelen, GEB (DPIA) verwijzing naar de documenten die de procedures ter respectering van de rechten van de betrokkenen bepalen informatieover de status van de verwerking: startdatum, einddatum en plaatsvervangendeverwerking noteer eventuele opmerkingen/aandachtspunten mbt de verwerkingsactiviteit Process Purpose (why) Data processed (what) Retention (how long) Data processor (who) Legal ground What technology is used? What is the risk? What rights could be exercised? Status Remarks Be accountable – document your processes News letter sharing Send updates via newsletter Name, mail address till opt-out by customer Marketing dpt Consent (legitimate interest ?) Mail chimp low Correct, get, opt-out, forget Checking software & process Ready for May 25
  • 26. Job Applications & Staff Existing CLA’s (61,81,82,89,…) Check your HR Agency Add GDPR ‘NDA’ to contract
  • 28. Your organisation Madrid Your mission Your value prop marketing What about security?
  • 29. unlikely low medium high certain Probability of leaks negligableminimalsignificanthighcritical Impactofleaks • Respect for private and family life, home and communications • Physical and mental integrity • Liberty and security • Freedom of thought • Data protection • Freedom to work and choose an occupation ÂŤ Risk assessment Âť Incidents must be reported within 72hrs
  • 30. On premise Outside (! Outside Europe) Fixed Mobile Security = where, what, who, when, how? List - devices - software - apps - other? As you see them inside the company and outside the company both fixed and mobile
  • 32. High impact Low impact Easy Complex Next move
  • 34. Your organisation Madrid Your mission Your value prop marketing Steps toward GDPR compliancy for self-employed and Small & Medium size businesses
  • 35. Thank you http://Thedataprotectionoffice.eu hans@thedataprotectionoffice.eu Lees onze welkomstbrochure The Data Protection Office Mosseveldstraat 34 a 9290 Overmere +32 496 16 33 01 GDPR begeleiding voor Zelfstandigen en KMO’s Reserveer uw begeleiding hier The Data Protection Office is een handelsmerk van CT-Interactive bvba – BE0462541827