SlideShare a Scribd company logo
1 of 36
Download to read offline
© IT Governance Ltd 2018
Presenter:StefanieRetfalvi,LearningDesign&SolutionsConsultant,ITGovernance
GDPR Compliance:
Getting Everyone On Board
© IT Governance Ltd 2018
Agenda
01
02
03
04
06
07
?
Q&A
05
Cyber Security
Awareness
Programme
GDPR Compliance:
Getting Everyone
on board
About IT Governance
& Introduction
© IT Governance Ltd 2018
About IT Governance
© IT Governance Ltd 2018
Introduction
• Stefanie Ildiko RETFALVI
• Learning Design & Solutions Consultant
• International cross-sector experience
© IT Governance Ltd 2018
Staff Awareness &
The GDPR
© IT Governance Ltd 2018
Article 36
1. (b) to monitor compliance with this Regulation, with other
Union or Member State data protection provisions and with
the policies of the controller or processor in relation to the
protection of personal data, including the assignment of
responsibilities, awareness-raising and training of staff
involved in processing operations, and the related audits;
“
© IT Governance Ltd 2018
Why it matters
ICO publication:
Preparing for the General Data Protection
Regulation (GDPR): 12 steps to take now
© IT Governance Ltd 2018
Stakeholders, Focus
Groups & Planning
© IT Governance Ltd 2018
Compliance affects Everyone
• C-Suite, senior management buy-in
(leading by example)
• DPOs, CISOs, CIOs
• Business process owners
• HR, change management, internal comms
• Focus groups
• Surveys
© IT Governance Ltd 2018
Managing Change
© IT Governance Ltd 2018
Dealing with resistance
Aversion to change
is natural
Resistance to Content
versus
Resistance to Process Consider this question
within your
organisational context
© IT Governance Ltd 2018
• Understand your audience(s)
• Align your strategy and your culture
• Read and rewrite the context
• Make use of proven engagement techniques
• Be opportunistic
Managing the Transition
© IT Governance Ltd 2018
To attain the highest levels of employee
engagement, it is important to generate
personal investment and motivation for
adopting the GDPR.
“
Bringing about a Change in Mindset
© IT Governance Ltd 2018
Common Challenges
© IT Governance Ltd 2018
The GDPR as a focal subject
• Viewed as dry
• Perceived as overwhelming
• Misconceptions (regarding
implications)
© IT Governance Ltd 2018
Training Audit Trail
True Engagement &
Behaviour Change
© IT Governance Ltd 2018
Proven Techniques
& Solutions
© IT Governance Ltd 2018
Identifying Problems
Identifying common drivers for
resistance or gaps in understanding
is the first step to gaining
organisation-wide buy-in.
“
© IT Governance Ltd 2018
Implementing a GDPR Awareness Programme
It is important to offer a
modern mix of different
GDPR-focused learning and
communications tools to
address individuals’ diverse
needs and preferences.
“
© IT Governance Ltd 2018
Gaining Buy-In
Don’t treat GDPR awareness
training like a bitter medicine
that everyone needs to swallow.
“
© IT Governance Ltd 2018
Example
© IT Governance Ltd 2018
Delivering Knowledge
Understanding the GDPR will help to
mitigate aversion to change and
reduce the human factor as a risk.
“
© IT Governance Ltd 2018
Example
© IT Governance Ltd 2018
Encouraging Knowledge Transfer to the Workplace
It is not enough to know what best
practice involves. Employees need
to apply their obtained knowledge in
their everyday activities.
“
© IT Governance Ltd 2018
Sample Solution
These should:
• Be meaningful, encouraging deep reflection and the transfer
of acquired knowledge to the workplace;
• Make learners active participants by challenging them to
recall key information in relevant contexts; and
• Prompt participants to identify risks and apply best practice
in situations that could arise in real life on the job.
© IT Governance Ltd 2018
Example
© IT Governance Ltd 2018
Continual monitoring of progress will
ensure that everyone has achieved
the required level of knowledge and
understanding.
“
Evaluation
© IT Governance Ltd 2018
Example
© IT Governance Ltd 2018
Once the programme is finished, it is
important to ensure that the GDPR
remains at the forefront of
individuals’ minds.
“
Continual Reinforcement
© IT Governance Ltd 2018
Useful References
© IT Governance Ltd 2018
Useful References
“GDPR in the workplace”
“Employee communication”
“Change management”
https://www.cipd.co.uk/
http://www.wfpma.com/
https://ico.org.uk/about-the-ico/what-we-do/taking-action-data-
protection/
https://www.itgovernance.co.uk/blog
© IT Governance Ltd 2018
Conclusion &
Your turn! Q&A
© IT Governance Ltd 2018
Conclusion
© IT Governance Ltd 2018
Call us
+44 (0)333 800 7000
Email us
servicecentre@itgovernance.co.uk
Visit our website
www.itgovernance.co.uk
Like us on Facebook
/ITGovernanceLtd
Follow us on Twitter
/itgovernance
Join us on LinkedIn
/company/it-governance
Read our blog
www.itgovernance.co.uk/blog
Stay in touch!
© IT Governance Ltd 2018
Queries?
Understanding?
Clarification?
Your Turn!

More Related Content

What's hot

Risk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR complianceRisk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR complianceIT Governance Ltd
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...IT Governance Ltd
 
It security iso 27001
It security iso 27001It security iso 27001
It security iso 27001Iris Maaß
 
MCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationWilliam McBorrough
 
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...IT Governance Ltd
 
Gdpr data p rotection
Gdpr data p rotectionGdpr data p rotection
Gdpr data p rotectionFileOM
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance IT Governance Ltd
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceIT Governance Ltd
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data GovernanceDATUM LLC
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRIT Governance Ltd
 
Legal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services SectorLegal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services SectorMSpadea
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?PECB
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrityAxon Lawyers
 
Business Continuity requires a Security Architecture to reduce risk and cost
Business Continuity requires a Security Architecture to reduce risk and costBusiness Continuity requires a Security Architecture to reduce risk and cost
Business Continuity requires a Security Architecture to reduce risk and costPECB
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Karina Matos
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB
 
Are you preparing for GDPR?
Are you preparing for GDPR?Are you preparing for GDPR?
Are you preparing for GDPR?Chris Bullock
 
Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...
Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...
Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...PECB
 
Any Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsAny Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsPECB
 

What's hot (20)

Risk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR complianceRisk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR compliance
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 
It security iso 27001
It security iso 27001It security iso 27001
It security iso 27001
 
MCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service Presentation
 
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
 
Gdpr data p rotection
Gdpr data p rotectionGdpr data p rotection
Gdpr data p rotection
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
Legal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services SectorLegal And Regulatory Dp Challenges For The Financial Services Sector
Legal And Regulatory Dp Challenges For The Financial Services Sector
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrity
 
Business Continuity requires a Security Architecture to reduce risk and cost
Business Continuity requires a Security Architecture to reduce risk and costBusiness Continuity requires a Security Architecture to reduce risk and cost
Business Continuity requires a Security Architecture to reduce risk and cost
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?
 
Are you preparing for GDPR?
Are you preparing for GDPR?Are you preparing for GDPR?
Are you preparing for GDPR?
 
Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...
Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...
Data Privacy, Information Security, and Cybersecurity: What Your Business Nee...
 
Any Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsAny Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO Standards
 

Similar to GDPR Compliance: Getting Everyone On Board

Get doing GDPR right now! IRMS May 2018
Get doing GDPR right now!  IRMS May 2018Get doing GDPR right now!  IRMS May 2018
Get doing GDPR right now! IRMS May 2018Metataxis
 
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-smIBM Sverige
 
5 Steps to Effectively Handle Digital Transformation and Business Disruption:...
5 Steps to Effectively Handle Digital Transformation and Business Disruption:...5 Steps to Effectively Handle Digital Transformation and Business Disruption:...
5 Steps to Effectively Handle Digital Transformation and Business Disruption:...SVRTechnologies
 
Webinar for May 2020 - Putting people skills and cultural change at the heart...
Webinar for May 2020 - Putting people skills and cultural change at the heart...Webinar for May 2020 - Putting people skills and cultural change at the heart...
Webinar for May 2020 - Putting people skills and cultural change at the heart...The Digital Insurer
 
The Adaptive PMO: Manage and Maintain Change Management for long term success
The Adaptive PMO: Manage and Maintain Change Management for long term successThe Adaptive PMO: Manage and Maintain Change Management for long term success
The Adaptive PMO: Manage and Maintain Change Management for long term successKeyedIn Projects
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...AIIM International
 
The 3 Phased Approach to Data Leakage Prevention (DLP)
The 3 Phased Approach to Data Leakage Prevention (DLP)The 3 Phased Approach to Data Leakage Prevention (DLP)
The 3 Phased Approach to Data Leakage Prevention (DLP)Kirsty Donovan
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
Implementing green IT strategy & governance
Implementing green IT strategy & governanceImplementing green IT strategy & governance
Implementing green IT strategy & governanceTanguy Swinnen
 
Where will BRM find themselves in Product Centric Organizations in the Near F...
Where will BRM find themselves in Product Centric Organizations in the Near F...Where will BRM find themselves in Product Centric Organizations in the Near F...
Where will BRM find themselves in Product Centric Organizations in the Near F...Svetlana Sidenko
 
GDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementationGDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementationFERMA
 
Gartner Symposium 2015 - Brochure
Gartner Symposium 2015 - BrochureGartner Symposium 2015 - Brochure
Gartner Symposium 2015 - BrochurePaul Woudstra
 
How to embrace digital transformation in the Financial Services sector
How to embrace digital transformation in the Financial Services sectorHow to embrace digital transformation in the Financial Services sector
How to embrace digital transformation in the Financial Services sectorBrandworkz
 
Accelerate your Digital Transformation Journey
Accelerate your Digital Transformation JourneyAccelerate your Digital Transformation Journey
Accelerate your Digital Transformation JourneyNkemdilim Uwaje Begho
 
Being digital: Fast-forward to the right digital strategy
Being digital: Fast-forward to the right digital strategyBeing digital: Fast-forward to the right digital strategy
Being digital: Fast-forward to the right digital strategyaccenture
 
Transform with Cloud to drive your future
Transform with Cloud to drive your futureTransform with Cloud to drive your future
Transform with Cloud to drive your futureAmazon Web Services
 
Born to be digital - how leading CIOs are preparing for digital transformation
Born to be digital - how leading CIOs are preparing for digital transformationBorn to be digital - how leading CIOs are preparing for digital transformation
Born to be digital - how leading CIOs are preparing for digital transformationEY
 
FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...
FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...
FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...Wellingtone
 

Similar to GDPR Compliance: Getting Everyone On Board (20)

Get doing GDPR right now! IRMS May 2018
Get doing GDPR right now!  IRMS May 2018Get doing GDPR right now!  IRMS May 2018
Get doing GDPR right now! IRMS May 2018
 
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
 
5 Steps to Effectively Handle Digital Transformation and Business Disruption:...
5 Steps to Effectively Handle Digital Transformation and Business Disruption:...5 Steps to Effectively Handle Digital Transformation and Business Disruption:...
5 Steps to Effectively Handle Digital Transformation and Business Disruption:...
 
Webinar for May 2020 - Putting people skills and cultural change at the heart...
Webinar for May 2020 - Putting people skills and cultural change at the heart...Webinar for May 2020 - Putting people skills and cultural change at the heart...
Webinar for May 2020 - Putting people skills and cultural change at the heart...
 
The Adaptive PMO: Manage and Maintain Change Management for long term success
The Adaptive PMO: Manage and Maintain Change Management for long term successThe Adaptive PMO: Manage and Maintain Change Management for long term success
The Adaptive PMO: Manage and Maintain Change Management for long term success
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
 
The 3 Phased Approach to Data Leakage Prevention (DLP)
The 3 Phased Approach to Data Leakage Prevention (DLP)The 3 Phased Approach to Data Leakage Prevention (DLP)
The 3 Phased Approach to Data Leakage Prevention (DLP)
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
Implementing green IT strategy & governance
Implementing green IT strategy & governanceImplementing green IT strategy & governance
Implementing green IT strategy & governance
 
Where will BRM find themselves in Product Centric Organizations in the Near F...
Where will BRM find themselves in Product Centric Organizations in the Near F...Where will BRM find themselves in Product Centric Organizations in the Near F...
Where will BRM find themselves in Product Centric Organizations in the Near F...
 
GDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementationGDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementation
 
Gartner Symposium 2015 - Brochure
Gartner Symposium 2015 - BrochureGartner Symposium 2015 - Brochure
Gartner Symposium 2015 - Brochure
 
Cv jagroop jagpal
Cv jagroop jagpalCv jagroop jagpal
Cv jagroop jagpal
 
How to embrace digital transformation in the Financial Services sector
How to embrace digital transformation in the Financial Services sectorHow to embrace digital transformation in the Financial Services sector
How to embrace digital transformation in the Financial Services sector
 
Digital transformation guide and checklist 2020
Digital transformation guide and checklist 2020 Digital transformation guide and checklist 2020
Digital transformation guide and checklist 2020
 
Accelerate your Digital Transformation Journey
Accelerate your Digital Transformation JourneyAccelerate your Digital Transformation Journey
Accelerate your Digital Transformation Journey
 
Being digital: Fast-forward to the right digital strategy
Being digital: Fast-forward to the right digital strategyBeing digital: Fast-forward to the right digital strategy
Being digital: Fast-forward to the right digital strategy
 
Transform with Cloud to drive your future
Transform with Cloud to drive your futureTransform with Cloud to drive your future
Transform with Cloud to drive your future
 
Born to be digital - how leading CIOs are preparing for digital transformation
Born to be digital - how leading CIOs are preparing for digital transformationBorn to be digital - how leading CIOs are preparing for digital transformation
Born to be digital - how leading CIOs are preparing for digital transformation
 
FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...
FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...
FuturePMO 2018 - Michael Cooch PwC - The Future of Work - A Closer Look at Ar...
 

More from IT Governance Ltd

The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...IT Governance Ltd
 
Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...IT Governance Ltd
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...IT Governance Ltd
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
Privacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failingPrivacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failingIT Governance Ltd
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRIT Governance Ltd
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersIT Governance Ltd
 
Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?IT Governance Ltd
 
EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer IT Governance Ltd
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPRIT Governance Ltd
 
Using international standards to improve US cybersecurity
Using international standards to improve US cybersecurityUsing international standards to improve US cybersecurity
Using international standards to improve US cybersecurityIT Governance Ltd
 
Using international standards to improve Asia-Pacific cyber security
Using international standards to improve Asia-Pacific cyber securityUsing international standards to improve Asia-Pacific cyber security
Using international standards to improve Asia-Pacific cyber securityIT Governance Ltd
 
Using international standards to improve EU cyber security
Using international standards to improve EU cyber securityUsing international standards to improve EU cyber security
Using international standards to improve EU cyber securityIT Governance Ltd
 
Implementing PCI DSS v 2.0 and v 3.0
Implementing PCI DSS v 2.0 and v 3.0Implementing PCI DSS v 2.0 and v 3.0
Implementing PCI DSS v 2.0 and v 3.0IT Governance Ltd
 

More from IT Governance Ltd (17)

The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...
 
Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Privacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failingPrivacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failing
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPR
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud Providers
 
Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
 
Using international standards to improve US cybersecurity
Using international standards to improve US cybersecurityUsing international standards to improve US cybersecurity
Using international standards to improve US cybersecurity
 
Using international standards to improve Asia-Pacific cyber security
Using international standards to improve Asia-Pacific cyber securityUsing international standards to improve Asia-Pacific cyber security
Using international standards to improve Asia-Pacific cyber security
 
Using international standards to improve EU cyber security
Using international standards to improve EU cyber securityUsing international standards to improve EU cyber security
Using international standards to improve EU cyber security
 
Implementing PCI DSS v 2.0 and v 3.0
Implementing PCI DSS v 2.0 and v 3.0Implementing PCI DSS v 2.0 and v 3.0
Implementing PCI DSS v 2.0 and v 3.0
 

Recently uploaded

Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Future Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionFuture Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionMintel Group
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadAyesha Khan
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africaictsugar
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Timedelhimodelshub1
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCRashishs7044
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607dollysharma2066
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 

Recently uploaded (20)

Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Future Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionFuture Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted Version
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africa
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Time
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 

GDPR Compliance: Getting Everyone On Board

  • 1. © IT Governance Ltd 2018 Presenter:StefanieRetfalvi,LearningDesign&SolutionsConsultant,ITGovernance GDPR Compliance: Getting Everyone On Board
  • 2. © IT Governance Ltd 2018 Agenda 01 02 03 04 06 07 ? Q&A 05 Cyber Security Awareness Programme GDPR Compliance: Getting Everyone on board
  • 3. About IT Governance & Introduction
  • 4. © IT Governance Ltd 2018 About IT Governance
  • 5. © IT Governance Ltd 2018 Introduction • Stefanie Ildiko RETFALVI • Learning Design & Solutions Consultant • International cross-sector experience
  • 6. © IT Governance Ltd 2018 Staff Awareness & The GDPR
  • 7. © IT Governance Ltd 2018 Article 36 1. (b) to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits; “
  • 8. © IT Governance Ltd 2018 Why it matters ICO publication: Preparing for the General Data Protection Regulation (GDPR): 12 steps to take now
  • 9. © IT Governance Ltd 2018 Stakeholders, Focus Groups & Planning
  • 10. © IT Governance Ltd 2018 Compliance affects Everyone • C-Suite, senior management buy-in (leading by example) • DPOs, CISOs, CIOs • Business process owners • HR, change management, internal comms • Focus groups • Surveys
  • 11. © IT Governance Ltd 2018 Managing Change
  • 12. © IT Governance Ltd 2018 Dealing with resistance Aversion to change is natural Resistance to Content versus Resistance to Process Consider this question within your organisational context
  • 13. © IT Governance Ltd 2018 • Understand your audience(s) • Align your strategy and your culture • Read and rewrite the context • Make use of proven engagement techniques • Be opportunistic Managing the Transition
  • 14. © IT Governance Ltd 2018 To attain the highest levels of employee engagement, it is important to generate personal investment and motivation for adopting the GDPR. “ Bringing about a Change in Mindset
  • 15. © IT Governance Ltd 2018 Common Challenges
  • 16. © IT Governance Ltd 2018 The GDPR as a focal subject • Viewed as dry • Perceived as overwhelming • Misconceptions (regarding implications)
  • 17. © IT Governance Ltd 2018 Training Audit Trail True Engagement & Behaviour Change
  • 18. © IT Governance Ltd 2018 Proven Techniques & Solutions
  • 19. © IT Governance Ltd 2018 Identifying Problems Identifying common drivers for resistance or gaps in understanding is the first step to gaining organisation-wide buy-in. “
  • 20. © IT Governance Ltd 2018 Implementing a GDPR Awareness Programme It is important to offer a modern mix of different GDPR-focused learning and communications tools to address individuals’ diverse needs and preferences. “
  • 21. © IT Governance Ltd 2018 Gaining Buy-In Don’t treat GDPR awareness training like a bitter medicine that everyone needs to swallow. “
  • 22. © IT Governance Ltd 2018 Example
  • 23. © IT Governance Ltd 2018 Delivering Knowledge Understanding the GDPR will help to mitigate aversion to change and reduce the human factor as a risk. “
  • 24. © IT Governance Ltd 2018 Example
  • 25. © IT Governance Ltd 2018 Encouraging Knowledge Transfer to the Workplace It is not enough to know what best practice involves. Employees need to apply their obtained knowledge in their everyday activities. “
  • 26. © IT Governance Ltd 2018 Sample Solution These should: • Be meaningful, encouraging deep reflection and the transfer of acquired knowledge to the workplace; • Make learners active participants by challenging them to recall key information in relevant contexts; and • Prompt participants to identify risks and apply best practice in situations that could arise in real life on the job.
  • 27. © IT Governance Ltd 2018 Example
  • 28. © IT Governance Ltd 2018 Continual monitoring of progress will ensure that everyone has achieved the required level of knowledge and understanding. “ Evaluation
  • 29. © IT Governance Ltd 2018 Example
  • 30. © IT Governance Ltd 2018 Once the programme is finished, it is important to ensure that the GDPR remains at the forefront of individuals’ minds. “ Continual Reinforcement
  • 31. © IT Governance Ltd 2018 Useful References
  • 32. © IT Governance Ltd 2018 Useful References “GDPR in the workplace” “Employee communication” “Change management” https://www.cipd.co.uk/ http://www.wfpma.com/ https://ico.org.uk/about-the-ico/what-we-do/taking-action-data- protection/ https://www.itgovernance.co.uk/blog
  • 33. © IT Governance Ltd 2018 Conclusion & Your turn! Q&A
  • 34. © IT Governance Ltd 2018 Conclusion
  • 35. © IT Governance Ltd 2018 Call us +44 (0)333 800 7000 Email us servicecentre@itgovernance.co.uk Visit our website www.itgovernance.co.uk Like us on Facebook /ITGovernanceLtd Follow us on Twitter /itgovernance Join us on LinkedIn /company/it-governance Read our blog www.itgovernance.co.uk/blog Stay in touch!
  • 36. © IT Governance Ltd 2018 Queries? Understanding? Clarification? Your Turn!