SlideShare a Scribd company logo
1 of 22
Download to read offline
16th November 2007
EU GDPR – 58 Days to Go
Presented by Scott Simpson for IRIS
Scott Simpson
Certified GDPR Consultant
Cyber Security Consultant
Data Protection Officer
Certified ISO 27001
Lead Implementer
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
This Morning’s Objectives
CONSULTANCY | CYBER SECURITY TRAINING | TECHNOLOGIES
§ Understand the GDPR landscape
§ What compliance looks like
§ How to start your compliance project
§ Risk mitigation - what you need to do before 25th May
Commonly Used GDPR Phrases
ON WSHS (GDPR) 12MTHSAGO
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Commonly Used GDPR Phrases
Oh No -
I wish we had started
GDPR 12 months ago
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
GDPR – the new Y2K?
GDPR isn’t just another regulation
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Why GDPR is important
— Are the punitive Fines 2-4% of turnover your highest risk?
— Brand and reputational damage
— Loss of clients – current 30-40% customer requirement adoption
— Punitive Fines
— Contract clauses regarding data protection and data breach
— Business value / Share price
— Private Equity implications
— Compromising your clients’ / employees / investors personal information
— GDPR is now part of the standard Due Diligence process
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Why GDPR is important
People & businesses will
only work with businesses
they trust to protect their data
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
How GDPR has changed the landscape
— No more box-ticking compliance
— Demonstrable compliance is here to stay
— Supplier Assurance Programs - Businesses are putting their suppliers
through increased levels of due diligence for information security and
data compliance
— Organisations and their employees must handle personal and sensitive
data differently going forward
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Businesses grow faster than they mature
• Corporate Governance
• Risk Management
• Information Security Framework
• Data Protection
• Cyber Resilience / Security
• Policies & Processes
• Records Management
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
The six data processing principles
• Article 5: Principles relating to processing of personal data
• “The controller shall be responsible for, and be able to demonstrate
compliance
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Eight rights of data subjects under GDPR
1. The right to be informed
2. The right of access
3. The right to rectification
4. The right to erasure
5. The right to restrict processing
6. The right to data portability
7. The right to object
8. Rights in relation to automated decision making and profiling.
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
GDPR compliance is cultural
It is a governance not an IT issue
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
What do we have to do to be compliant?
Process personal data in accordance to the 6 Principles of the GDPR
Protect the 8 rights of data subjects
Demonstrable Compliance
Policies & Processes
Data Security & Cyber Resilience/Accreditation
Information registers:
— Corporate Risk Register
— Employee Training Register
— Data Breach Register
— Data Protection Impact Assessments Register
— Data Subject Assess Request Register
— Deleted Information Register
— (Legitimate Interest Assessment Register)
Staff Training
HR Contract Reviews
Compliant supplier contracts and GDPR due diligence
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
How to start
Assessment & Gap Analysis
Start preparing your compliance plan
Probable implementation time to become compliant 10-12 months
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
What to have completed by 25th May
1. Implement your plan on a risk based approach
2. Mitigate as much risk as soon as possible from a client & supervisory
perspective
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
The Process towards compliance
1. Gap Analysis or Assessment
2. Create a Project Team
3. Ensure Board Buy-in
4. Communications – Internal
5. Data Mapping – Inventory, Data Flow Analysis & Process Maps
6. Commence Cyber Resilience
7. Implement Gap Analysis Findings
8. Create Staff Training Programme
9. Create a Risk Management Process
10. Implement a Privacy Compliance Framework & PIMS
11. Implement Information Registers
12. Implement a Data Subject Access Request Process
13. Create and Improve Policies & Procedures
14. Implement an Incident Response Plan
15. Communications - External
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
What to have completed by 25th May
1. Have a thorough plan in place towards compliance
2. Have a project team in place
3. Gap Analysis or Assessment
4. Data Mapping – Inventory, Data Flow Analysis & Process Maps
5. Delete all data that you have no lawful basis for processing
6. Document all data processing activities that use PII
7. Conduct DPIAs for all Relevant or high risk processes in the business
8. Cyber Resilience – Cyber Essentials as a minimum
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
What to have completed by 25th May
1. Encrypt everything – Hard drives, databases, mobile devices, email
attachments
2. Create Staff Training Programme
3. Have Privacy risk on your Risk Register
4. Implement the Information Registers
5. Implement a Data Subject Access Request Process
6. Implement compliant Policies & Procedures
7. Controller/Processor Agreements in place with processors
8. Supplier GDPR due diligence
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
GDPR Implementation Process
Gap Analysis or Assessment
§ Detailed Roadmap
§ Security Review
§ Compliance Plan
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Do I really need to do this?
Clients only working with GDPR compliant firms
National GDPR Certification likely
Private Equity and investors are now taking the view that they do not want to
invest or buy any B2C business that does haven’t a GDPR Compliance Plan
For B2B businesses, it will reduce the value of the company by a minimum of 10%
Investors & PE need to know any underlying claims, impending fines, legal action
or reputational damage
GDPR is becoming part of standard Due Diligence
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
Questions?
CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES

More Related Content

What's hot

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...Giulio Coraggio
 
3 oraclex evento reg puglia_v2017-09-14-2
3 oraclex evento reg puglia_v2017-09-14-23 oraclex evento reg puglia_v2017-09-14-2
3 oraclex evento reg puglia_v2017-09-14-2Redazione InnovaPuglia
 
CIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieCIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieAndrew Pryor
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
Data Protection Forum Brussels 230517 - Implementing GDPR
Data Protection Forum Brussels 230517 - Implementing GDPRData Protection Forum Brussels 230517 - Implementing GDPR
Data Protection Forum Brussels 230517 - Implementing GDPRJohn M Walsh
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Doing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and doDoing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and doPatric Dahse
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 
HPE Security Keynote from Istanbul 20th Jan 2016
HPE Security Keynote from Istanbul 20th Jan 2016HPE Security Keynote from Istanbul 20th Jan 2016
HPE Security Keynote from Istanbul 20th Jan 2016SteveAtHPE
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers Gary Dodson
 
Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPRMissMarvel70
 
Privacy-by-design for Startups - why, what and how
Privacy-by-design for Startups - why, what and howPrivacy-by-design for Startups - why, what and how
Privacy-by-design for Startups - why, what and howPrivacyRoad
 
Convince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XConvince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XDave James
 
How is GDPR relevant for US companies
How is GDPR relevant for US companies How is GDPR relevant for US companies
How is GDPR relevant for US companies Patric Dahse
 
Industry 4.0 : How to Build Relevant IT Skills
Industry 4.0 : How to Build Relevant IT SkillsIndustry 4.0 : How to Build Relevant IT Skills
Industry 4.0 : How to Build Relevant IT SkillsEryk Budi Pratama
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Iron Mountain
 
Safeguarding Your Brand With Secure IT Asset Disposition
Safeguarding Your Brand With Secure IT Asset DispositionSafeguarding Your Brand With Secure IT Asset Disposition
Safeguarding Your Brand With Secure IT Asset DispositionIron Mountain
 

What's hot (20)

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
 
3 oraclex evento reg puglia_v2017-09-14-2
3 oraclex evento reg puglia_v2017-09-14-23 oraclex evento reg puglia_v2017-09-14-2
3 oraclex evento reg puglia_v2017-09-14-2
 
CIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieCIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James Duthie
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
Data Protection Forum Brussels 230517 - Implementing GDPR
Data Protection Forum Brussels 230517 - Implementing GDPRData Protection Forum Brussels 230517 - Implementing GDPR
Data Protection Forum Brussels 230517 - Implementing GDPR
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Doing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and doDoing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and do
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
HPE Security Keynote from Istanbul 20th Jan 2016
HPE Security Keynote from Istanbul 20th Jan 2016HPE Security Keynote from Istanbul 20th Jan 2016
HPE Security Keynote from Istanbul 20th Jan 2016
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
 
Data Privacy and Canadian Anti-Spam Law
Data Privacy and Canadian Anti-Spam LawData Privacy and Canadian Anti-Spam Law
Data Privacy and Canadian Anti-Spam Law
 
IP 101 for Emerging Companies
IP 101 for Emerging Companies IP 101 for Emerging Companies
IP 101 for Emerging Companies
 
Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPR
 
Privacy-by-design for Startups - why, what and how
Privacy-by-design for Startups - why, what and howPrivacy-by-design for Startups - why, what and how
Privacy-by-design for Startups - why, what and how
 
Convince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XConvince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List X
 
How is GDPR relevant for US companies
How is GDPR relevant for US companies How is GDPR relevant for US companies
How is GDPR relevant for US companies
 
Industry 4.0 : How to Build Relevant IT Skills
Industry 4.0 : How to Build Relevant IT SkillsIndustry 4.0 : How to Build Relevant IT Skills
Industry 4.0 : How to Build Relevant IT Skills
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
 
Safeguarding Your Brand With Secure IT Asset Disposition
Safeguarding Your Brand With Secure IT Asset DispositionSafeguarding Your Brand With Secure IT Asset Disposition
Safeguarding Your Brand With Secure IT Asset Disposition
 

Similar to Whos role is it anyway

Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017Match-Maker Ventures
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceMongoDB
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesDimitri Sirota
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPRJuan Niekerk
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPRJuan Niekerk
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Complianceaccenture
 
A successful GDPR Program
A successful GDPR ProgramA successful GDPR Program
A successful GDPR ProgramAlberto Canadè
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]TrustArc
 
DEFeND Project Presentation - July 2018
DEFeND Project Presentation - July 2018DEFeND Project Presentation - July 2018
DEFeND Project Presentation - July 2018DEFeND Project
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe
 
Common Practice in Data Privacy Program Management
Common Practice in Data Privacy Program ManagementCommon Practice in Data Privacy Program Management
Common Practice in Data Privacy Program ManagementEryk Budi Pratama
 
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRMatt Stubbs
 
GDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsGDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsRevulytics Inc.
 
Ciso round table on effective implementation of dlp & data security
Ciso round table on effective implementation of dlp & data securityCiso round table on effective implementation of dlp & data security
Ciso round table on effective implementation of dlp & data securityPriyanka Aash
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 

Similar to Whos role is it anyway (20)

Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPR
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPR
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 
A successful GDPR Program
A successful GDPR ProgramA successful GDPR Program
A successful GDPR Program
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
DEFeND Project Presentation - July 2018
DEFeND Project Presentation - July 2018DEFeND Project Presentation - July 2018
DEFeND Project Presentation - July 2018
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance Primer
 
Common Practice in Data Privacy Program Management
Common Practice in Data Privacy Program ManagementCommon Practice in Data Privacy Program Management
Common Practice in Data Privacy Program Management
 
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPR
 
GDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsGDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage Analytics
 
Ciso round table on effective implementation of dlp & data security
Ciso round table on effective implementation of dlp & data securityCiso round table on effective implementation of dlp & data security
Ciso round table on effective implementation of dlp & data security
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Cv jagroop jagpal
Cv jagroop jagpalCv jagroop jagpal
Cv jagroop jagpal
 

More from IRIS

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS
 
HMRC
HMRCHMRC
HMRCIRIS
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdprIRIS
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burdenIRIS
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedIRIS
 
Happy clients happy compliance
Happy clients happy complianceHappy clients happy compliance
Happy clients happy complianceIRIS
 
Game changing legislation
Game changing legislationGame changing legislation
Game changing legislationIRIS
 

More from IRIS (10)

IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 3 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 4 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital EconomyIRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
IRIS World 2018 - Keynote 2 - Thrive in the Digital Economy
 
IRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital EconomyIRIS World 2018 - Keynote - Thrive in the Digital Economy
IRIS World 2018 - Keynote - Thrive in the Digital Economy
 
HMRC
HMRCHMRC
HMRC
 
Software impact of gdpr
Software impact of gdprSoftware impact of gdpr
Software impact of gdpr
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
Don't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint heartedDon't panic - cyber security for the faint hearted
Don't panic - cyber security for the faint hearted
 
Happy clients happy compliance
Happy clients happy complianceHappy clients happy compliance
Happy clients happy compliance
 
Game changing legislation
Game changing legislationGame changing legislation
Game changing legislation
 

Recently uploaded

Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111Sapana Sha
 
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With RoomVIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Roomdivyansh0kumar0
 
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
20240417-Calibre-April-2024-Investor-Presentation.pdf
20240417-Calibre-April-2024-Investor-Presentation.pdf20240417-Calibre-April-2024-Investor-Presentation.pdf
20240417-Calibre-April-2024-Investor-Presentation.pdfAdnet Communications
 
VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...
VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...
VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...Suhani Kapoor
 
VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...Suhani Kapoor
 
VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...
VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...
VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...Suhani Kapoor
 
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure serviceCall US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure servicePooja Nehwal
 
Stock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdfStock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdfMichael Silva
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignHenry Tapper
 
The Economic History of the U.S. Lecture 17.pdf
The Economic History of the U.S. Lecture 17.pdfThe Economic History of the U.S. Lecture 17.pdf
The Economic History of the U.S. Lecture 17.pdfGale Pooley
 
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service AizawlVip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawlmakika9823
 
Quarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingQuarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingMaristelaRamos12
 
Instant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School SpiritInstant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School Spiritegoetzinger
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escortsranjana rawat
 
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Delhi Call girls
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex
 

Recently uploaded (20)

Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111
 
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With RoomVIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Room
 
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
20240417-Calibre-April-2024-Investor-Presentation.pdf
20240417-Calibre-April-2024-Investor-Presentation.pdf20240417-Calibre-April-2024-Investor-Presentation.pdf
20240417-Calibre-April-2024-Investor-Presentation.pdf
 
VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...
VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...
VIP Call Girls in Saharanpur Aarohi 8250192130 Independent Escort Service Sah...
 
VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Saharanpur Anushka 8250192130 Independent Escort Se...
 
VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...
VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...
VIP Call Girls LB Nagar ( Hyderabad ) Phone 8250192130 | ₹5k To 25k With Room...
 
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure serviceCall US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
Call US 📞 9892124323 ✅ Kurla Call Girls In Kurla ( Mumbai ) secure service
 
Stock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdfStock Market Brief Deck for 4/24/24 .pdf
Stock Market Brief Deck for 4/24/24 .pdf
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaign
 
The Economic History of the U.S. Lecture 17.pdf
The Economic History of the U.S. Lecture 17.pdfThe Economic History of the U.S. Lecture 17.pdf
The Economic History of the U.S. Lecture 17.pdf
 
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service AizawlVip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
 
Quarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingQuarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of Marketing
 
Instant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School SpiritInstant Issue Debit Cards - High School Spirit
Instant Issue Debit Cards - High School Spirit
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
 
Monthly Economic Monitoring of Ukraine No 231, April 2024
Monthly Economic Monitoring of Ukraine No 231, April 2024Monthly Economic Monitoring of Ukraine No 231, April 2024
Monthly Economic Monitoring of Ukraine No 231, April 2024
 
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
 
Veritas Interim Report 1 January–31 March 2024
Veritas Interim Report 1 January–31 March 2024Veritas Interim Report 1 January–31 March 2024
Veritas Interim Report 1 January–31 March 2024
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024
 

Whos role is it anyway

  • 1. 16th November 2007 EU GDPR – 58 Days to Go Presented by Scott Simpson for IRIS
  • 2. Scott Simpson Certified GDPR Consultant Cyber Security Consultant Data Protection Officer Certified ISO 27001 Lead Implementer CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 3. This Morning’s Objectives CONSULTANCY | CYBER SECURITY TRAINING | TECHNOLOGIES § Understand the GDPR landscape § What compliance looks like § How to start your compliance project § Risk mitigation - what you need to do before 25th May
  • 4. Commonly Used GDPR Phrases ON WSHS (GDPR) 12MTHSAGO CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 5. Commonly Used GDPR Phrases Oh No - I wish we had started GDPR 12 months ago CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 6. GDPR – the new Y2K? GDPR isn’t just another regulation CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 7. Why GDPR is important — Are the punitive Fines 2-4% of turnover your highest risk? — Brand and reputational damage — Loss of clients – current 30-40% customer requirement adoption — Punitive Fines — Contract clauses regarding data protection and data breach — Business value / Share price — Private Equity implications — Compromising your clients’ / employees / investors personal information — GDPR is now part of the standard Due Diligence process CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 8. Why GDPR is important People & businesses will only work with businesses they trust to protect their data CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 9. How GDPR has changed the landscape — No more box-ticking compliance — Demonstrable compliance is here to stay — Supplier Assurance Programs - Businesses are putting their suppliers through increased levels of due diligence for information security and data compliance — Organisations and their employees must handle personal and sensitive data differently going forward CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 10. Businesses grow faster than they mature • Corporate Governance • Risk Management • Information Security Framework • Data Protection • Cyber Resilience / Security • Policies & Processes • Records Management CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 11. The six data processing principles • Article 5: Principles relating to processing of personal data • “The controller shall be responsible for, and be able to demonstrate compliance CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 12. Eight rights of data subjects under GDPR 1. The right to be informed 2. The right of access 3. The right to rectification 4. The right to erasure 5. The right to restrict processing 6. The right to data portability 7. The right to object 8. Rights in relation to automated decision making and profiling. CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 13. GDPR compliance is cultural It is a governance not an IT issue CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 14. What do we have to do to be compliant? Process personal data in accordance to the 6 Principles of the GDPR Protect the 8 rights of data subjects Demonstrable Compliance Policies & Processes Data Security & Cyber Resilience/Accreditation Information registers: — Corporate Risk Register — Employee Training Register — Data Breach Register — Data Protection Impact Assessments Register — Data Subject Assess Request Register — Deleted Information Register — (Legitimate Interest Assessment Register) Staff Training HR Contract Reviews Compliant supplier contracts and GDPR due diligence CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 15. How to start Assessment & Gap Analysis Start preparing your compliance plan Probable implementation time to become compliant 10-12 months CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 16. What to have completed by 25th May 1. Implement your plan on a risk based approach 2. Mitigate as much risk as soon as possible from a client & supervisory perspective CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 17. The Process towards compliance 1. Gap Analysis or Assessment 2. Create a Project Team 3. Ensure Board Buy-in 4. Communications – Internal 5. Data Mapping – Inventory, Data Flow Analysis & Process Maps 6. Commence Cyber Resilience 7. Implement Gap Analysis Findings 8. Create Staff Training Programme 9. Create a Risk Management Process 10. Implement a Privacy Compliance Framework & PIMS 11. Implement Information Registers 12. Implement a Data Subject Access Request Process 13. Create and Improve Policies & Procedures 14. Implement an Incident Response Plan 15. Communications - External CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 18. What to have completed by 25th May 1. Have a thorough plan in place towards compliance 2. Have a project team in place 3. Gap Analysis or Assessment 4. Data Mapping – Inventory, Data Flow Analysis & Process Maps 5. Delete all data that you have no lawful basis for processing 6. Document all data processing activities that use PII 7. Conduct DPIAs for all Relevant or high risk processes in the business 8. Cyber Resilience – Cyber Essentials as a minimum CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 19. What to have completed by 25th May 1. Encrypt everything – Hard drives, databases, mobile devices, email attachments 2. Create Staff Training Programme 3. Have Privacy risk on your Risk Register 4. Implement the Information Registers 5. Implement a Data Subject Access Request Process 6. Implement compliant Policies & Procedures 7. Controller/Processor Agreements in place with processors 8. Supplier GDPR due diligence CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 20. GDPR Implementation Process Gap Analysis or Assessment § Detailed Roadmap § Security Review § Compliance Plan CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 21. Do I really need to do this? Clients only working with GDPR compliant firms National GDPR Certification likely Private Equity and investors are now taking the view that they do not want to invest or buy any B2C business that does haven’t a GDPR Compliance Plan For B2B businesses, it will reduce the value of the company by a minimum of 10% Investors & PE need to know any underlying claims, impending fines, legal action or reputational damage GDPR is becoming part of standard Due Diligence CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES
  • 22. Questions? CONSULTANCY | AUDITING | TRAINING | TECHNOLOGIES