SlideShare a Scribd company logo
1 of 18
Download to read offline
EU GENERAL DATA PROTECTION
REGULATIONS (GDPR) – FIRST STEPS
qGDPR replaces Directive 95/46/EC
and builds on existing DPA 1998
qDesigned to give individuals more
control over the use of their personal
data
qExplicitly shifts emphasis onto data
controllers demonstrating
compliance
qSpecific obligation on data
processors
qChanges in the way the organisation
process personal data
The EU General Data Protection
Regulation (GDPR) is the most
important change in data privacy
regulation in 20 years.
TIME UNTIL GDPR ENFORCEMENT:
42 days and counting…
3
qApplies to activities which an organisation
does which amounts to the:
q‘Processing’ of ‘Personal Data’ (PD) of a natural
person (living individual)
Changes?
qGDPR definitions/scope are wider
qMain aim to protect rights of individuals – more
rights
qProcessor has defined obligations
qExcessive fines for not complying with GDPR
WHICH ORGANISATIONS?
Likely to apply to all organisations
4
q“Personal data” means: any information
relating to an identified or identifiable
natural person ("data subject");
qIncludes:
Name, Address, Location data, Online identifiers,
Cookies, IP address, any factor specific to the
physical, physiological, genetic, mental, economic,
cultural or social identity of that person.
PERSONAL DATA
Name: Laura Kao
Born: 22.06.86
Student ID: 6715
22 Loft Road etc.
j.chan@email.com
British
Buddhist
Partially sighted
Blood Group: A
Laura Kao’s photo
5
q"Processing" means any operation or set of
operations performed upon personal data
or sets of personal data, whether or not by
automated means, such as:
Collection, recording, organisation, storage …
erasure or destruction
qIncludes everything – also misuse of information
PROCESSING
6
“Controller" means the natural or legal person, public authority,
agency or any other body which alone or jointly with others
determines the purposes and means of the
processing of personal data…;
Examples:
q A bank collects the data of its clients when they open an
account.
q A law firm collects data when opening a client’s file.
q A retail outlet collects data to provide a customer with an
online receipt.
CONTROLLER
7
“Natural or legal person, public authority, agency or
other body which processes personal data on behalf
of the controller”
qData centres; Document management companies; or Any
company which is outsourced to do work on behalf of the
Controller
Wider responsibilities:
q Processor can be liable for damage under the contract with Controller –
if does not act upon instructions
q Processor must maintain records re: processing of Personal data.
q Processor to provide Controller with guarantees that it is GDPR
compliant
PROCESSOR
9
qRight to be informed regarding their PD
qRight to have access to their PD – ‘SAR’
qRight to rectify their PD
qRight to have their PD deleted – ‘right to be
forgotten’
qRight to restrict processing
qRight to data portability
qRight to object to automated decision
making, marketing and profiling
GDPR – GREATER RIGHTS TO INDIVIDUALS
Controller Data Subjects
10
RISKS
Once the personal data has been obtained…
Risks!
Risks!
Risks!
Loss of personal data
11
q10 million Euro or 2% of the gross annual turnover for the
preceding year
q20 million EURO or 4% of gross annual global turnover
NON-COMPLIANCE – FINES!
12
Training and Awareness
qStaff must be trained both on
law, policies and procedure
qThis applies also to directors
and stakeholders
STEPS TOWARDS COMPLIANCE
13
Know what data you have, where it came from and
who you are sharing it with, why are you sharing
qWhere is the data you process and how are they
protected?
qWho provides the data?
qLawful processing conditions?
qWho do you share data with? Purpose? Security ?
qAre the key principles being complied with?
INFORMATION AUDIT
14
qProtecting CIA (confidentiality, Integrity and Availability) of data
qTrain staff on their roles and responsibilities
qDesign security control based on risk assessment.
qFollow ‘Need to Know’ and ‘Least Privilege’ principle for access
control
qHave appropriate technical and organisational measure
qEnsure ‘Accountability’ for all actions
qSecurity by Design & default and DPIA
SECURE PROCESSING
15
qPrivacy Notice, Information Security, Data Protection, AUP
qConsent Procedure and Withdrawal – remember children!
qSAR procedure, notices and record, complaint procedure
qData Portability Procedure
qData Protection Notification Breach
qSub-contracting Processing, Data Protection Assessment
POLICIES, NOTICES, PROCEDURES UPDATE
16
qPolicies/procedures
qEmployees awareness
qInternal Reporting Procedure
qBreach Management Process
qBreach high risk ?
qReport to Supervisory Authority/ICO
qIf risk is high to individual then Controller must report to
Data Subject/s without undue delay
DATA BREACH NOTIFICATION
17
Potential Benefits
qIncreased customer trust /
loyalty
qClean House
qIncreased level of security
qPositive effect on brand
qIncreased revenue potential
qReal business driver
BENEFITS AND IMPACTS OF GDPR
Impact of Non-Compliance
qFinancial Penalty from ICO
qOther financial loss i.e loss
of revenue, incident
management cost
qImpact to data subject
qReputational impact
qOrganisational Risk
THANK YOU
More information about QA’s Cyber Practice can be found at qa.com/cyber
More information about QA’s GDPR courses can be found at qa.com/GDPR

More Related Content

What's hot

What's hot (20)

GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
5 Signs Your Privacy Management Program is Not Working for You
5 Signs Your Privacy Management Program is Not Working for You5 Signs Your Privacy Management Program is Not Working for You
5 Signs Your Privacy Management Program is Not Working for You
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017
 
Tech Connect Live 30th May 2018 ,GDPR Summit John Ghent
Tech Connect Live 30th May 2018 ,GDPR Summit John GhentTech Connect Live 30th May 2018 ,GDPR Summit John Ghent
Tech Connect Live 30th May 2018 ,GDPR Summit John Ghent
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
GDPR, WordPress and You.
GDPR, WordPress and You.GDPR, WordPress and You.
GDPR, WordPress and You.
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
A very clear gdpr story for normal people
A very clear gdpr story for normal peopleA very clear gdpr story for normal people
A very clear gdpr story for normal people
 

Similar to Happy clients happy compliance

Similar to Happy clients happy compliance (20)

GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
Analytics in Action - Data Protection
Analytics in Action - Data ProtectionAnalytics in Action - Data Protection
Analytics in Action - Data Protection
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdf
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
How GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneHow GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect Everyone
 
The Role of GDPR in Customer Identity and Access Management
The Role of GDPR in Customer Identity and Access ManagementThe Role of GDPR in Customer Identity and Access Management
The Role of GDPR in Customer Identity and Access Management
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
Living with gdpr
Living with gdprLiving with gdpr
Living with gdpr
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 

More from IRIS

Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint hearted
IRIS
 

More from IRIS (10)

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital Economy
 
HMRC
HMRCHMRC
HMRC
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdpr
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint hearted
 
Game changing legislation
Game changing legislationGame changing legislation
Game changing legislation
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
 

Recently uploaded

Call Girls in Yamuna Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
Call Girls in  Yamuna Vihar  (delhi) call me [🔝9953056974🔝] escort service 24X7Call Girls in  Yamuna Vihar  (delhi) call me [🔝9953056974🔝] escort service 24X7
Call Girls in Yamuna Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 

Recently uploaded (20)

7 tips trading Deriv Accumulator Options
7 tips trading Deriv Accumulator Options7 tips trading Deriv Accumulator Options
7 tips trading Deriv Accumulator Options
 
7 steps to achieve financial freedom.pdf
7 steps to achieve financial freedom.pdf7 steps to achieve financial freedom.pdf
7 steps to achieve financial freedom.pdf
 
GIFT City Overview India's Gateway to Global Finance
GIFT City Overview  India's Gateway to Global FinanceGIFT City Overview  India's Gateway to Global Finance
GIFT City Overview India's Gateway to Global Finance
 
Call Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budgetCall Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budget
 
Mahendragarh Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
Mahendragarh Escorts 🥰 8617370543 Call Girls Offer VIP Hot GirlsMahendragarh Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
Mahendragarh Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
 
Webinar on E-Invoicing for Fintech Belgium
Webinar on E-Invoicing for Fintech BelgiumWebinar on E-Invoicing for Fintech Belgium
Webinar on E-Invoicing for Fintech Belgium
 
Escorts Indore Call Girls-9155612368-Vijay Nagar Decent Fantastic Call Girls ...
Escorts Indore Call Girls-9155612368-Vijay Nagar Decent Fantastic Call Girls ...Escorts Indore Call Girls-9155612368-Vijay Nagar Decent Fantastic Call Girls ...
Escorts Indore Call Girls-9155612368-Vijay Nagar Decent Fantastic Call Girls ...
 
cost-volume-profit analysis.ppt(managerial accounting).pptx
cost-volume-profit analysis.ppt(managerial accounting).pptxcost-volume-profit analysis.ppt(managerial accounting).pptx
cost-volume-profit analysis.ppt(managerial accounting).pptx
 
Call Girls in Yamuna Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
Call Girls in  Yamuna Vihar  (delhi) call me [🔝9953056974🔝] escort service 24X7Call Girls in  Yamuna Vihar  (delhi) call me [🔝9953056974🔝] escort service 24X7
Call Girls in Yamuna Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
 
Explore Dual Citizenship in Africa | Citizenship Benefits & Requirements
Explore Dual Citizenship in Africa | Citizenship Benefits & RequirementsExplore Dual Citizenship in Africa | Citizenship Benefits & Requirements
Explore Dual Citizenship in Africa | Citizenship Benefits & Requirements
 
2999,Vashi Fantastic Ellete Call Girls📞📞9833754194 CBD Belapur Genuine Call G...
2999,Vashi Fantastic Ellete Call Girls📞📞9833754194 CBD Belapur Genuine Call G...2999,Vashi Fantastic Ellete Call Girls📞📞9833754194 CBD Belapur Genuine Call G...
2999,Vashi Fantastic Ellete Call Girls📞📞9833754194 CBD Belapur Genuine Call G...
 
Famous No1 Amil Baba Love marriage Astrologer Specialist Expert In Pakistan a...
Famous No1 Amil Baba Love marriage Astrologer Specialist Expert In Pakistan a...Famous No1 Amil Baba Love marriage Astrologer Specialist Expert In Pakistan a...
Famous No1 Amil Baba Love marriage Astrologer Specialist Expert In Pakistan a...
 
Call Girls in Benson Town / 8250092165 Genuine Call girls with real Photos an...
Call Girls in Benson Town / 8250092165 Genuine Call girls with real Photos an...Call Girls in Benson Town / 8250092165 Genuine Call girls with real Photos an...
Call Girls in Benson Town / 8250092165 Genuine Call girls with real Photos an...
 
W.D. Gann Theory Complete Information.pdf
W.D. Gann Theory Complete Information.pdfW.D. Gann Theory Complete Information.pdf
W.D. Gann Theory Complete Information.pdf
 
Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...
Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...
Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...
 
Pension dashboards forum 1 May 2024 (1).pdf
Pension dashboards forum 1 May 2024 (1).pdfPension dashboards forum 1 May 2024 (1).pdf
Pension dashboards forum 1 May 2024 (1).pdf
 
Kopar Khairane Cheapest Call Girls✔✔✔9833754194 Nerul Premium Call Girls-Navi...
Kopar Khairane Cheapest Call Girls✔✔✔9833754194 Nerul Premium Call Girls-Navi...Kopar Khairane Cheapest Call Girls✔✔✔9833754194 Nerul Premium Call Girls-Navi...
Kopar Khairane Cheapest Call Girls✔✔✔9833754194 Nerul Premium Call Girls-Navi...
 
Solution Manual For Financial Statement Analysis, 13th Edition By Charles H. ...
Solution Manual For Financial Statement Analysis, 13th Edition By Charles H. ...Solution Manual For Financial Statement Analysis, 13th Edition By Charles H. ...
Solution Manual For Financial Statement Analysis, 13th Edition By Charles H. ...
 
Business Principles, Tools, and Techniques in Participating in Various Types...
Business Principles, Tools, and Techniques  in Participating in Various Types...Business Principles, Tools, and Techniques  in Participating in Various Types...
Business Principles, Tools, and Techniques in Participating in Various Types...
 
Kurla Capable Call Girls ,07506202331, Sion Affordable Call Girls
Kurla Capable Call Girls ,07506202331, Sion Affordable Call GirlsKurla Capable Call Girls ,07506202331, Sion Affordable Call Girls
Kurla Capable Call Girls ,07506202331, Sion Affordable Call Girls
 

Happy clients happy compliance

  • 1. EU GENERAL DATA PROTECTION REGULATIONS (GDPR) – FIRST STEPS
  • 2. qGDPR replaces Directive 95/46/EC and builds on existing DPA 1998 qDesigned to give individuals more control over the use of their personal data qExplicitly shifts emphasis onto data controllers demonstrating compliance qSpecific obligation on data processors qChanges in the way the organisation process personal data The EU General Data Protection Regulation (GDPR) is the most important change in data privacy regulation in 20 years. TIME UNTIL GDPR ENFORCEMENT: 42 days and counting…
  • 3. 3 qApplies to activities which an organisation does which amounts to the: q‘Processing’ of ‘Personal Data’ (PD) of a natural person (living individual) Changes? qGDPR definitions/scope are wider qMain aim to protect rights of individuals – more rights qProcessor has defined obligations qExcessive fines for not complying with GDPR WHICH ORGANISATIONS? Likely to apply to all organisations
  • 4. 4 q“Personal data” means: any information relating to an identified or identifiable natural person ("data subject"); qIncludes: Name, Address, Location data, Online identifiers, Cookies, IP address, any factor specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person. PERSONAL DATA Name: Laura Kao Born: 22.06.86 Student ID: 6715 22 Loft Road etc. j.chan@email.com British Buddhist Partially sighted Blood Group: A Laura Kao’s photo
  • 5. 5 q"Processing" means any operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as: Collection, recording, organisation, storage … erasure or destruction qIncludes everything – also misuse of information PROCESSING
  • 6. 6 “Controller" means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data…; Examples: q A bank collects the data of its clients when they open an account. q A law firm collects data when opening a client’s file. q A retail outlet collects data to provide a customer with an online receipt. CONTROLLER
  • 7. 7 “Natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller” qData centres; Document management companies; or Any company which is outsourced to do work on behalf of the Controller Wider responsibilities: q Processor can be liable for damage under the contract with Controller – if does not act upon instructions q Processor must maintain records re: processing of Personal data. q Processor to provide Controller with guarantees that it is GDPR compliant PROCESSOR
  • 8.
  • 9. 9 qRight to be informed regarding their PD qRight to have access to their PD – ‘SAR’ qRight to rectify their PD qRight to have their PD deleted – ‘right to be forgotten’ qRight to restrict processing qRight to data portability qRight to object to automated decision making, marketing and profiling GDPR – GREATER RIGHTS TO INDIVIDUALS Controller Data Subjects
  • 10. 10 RISKS Once the personal data has been obtained… Risks! Risks! Risks! Loss of personal data
  • 11. 11 q10 million Euro or 2% of the gross annual turnover for the preceding year q20 million EURO or 4% of gross annual global turnover NON-COMPLIANCE – FINES!
  • 12. 12 Training and Awareness qStaff must be trained both on law, policies and procedure qThis applies also to directors and stakeholders STEPS TOWARDS COMPLIANCE
  • 13. 13 Know what data you have, where it came from and who you are sharing it with, why are you sharing qWhere is the data you process and how are they protected? qWho provides the data? qLawful processing conditions? qWho do you share data with? Purpose? Security ? qAre the key principles being complied with? INFORMATION AUDIT
  • 14. 14 qProtecting CIA (confidentiality, Integrity and Availability) of data qTrain staff on their roles and responsibilities qDesign security control based on risk assessment. qFollow ‘Need to Know’ and ‘Least Privilege’ principle for access control qHave appropriate technical and organisational measure qEnsure ‘Accountability’ for all actions qSecurity by Design & default and DPIA SECURE PROCESSING
  • 15. 15 qPrivacy Notice, Information Security, Data Protection, AUP qConsent Procedure and Withdrawal – remember children! qSAR procedure, notices and record, complaint procedure qData Portability Procedure qData Protection Notification Breach qSub-contracting Processing, Data Protection Assessment POLICIES, NOTICES, PROCEDURES UPDATE
  • 16. 16 qPolicies/procedures qEmployees awareness qInternal Reporting Procedure qBreach Management Process qBreach high risk ? qReport to Supervisory Authority/ICO qIf risk is high to individual then Controller must report to Data Subject/s without undue delay DATA BREACH NOTIFICATION
  • 17. 17 Potential Benefits qIncreased customer trust / loyalty qClean House qIncreased level of security qPositive effect on brand qIncreased revenue potential qReal business driver BENEFITS AND IMPACTS OF GDPR Impact of Non-Compliance qFinancial Penalty from ICO qOther financial loss i.e loss of revenue, incident management cost qImpact to data subject qReputational impact qOrganisational Risk
  • 18. THANK YOU More information about QA’s Cyber Practice can be found at qa.com/cyber More information about QA’s GDPR courses can be found at qa.com/GDPR