SlideShare a Scribd company logo
1 of 22
An introduction to the General Data
Protection Regulation (GDPR)
Legal disclaimer
This document does not constitute legal advice of any kind and
we take no responsibility on the correctness and completeness
of the information presented. Our goal is to provide a simplified
summary of the GDPR from our own subjective view. We
strongly recommend that you obtain proper legal advice and a
binding interpretation of the regulation for your organisation.
Example: Website and Online Shop
User Profile Data
- Personal data
- Payment information
- Newsletter data/preferences
- Order history
Payment provider
Logistics partner
Email marketing tool
Automated decision-making
- Behavioral (clickstream, order
history)
- Profiling (location, interests)
Primary goals of the GDPR
Protection of natural persons with regards to
- the processing of personal data
- the free movement of personal data
What is personal data?
- Personal data = information relating to a natural person (also
called ‘data subject’)
- Data subjects can be both identified or identifiable
EXAMPLES:
- IP address
- User name
- E-mail address
- Account number
- PIN/Password
- Voice scan
- Credit card number
Data controller and data processor
Data Controller
determines the purposes and
means of the processing
Data Processor
processes personal data on
behalf of the controller
EXAMPLE:
- Online shop provider
- Payment provider
- Logistics partner
- Email marketing tool provider
Article 5
Principles of personal data processing
- lawfulness, fairness and transparency
- purpose limitation
- data minimisation
- accuracy
- storage limitation
- integrity and confidentiality
- accountability
Article 6
Lawfulness of processing
Processing is lawful if at least one of the following applies:
- Consent given by data subject
- Legitimate interest in processing the data
- Necessity for fulfilment of a contract
- There is a legal obligation
- Necessary for vital interests of the data subject
- Necessity for performance of a task in the public interest
Article 7
Consent of the data subject
Lawful consent according to the GDRP:
- No pre-checked boxes
- Easy to understand wording
- Specific consent for every purpose
- Is recorded in the system
- Is easy to recall
Best Practice Example https://onetrust.com/products/cookies/
Article 25
Privacy by design and by default
Systems and processes have to be designed to
- implement data protection in an effective manner and
- to integrate the necessary safeguards into the processing
EXAMPLES:
OK Pseudonymization of data for tracking of user behaviour
OK Data minimisation when signing up users for a newsletter
NOT OK Form data submission by email (not using a secure database)
NOT OK Lack of account removal function
Article 13
Information and access to personal data
Controller must provide the following information:
- Contact details
- Purposes and legal basis of the processing
- Recipients of the data
- Period for which the personal data will be stored
- Description of data subject rights
- Source of the data
- Existence of automated decision-making, including profiling
Articles 15, 16, 17, 20, 21, 22
Rights of the data subject
The data subject has the right to
- get confirmation if data are being processed
- get access to, correct, delete and receive an export of all
personal data
- object to personal data processing for direct marketing
purposes
- object to automated decision-making (such as profiling)
- get human intervention to contest the above decision
Article 24
Responsibility of the data controller
The data controller must implement technical and
organisational measures to
- ensure that data processing is in accordance with the GDPR
- be able to demonstrate the above
- review and update those measures
Article 30
Records of processing activities
Who/When
- more than 250 employees
- regular data processing
- risks to rights and
freedoms of data subjects
- special data categories
What to include
- contact details
- purposes of the processing
- categories of data subjects
- categories of personal data
- categories of recipients
- time limits for erasure of the different
categories of data
- description of the technical and
organisational security measures
Article 32
Security of processing
Technical and organisational measures:
- pseudonymisation and encryption of personal data
- ability to ensure ongoing confidentiality, integrity, availability
and resilience of processing systems and services
- ability to quickly restore access to personal data in the event
of an incident
- process for regular testing, assessment and evaluation of
the effectiveness of security measures
Articles 33, 34
Notification of a personal data breach
A data breach must be reported to
- the supervisory authority
- within 72 hours
- unless the personal data breach is unlikely to result in a risk to the
rights and freedoms of natural persons
- to the data subject
- without undue delay
- only in case of high risk to the rights and freedoms of natural persons
Articles 35
Data protection impact assessment
Who/When
- in case of high risk to
rights and freedoms of
natural persons
- prior to the processing
- single assessment for
similar processing
operations or similar high
risks
What to include
- description of processing operations
and purposes of the processing
- assessment of necessity and
proportionality of processing
operations in relation to the purposes
- assessment of risks to rights and
freedoms of data subjects
- documentation of measures that will
be taken to address the risks
Articles 37, 38, 39
Data protection officer
Who/When
- public authority
- regular processing
- special categories
of data
How
- is involved in all issues
- has required resources to
process with tasks and
maintain the knowledge
- is independent
What
- inform and advise
- monitor compliance
- cooperate with the
supervisory authority
Articles 42, 77, 83
Certification and supervision
- Complaints with a supervisory authority
- every data subject has the right to lodge a complaint
- supervisory authority must inform on progress and outcome
- Fines
- effective, proportionate and dissuasive
- up to EUR 20 million or 4% of the total worldwide annual turnover
- Certification
- register of certification mechanisms and data protection seals and
marks will be available publicly
Overview of overall GDPR impact
Functional
- Get express consent from users
- Provision of additional information to data
subjects
- Add ability to erase and export all user data
- Add ability to correct inaccurate user data
- Recall consent for one purpose (marketing)
and leave the others
- Add ability for human intervention
- Demonstrate security measures
- Control access to the user data
Business/Process
- Clearly define purposes and consents
- Add human intervention mechanisms to the
system(s)
- Review and update security measures
- Create Records for Processing Activities
- Ensure informing supervising authority in the
case of incidents (within 72h)
- Create Data Protection Impact Assessment
- Assignment of Data Protection Officer(s)
Questions?

More Related Content

Similar to An Introduction to the General Data Protection Regulation (GDPR)

Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...Mailjet
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT LegalCyber Watching
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityEQS Group
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORIKarel Holst
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical OverviewErnest Staats
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Happiest Minds Technologies
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIKarel Holst
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 

Similar to An Introduction to the General Data Protection Regulation (GDPR) (20)

GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
GDPR
GDPRGDPR
GDPR
 
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
#CyberSafeLambeth
#CyberSafeLambeth#CyberSafeLambeth
#CyberSafeLambeth
 
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
Gdpr brief and controls ver2.0
Gdpr brief and controls ver2.0Gdpr brief and controls ver2.0
Gdpr brief and controls ver2.0
 
The general data protection act overview
The general data protection act overviewThe general data protection act overview
The general data protection act overview
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 

Recently uploaded

Storyboards for my Final Major Project Video
Storyboards for my Final Major Project VideoStoryboards for my Final Major Project Video
Storyboards for my Final Major Project VideoSineadBidwell
 
Cost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surgesCost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surgesPushON Ltd
 
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...Benjamin Szturmaj
 
Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresLisa M. Masiello
 
DIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdf
DIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdfDIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdf
DIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdfmayanksharma0441
 
Influencer Marketing Power point presentation
Influencer Marketing  Power point presentationInfluencer Marketing  Power point presentation
Influencer Marketing Power point presentationdgtivemarketingagenc
 
How To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot SetupHow To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot Setupssuser4571da
 
The Skin Games 2024 25 - Sponsorship Deck
The Skin Games 2024 25 - Sponsorship DeckThe Skin Games 2024 25 - Sponsorship Deck
The Skin Games 2024 25 - Sponsorship DeckToluwanimi Balogun
 
ASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationAli Raza
 
DIGITAL MARKETING COURSE IN BTM -Influencer Marketing Strategy
DIGITAL MARKETING COURSE IN BTM -Influencer Marketing StrategyDIGITAL MARKETING COURSE IN BTM -Influencer Marketing Strategy
DIGITAL MARKETING COURSE IN BTM -Influencer Marketing StrategySouvikRay24
 
Mastering SEO in the Evolving AI-driven World
Mastering SEO in the Evolving AI-driven WorldMastering SEO in the Evolving AI-driven World
Mastering SEO in the Evolving AI-driven WorldScalenut
 
McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)DEVARAJV16
 
Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guidekiva6
 
Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Fueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdfFueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdfVWO
 
Red bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxxRed bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxx216310017
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfEastern Online-iSURVEY
 
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...Search Engine Journal
 
The Impact of Digital Technologies
The Impact of Digital Technologies The Impact of Digital Technologies
The Impact of Digital Technologies bruguardarib
 
Avoid the 2025 web accessibility rush: do not fear WCAG compliance
Avoid the 2025 web accessibility rush: do not fear WCAG complianceAvoid the 2025 web accessibility rush: do not fear WCAG compliance
Avoid the 2025 web accessibility rush: do not fear WCAG complianceDamien ROBERT
 

Recently uploaded (20)

Storyboards for my Final Major Project Video
Storyboards for my Final Major Project VideoStoryboards for my Final Major Project Video
Storyboards for my Final Major Project Video
 
Cost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surgesCost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surges
 
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
 
Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample Genres
 
DIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdf
DIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdfDIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdf
DIGITAL MARKETING STRATEGY_INFOGRAPHIC IMAGE.pdf
 
Influencer Marketing Power point presentation
Influencer Marketing  Power point presentationInfluencer Marketing  Power point presentation
Influencer Marketing Power point presentation
 
How To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot SetupHow To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot Setup
 
The Skin Games 2024 25 - Sponsorship Deck
The Skin Games 2024 25 - Sponsorship DeckThe Skin Games 2024 25 - Sponsorship Deck
The Skin Games 2024 25 - Sponsorship Deck
 
ASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationASO Process: What is App Store Optimization
ASO Process: What is App Store Optimization
 
DIGITAL MARKETING COURSE IN BTM -Influencer Marketing Strategy
DIGITAL MARKETING COURSE IN BTM -Influencer Marketing StrategyDIGITAL MARKETING COURSE IN BTM -Influencer Marketing Strategy
DIGITAL MARKETING COURSE IN BTM -Influencer Marketing Strategy
 
Mastering SEO in the Evolving AI-driven World
Mastering SEO in the Evolving AI-driven WorldMastering SEO in the Evolving AI-driven World
Mastering SEO in the Evolving AI-driven World
 
McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)McDonald's: A Journey Through Time (PPT)
McDonald's: A Journey Through Time (PPT)
 
Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guide
 
Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Lajpat Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Fueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdfFueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdf
 
Red bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxxRed bull marketing presentation pptxxxxx
Red bull marketing presentation pptxxxxx
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
 
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
 
The Impact of Digital Technologies
The Impact of Digital Technologies The Impact of Digital Technologies
The Impact of Digital Technologies
 
Avoid the 2025 web accessibility rush: do not fear WCAG compliance
Avoid the 2025 web accessibility rush: do not fear WCAG complianceAvoid the 2025 web accessibility rush: do not fear WCAG compliance
Avoid the 2025 web accessibility rush: do not fear WCAG compliance
 

An Introduction to the General Data Protection Regulation (GDPR)

  • 1. An introduction to the General Data Protection Regulation (GDPR)
  • 2. Legal disclaimer This document does not constitute legal advice of any kind and we take no responsibility on the correctness and completeness of the information presented. Our goal is to provide a simplified summary of the GDPR from our own subjective view. We strongly recommend that you obtain proper legal advice and a binding interpretation of the regulation for your organisation.
  • 3. Example: Website and Online Shop User Profile Data - Personal data - Payment information - Newsletter data/preferences - Order history Payment provider Logistics partner Email marketing tool Automated decision-making - Behavioral (clickstream, order history) - Profiling (location, interests)
  • 4. Primary goals of the GDPR Protection of natural persons with regards to - the processing of personal data - the free movement of personal data
  • 5. What is personal data? - Personal data = information relating to a natural person (also called ‘data subject’) - Data subjects can be both identified or identifiable EXAMPLES: - IP address - User name - E-mail address - Account number - PIN/Password - Voice scan - Credit card number
  • 6. Data controller and data processor Data Controller determines the purposes and means of the processing Data Processor processes personal data on behalf of the controller EXAMPLE: - Online shop provider - Payment provider - Logistics partner - Email marketing tool provider
  • 7. Article 5 Principles of personal data processing - lawfulness, fairness and transparency - purpose limitation - data minimisation - accuracy - storage limitation - integrity and confidentiality - accountability
  • 8. Article 6 Lawfulness of processing Processing is lawful if at least one of the following applies: - Consent given by data subject - Legitimate interest in processing the data - Necessity for fulfilment of a contract - There is a legal obligation - Necessary for vital interests of the data subject - Necessity for performance of a task in the public interest
  • 9. Article 7 Consent of the data subject Lawful consent according to the GDRP: - No pre-checked boxes - Easy to understand wording - Specific consent for every purpose - Is recorded in the system - Is easy to recall
  • 10. Best Practice Example https://onetrust.com/products/cookies/
  • 11. Article 25 Privacy by design and by default Systems and processes have to be designed to - implement data protection in an effective manner and - to integrate the necessary safeguards into the processing EXAMPLES: OK Pseudonymization of data for tracking of user behaviour OK Data minimisation when signing up users for a newsletter NOT OK Form data submission by email (not using a secure database) NOT OK Lack of account removal function
  • 12. Article 13 Information and access to personal data Controller must provide the following information: - Contact details - Purposes and legal basis of the processing - Recipients of the data - Period for which the personal data will be stored - Description of data subject rights - Source of the data - Existence of automated decision-making, including profiling
  • 13. Articles 15, 16, 17, 20, 21, 22 Rights of the data subject The data subject has the right to - get confirmation if data are being processed - get access to, correct, delete and receive an export of all personal data - object to personal data processing for direct marketing purposes - object to automated decision-making (such as profiling) - get human intervention to contest the above decision
  • 14. Article 24 Responsibility of the data controller The data controller must implement technical and organisational measures to - ensure that data processing is in accordance with the GDPR - be able to demonstrate the above - review and update those measures
  • 15. Article 30 Records of processing activities Who/When - more than 250 employees - regular data processing - risks to rights and freedoms of data subjects - special data categories What to include - contact details - purposes of the processing - categories of data subjects - categories of personal data - categories of recipients - time limits for erasure of the different categories of data - description of the technical and organisational security measures
  • 16. Article 32 Security of processing Technical and organisational measures: - pseudonymisation and encryption of personal data - ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services - ability to quickly restore access to personal data in the event of an incident - process for regular testing, assessment and evaluation of the effectiveness of security measures
  • 17. Articles 33, 34 Notification of a personal data breach A data breach must be reported to - the supervisory authority - within 72 hours - unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons - to the data subject - without undue delay - only in case of high risk to the rights and freedoms of natural persons
  • 18. Articles 35 Data protection impact assessment Who/When - in case of high risk to rights and freedoms of natural persons - prior to the processing - single assessment for similar processing operations or similar high risks What to include - description of processing operations and purposes of the processing - assessment of necessity and proportionality of processing operations in relation to the purposes - assessment of risks to rights and freedoms of data subjects - documentation of measures that will be taken to address the risks
  • 19. Articles 37, 38, 39 Data protection officer Who/When - public authority - regular processing - special categories of data How - is involved in all issues - has required resources to process with tasks and maintain the knowledge - is independent What - inform and advise - monitor compliance - cooperate with the supervisory authority
  • 20. Articles 42, 77, 83 Certification and supervision - Complaints with a supervisory authority - every data subject has the right to lodge a complaint - supervisory authority must inform on progress and outcome - Fines - effective, proportionate and dissuasive - up to EUR 20 million or 4% of the total worldwide annual turnover - Certification - register of certification mechanisms and data protection seals and marks will be available publicly
  • 21. Overview of overall GDPR impact Functional - Get express consent from users - Provision of additional information to data subjects - Add ability to erase and export all user data - Add ability to correct inaccurate user data - Recall consent for one purpose (marketing) and leave the others - Add ability for human intervention - Demonstrate security measures - Control access to the user data Business/Process - Clearly define purposes and consents - Add human intervention mechanisms to the system(s) - Review and update security measures - Create Records for Processing Activities - Ensure informing supervising authority in the case of incidents (within 72h) - Create Data Protection Impact Assessment - Assignment of Data Protection Officer(s)