SlideShare a Scribd company logo
1 of 23
Download to read offline
Marjane Moghimi
uk.marjanem@gmail.com
GDPR - time for action
November 2017
Soft or hard Brexit, GDPR is coming into force on 25 May
2018 and firms need to prepare…
Marjane Moghimi Nov 2017
The Queen’s Speech has confirmed that the General Data Protection
Regulation will form part of UK law following the country’s withdrawal from
the European Union. The Speech noted that “Over 70% of all trade in
services are enabled by data flows, meaning that data protection is critical
to international trade.” 22 June 2017
And after Brexit ?
Marjane Moghimi Nov 2017
• On 21 June 2017 the UK Government revealed its legislative programme for the
coming two years. As well as pressing ahead with the UK’s withdrawal from the
European Union, the Government has confirmed its intention to bring the EU
General Data Protection Regulation (the “GDPR”) into UK law, ensuring the
country’s data protection framework is “suitable for our new digital age, allowing
citizens to better control their data.”
• Therefore it seems that the after Brexit rules will be compatible and aligned with
the EU GDPR.
► But some of the EU based clients may ask for the localisation of databases in EU.
► So where the data (server, data centre, cloud) is stored needs some reflexion.
UK
Marjane Moghimi Nov 2017
UK Current
• Current legislation
• DPA 1998
25 May 2018
• Future legislation
• GDPR
Map
• Cross Map the change from current law to new regulation
• Will give you the picture of ‘As is’ and ‘To Be’
GDPR overview
Marjane Moghimi Nov 2017
Data
Controller
Data
Processor
Data
Subject
Aim is to protect a natural
person living in the EU
(include EEA) by expanding
the definition of personal
data and giving more
rights to privacy
Impose new duties
and obligation on
Initial assessment
• Data Controller
– Is in direct contact with Data
Subject
– It is ultimately responsible for
the application of Data
Protection principals
– Must provide privacy notice
when collecting data
– Must inform the data subject in
case of data breach
• Data Processor
– Has direct responsibility under
GDPR
– Must assure the security of
processing operations,
– Must name a Data Protection
Officer,
– Must notify any breach of data
protection obligations to the
Data Controller.
Marjane Moghimi Nov 2017
New rights of Data Subject
• The aim is to give to Data Subject the ownership of their own data
• the data subjects' rights :
– right to be informed,
– right to object to the accuracy of the information
– right of access (free)
– right to be forgotten (exceptions do exist)
– right to give consent and withdraw it easily
– The consents need to specific for each usage of data
– Right to be informed if a data breach occurred without undue delay
– Etc.
Marjane Moghimi Nov 2017
What is the new definition of Personal Data ?
• The GDPR broadens the definition of “personal data.”
• Sensitive data such as biometric and genetic data will be subject to a
higher standard.
• Under the terms of GDPR, personal data refers to anything that could be
used to identify an individual, such as :
– name,
– email address,
– IP address,
– social media profiles
– Phone numbers
– Social security numbers
– Etc.
Marjane Moghimi Nov 2017
GDPR for HR
• Your past, current and future employees are Data Subject
• Under GDPR they have extended rights such as: right to rectification and erasure, right of
portability of their data and subject access request (without fee )
• Action points, data audit:
– What data you have?
– Where it is located?
– Why such data is collected? Is it up to date?
– To and From where is transferred (in the company, outside 1/3 parties, outside EU and
EEA)? Which data points are transferred?
– How long is kept?
– On which basis ? Legitimate business ? If not erase.
– Consents need to be reviewed
►Data mapping and flow charts help to have a global view of the flow of Data from and into
various systems
►A gap analysis will highlight areas of concern you need to look at.
Marjane Moghimi Nov 2017
Data audit
What Staff data
do you have
Where is come
from?
Where /How is
stored?
What happens
with it in your
organization?
When/How is
it deleted?
Is it up to date?
It is transferred
outside the
firm?
Identify the
Stakeholders
HR
Finance
Payroll
Third parties
Etc.
Marjane Moghimi Nov 2017
Expand on each point
till you have a clear
picture and cover it
completely
Personal Data mapping -1
Why a firm is
processing
personal data?
1- Staff administration
2- Client administration
3- For safety and security
4- To meet legal obligation
5- To provide service to 1/3 parties
6- To improve services/businesses
7- For direct marketing
8- Etc.
Marjane Moghimi Nov 2017
Personal Data mapping -2
For each reason
defined, you
need to precise
each activities
that it covers
1- Staff administration
Recruitment (recruitment agency, reference etc.)
Payroll
Benefit (pension, private medical health, insurance etc.)
Appraisal
Record of attendance, leave, holidays
Correspondence related to the employment
Etc.
Marjane Moghimi Nov 2017
Personal Data mapping -3
Then define
each category,
sub category of
data you collect
Examples:
Job candidates
Current staff/contractors
Former staff/contractors
Emergency contact/relatives
Third party benefit providers
Contacts at suppliers
Etc.
Marjane Moghimi Nov 2017
Action list for compliance with GDPR
After the Data mapping:
1. Run a GDPR compliance gap
– Run a review of all of your data entries ( online, 1/3 parties etc.)
– Analysis of your operations, IT, processes, systems, procedures
• Data flow (in, out, from, to)
• Vendors and 1/3 parties data review
2. Create a GDPR Risk Register
3. Define areas for change: Processes, People, Technology
– Prioritize work according to the Risk Register
– Plan communication with data subject (consents, breach notification)
– Update your data protection compliance procedures
– Keep an audit trail of all your activities in order to comply with the regulation
4. Highlight and act on areas overlapping with other regulations (if applicable to
your industry)
Marjane Moghimi Nov 2017
People, processes, technology
Marjane Moghimi Nov 2017
Certification
• GDPR recommend certification schemes
Certification is voluntary. Currently there is no official certification body for GDPR
• ISO 27001 is such certification
– Is an information security management standard
– Follow international best practices
– Focus on information security (firms and their customers)
– Based on formal risk assessment
– 3 aspects to information security
• People
• Processes
• Technology
– Data protection arrangements and processes are similar to GDPR
recommendation
– It can be used as a reference on complying with GDPR regulation
Marjane Moghimi Nov 2017
We already comply with DPA 1998, what more should we do?
• Cross-map GDPR to DPA 1998:
– Focus your action to area of changes
• If you choose to apply ISO 27001:
– Cross-map GDPR to DPA 1998 and ISO 27001
– Highlight areas of changes
– Highlight high risk areas
– Prioritize the work on the most sensitive areas
• Change Management needs to cover
– People
– IT
– Processes and Procedures
– Training for staff
– Communication about GDPR and raising awareness about data security
Marjane Moghimi Nov 2017
GDPR in others European countries
If you have activities in EU you need to be aware of local GDPR application:
• France : CNIL is in forefront of GDPR application
– https://www.cnil.fr/
– https://www.cnil.fr/fr/node/15798
• Luxembourg
– https://cnpd.public.lu/en.html
• Offshore Isle of Man, Jersey, Guernsey (Third Country) have secured a Adequacy
status
– http://ec.europa.eu/justice/data-protection/international-
transfers/adequacy/index_en.htm
Marjane Moghimi Nov 2017
GDPR in Financial industry
• GDPR is overlapping with other regulation such as MIFID 2, PRIIPS, PSD2
• Firms need to separate 3 sort of data:
– Employees, professionals clients, non professional clients (under the definition
of MIFID 2)
• Personal data of employees
• Personal Data of professional clients and Non professional clients
• Personal Data of retail clients
• Interactions between various IT systems (backups systems are in the loop too)
• While banks and other financial firms are familiar with various regulations,
adhering to GDPR requires the collection of large amounts of customer data,
which is then collated and used for various activities, such as client on-boarding,
KYC, relationship management, trade-booking, accounting, etc.
• During these processes, customer data is exposed to a large number of different
people, systems at different stages, and this is the challenge.
Marjane Moghimi Nov 2017
Regulation Overlap: MIFID II and GDPR
MIFID II (3 Jan 2018)
• RTS 4 and ESMA Q&A Oct 2017:
The requirement to identify the clients and
clients of clients in transaction and position
reporting can not be waived.
• For natural persons, the important
identifiers are: passport number and
CONCAT code combining nationality, first
name and surname of position holder.
• If a person is used, that person must be
identified by their ID number, passport
number, tax or national insurance number,
depending on their nationality.
• In the absence of this information, a
concatenated code can be used consisting
of date of birth, the first five characters of
first name and the first five characters of
surname.
GDPR (25 May 2018)
• Under GDPR investments firms are Data
Controller.
• Under MIFID II they are required to report
disaggregated (i.e. Client, Client of Client
etc.) reports.
• Firms need to take steps to ensure that
the data they report is accurate, and that
appropriate consent is obtained to using
individual’s data as part of transaction
reporting, in a way that meets data
protection requirements.
• The safety, security and confidentiality of
clients information stay with the
investments firms
Marjane Moghimi Nov 2017
Regulation Overlap: MIFID II and GDPR
MIFID II
The name and date of birth in both side
of the trade are mandatory part of trade,
transaction and position reporting duties
• Buyer
• Buyer Decision Maker
• Seller
• Seller Decision Maker
GDPR
• Employees information are held in HR
database
• Counterparties information in
Counterparty Data base.
• Clients information in Client database
►You need to have specific consent from those data subject concerned by MIFID II
►Consents from all 1/3 parties are necessary if you have a legitimate interest in
collecting their data
Marjane Moghimi Nov 2017
e-privacy
• Is a Regulation coming into force the same date as GDPR
• Will replace the current Directive
• Its aim is high level of privacy and data protection
• The new regulation will bring significant changes:
– concern to all providers of electronic communication services
• Include Facebook Messenger, Whatsapp, etc.
– will apply to content and meta data
– Simpler rules regarding cookies and spam
– Needs for specific and free consents ; which can easily withdraw.
– Put the emphasis on confidentiality of electronic communications data
including while in transit and cover storage providers (including ’cloud’)
• The regulation is still not finalised so some changes may come into light later.
Marjane Moghimi Nov 2017
Reference
• Text:
– http://ec.europa.eu/justice/data-protection/individuals/index_en.htm
– https://gdpr-info.eu
– ec.europa.eu/justice/ data-protection/reform/ files/regulation_oj_en.pdf
• Summary: www.eugdpr.org/article-summaries.html
• FAQs: www.eugdpr.org/gdpr-faqs.html
• E-privacy: https://edps.europa.eu/sites/edp/files/publication/17-10-
05_edps_recommendations_on_ep_amendments_en.pdf
Marjane Moghimi Nov 2017

More Related Content

What's hot

Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?IT Governance Ltd
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRIT Governance Ltd
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeIBB Law
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPRIT Governance Ltd
 
Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Mark Honeyball
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
GDPR training
GDPR training GDPR training
GDPR training ASL
 
GDPR in practice
GDPR in practiceGDPR in practice
GDPR in practiceZoneFox
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoKeithBudden3
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...IT Governance Ltd
 
GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?Sage HR
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinWhitmeyerTuffin
 

What's hot (20)

Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPR
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
 
Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Datum DPO outsourced May 2016
Datum DPO outsourced May 2016
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
GDPR training
GDPR training GDPR training
GDPR training
 
GDPR in practice
GDPR in practiceGDPR in practice
GDPR in practice
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...
 
GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 

Similar to GDPR will be the new regulation on may 2018

The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRCase IQ
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance IT Governance Ltd
 
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...Mailjet
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacyGuyVanderSande
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Bart Van Den Brande
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPRSrijan Technologies
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceIT Governance Ltd
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 

Similar to GDPR will be the new regulation on may 2018 (20)

The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
 
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
MIFID II and GDPR
MIFID II and GDPR MIFID II and GDPR
MIFID II and GDPR
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 

Recently uploaded

Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...
Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...
Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...gajnagarg
 
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night StandCall Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Standamitlee9823
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...amitlee9823
 
Call Girls In Bellandur ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Bellandur ☎ 7737669865 🥵 Book Your One night StandCall Girls In Bellandur ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Bellandur ☎ 7737669865 🥵 Book Your One night Standamitlee9823
 
Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...
Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...
Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...amitlee9823
 
➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men 🔝Sambalpur🔝 Esc...
➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men  🔝Sambalpur🔝   Esc...➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men  🔝Sambalpur🔝   Esc...
➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men 🔝Sambalpur🔝 Esc...amitlee9823
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Valters Lauzums
 
Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...
Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...
Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...gajnagarg
 
Call Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night StandCall Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night Standamitlee9823
 
👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...
👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...
👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...karishmasinghjnh
 
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...amitlee9823
 
Call Girls In Attibele ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Attibele ☎ 7737669865 🥵 Book Your One night StandCall Girls In Attibele ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Attibele ☎ 7737669865 🥵 Book Your One night Standamitlee9823
 
Call Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night StandCall Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night Standamitlee9823
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNKTimothy Spann
 
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...Elaine Werffeli
 
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...amitlee9823
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Researchmichael115558
 

Recently uploaded (20)

Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...
Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...
Just Call Vip call girls kakinada Escorts ☎️9352988975 Two shot with one girl...
 
Predicting Loan Approval: A Data Science Project
Predicting Loan Approval: A Data Science ProjectPredicting Loan Approval: A Data Science Project
Predicting Loan Approval: A Data Science Project
 
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night StandCall Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Doddaballapur Road ☎ 7737669865 🥵 Book Your One night Stand
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Anomaly detection and data imputation within time series
Anomaly detection and data imputation within time seriesAnomaly detection and data imputation within time series
Anomaly detection and data imputation within time series
 
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Call Girls In Bellandur ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Bellandur ☎ 7737669865 🥵 Book Your One night StandCall Girls In Bellandur ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Bellandur ☎ 7737669865 🥵 Book Your One night Stand
 
Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...
Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...
Escorts Service Kumaraswamy Layout ☎ 7737669865☎ Book Your One night Stand (B...
 
➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men 🔝Sambalpur🔝 Esc...
➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men  🔝Sambalpur🔝   Esc...➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men  🔝Sambalpur🔝   Esc...
➥🔝 7737669865 🔝▻ Sambalpur Call-girls in Women Seeking Men 🔝Sambalpur🔝 Esc...
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
 
Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...
Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...
Just Call Vip call girls Erode Escorts ☎️9352988975 Two shot with one girl (E...
 
Call Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night StandCall Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Hsr Layout ☎ 7737669865 🥵 Book Your One night Stand
 
👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...
👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...
👉 Amritsar Call Girl 👉📞 6367187148 👉📞 Just📲 Call Ruhi Call Girl Phone No Amri...
 
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
 
Call Girls In Attibele ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Attibele ☎ 7737669865 🥵 Book Your One night StandCall Girls In Attibele ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Attibele ☎ 7737669865 🥵 Book Your One night Stand
 
Call Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night StandCall Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night Stand
Call Girls In Shivaji Nagar ☎ 7737669865 🥵 Book Your One night Stand
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
 
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
 
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Research
 

GDPR will be the new regulation on may 2018

  • 1. Marjane Moghimi uk.marjanem@gmail.com GDPR - time for action November 2017
  • 2. Soft or hard Brexit, GDPR is coming into force on 25 May 2018 and firms need to prepare… Marjane Moghimi Nov 2017 The Queen’s Speech has confirmed that the General Data Protection Regulation will form part of UK law following the country’s withdrawal from the European Union. The Speech noted that “Over 70% of all trade in services are enabled by data flows, meaning that data protection is critical to international trade.” 22 June 2017
  • 3. And after Brexit ? Marjane Moghimi Nov 2017 • On 21 June 2017 the UK Government revealed its legislative programme for the coming two years. As well as pressing ahead with the UK’s withdrawal from the European Union, the Government has confirmed its intention to bring the EU General Data Protection Regulation (the “GDPR”) into UK law, ensuring the country’s data protection framework is “suitable for our new digital age, allowing citizens to better control their data.” • Therefore it seems that the after Brexit rules will be compatible and aligned with the EU GDPR. ► But some of the EU based clients may ask for the localisation of databases in EU. ► So where the data (server, data centre, cloud) is stored needs some reflexion.
  • 4. UK Marjane Moghimi Nov 2017 UK Current • Current legislation • DPA 1998 25 May 2018 • Future legislation • GDPR Map • Cross Map the change from current law to new regulation • Will give you the picture of ‘As is’ and ‘To Be’
  • 5. GDPR overview Marjane Moghimi Nov 2017 Data Controller Data Processor Data Subject Aim is to protect a natural person living in the EU (include EEA) by expanding the definition of personal data and giving more rights to privacy Impose new duties and obligation on
  • 6. Initial assessment • Data Controller – Is in direct contact with Data Subject – It is ultimately responsible for the application of Data Protection principals – Must provide privacy notice when collecting data – Must inform the data subject in case of data breach • Data Processor – Has direct responsibility under GDPR – Must assure the security of processing operations, – Must name a Data Protection Officer, – Must notify any breach of data protection obligations to the Data Controller. Marjane Moghimi Nov 2017
  • 7. New rights of Data Subject • The aim is to give to Data Subject the ownership of their own data • the data subjects' rights : – right to be informed, – right to object to the accuracy of the information – right of access (free) – right to be forgotten (exceptions do exist) – right to give consent and withdraw it easily – The consents need to specific for each usage of data – Right to be informed if a data breach occurred without undue delay – Etc. Marjane Moghimi Nov 2017
  • 8. What is the new definition of Personal Data ? • The GDPR broadens the definition of “personal data.” • Sensitive data such as biometric and genetic data will be subject to a higher standard. • Under the terms of GDPR, personal data refers to anything that could be used to identify an individual, such as : – name, – email address, – IP address, – social media profiles – Phone numbers – Social security numbers – Etc. Marjane Moghimi Nov 2017
  • 9. GDPR for HR • Your past, current and future employees are Data Subject • Under GDPR they have extended rights such as: right to rectification and erasure, right of portability of their data and subject access request (without fee ) • Action points, data audit: – What data you have? – Where it is located? – Why such data is collected? Is it up to date? – To and From where is transferred (in the company, outside 1/3 parties, outside EU and EEA)? Which data points are transferred? – How long is kept? – On which basis ? Legitimate business ? If not erase. – Consents need to be reviewed ►Data mapping and flow charts help to have a global view of the flow of Data from and into various systems ►A gap analysis will highlight areas of concern you need to look at. Marjane Moghimi Nov 2017
  • 10. Data audit What Staff data do you have Where is come from? Where /How is stored? What happens with it in your organization? When/How is it deleted? Is it up to date? It is transferred outside the firm? Identify the Stakeholders HR Finance Payroll Third parties Etc. Marjane Moghimi Nov 2017 Expand on each point till you have a clear picture and cover it completely
  • 11. Personal Data mapping -1 Why a firm is processing personal data? 1- Staff administration 2- Client administration 3- For safety and security 4- To meet legal obligation 5- To provide service to 1/3 parties 6- To improve services/businesses 7- For direct marketing 8- Etc. Marjane Moghimi Nov 2017
  • 12. Personal Data mapping -2 For each reason defined, you need to precise each activities that it covers 1- Staff administration Recruitment (recruitment agency, reference etc.) Payroll Benefit (pension, private medical health, insurance etc.) Appraisal Record of attendance, leave, holidays Correspondence related to the employment Etc. Marjane Moghimi Nov 2017
  • 13. Personal Data mapping -3 Then define each category, sub category of data you collect Examples: Job candidates Current staff/contractors Former staff/contractors Emergency contact/relatives Third party benefit providers Contacts at suppliers Etc. Marjane Moghimi Nov 2017
  • 14. Action list for compliance with GDPR After the Data mapping: 1. Run a GDPR compliance gap – Run a review of all of your data entries ( online, 1/3 parties etc.) – Analysis of your operations, IT, processes, systems, procedures • Data flow (in, out, from, to) • Vendors and 1/3 parties data review 2. Create a GDPR Risk Register 3. Define areas for change: Processes, People, Technology – Prioritize work according to the Risk Register – Plan communication with data subject (consents, breach notification) – Update your data protection compliance procedures – Keep an audit trail of all your activities in order to comply with the regulation 4. Highlight and act on areas overlapping with other regulations (if applicable to your industry) Marjane Moghimi Nov 2017
  • 16. Certification • GDPR recommend certification schemes Certification is voluntary. Currently there is no official certification body for GDPR • ISO 27001 is such certification – Is an information security management standard – Follow international best practices – Focus on information security (firms and their customers) – Based on formal risk assessment – 3 aspects to information security • People • Processes • Technology – Data protection arrangements and processes are similar to GDPR recommendation – It can be used as a reference on complying with GDPR regulation Marjane Moghimi Nov 2017
  • 17. We already comply with DPA 1998, what more should we do? • Cross-map GDPR to DPA 1998: – Focus your action to area of changes • If you choose to apply ISO 27001: – Cross-map GDPR to DPA 1998 and ISO 27001 – Highlight areas of changes – Highlight high risk areas – Prioritize the work on the most sensitive areas • Change Management needs to cover – People – IT – Processes and Procedures – Training for staff – Communication about GDPR and raising awareness about data security Marjane Moghimi Nov 2017
  • 18. GDPR in others European countries If you have activities in EU you need to be aware of local GDPR application: • France : CNIL is in forefront of GDPR application – https://www.cnil.fr/ – https://www.cnil.fr/fr/node/15798 • Luxembourg – https://cnpd.public.lu/en.html • Offshore Isle of Man, Jersey, Guernsey (Third Country) have secured a Adequacy status – http://ec.europa.eu/justice/data-protection/international- transfers/adequacy/index_en.htm Marjane Moghimi Nov 2017
  • 19. GDPR in Financial industry • GDPR is overlapping with other regulation such as MIFID 2, PRIIPS, PSD2 • Firms need to separate 3 sort of data: – Employees, professionals clients, non professional clients (under the definition of MIFID 2) • Personal data of employees • Personal Data of professional clients and Non professional clients • Personal Data of retail clients • Interactions between various IT systems (backups systems are in the loop too) • While banks and other financial firms are familiar with various regulations, adhering to GDPR requires the collection of large amounts of customer data, which is then collated and used for various activities, such as client on-boarding, KYC, relationship management, trade-booking, accounting, etc. • During these processes, customer data is exposed to a large number of different people, systems at different stages, and this is the challenge. Marjane Moghimi Nov 2017
  • 20. Regulation Overlap: MIFID II and GDPR MIFID II (3 Jan 2018) • RTS 4 and ESMA Q&A Oct 2017: The requirement to identify the clients and clients of clients in transaction and position reporting can not be waived. • For natural persons, the important identifiers are: passport number and CONCAT code combining nationality, first name and surname of position holder. • If a person is used, that person must be identified by their ID number, passport number, tax or national insurance number, depending on their nationality. • In the absence of this information, a concatenated code can be used consisting of date of birth, the first five characters of first name and the first five characters of surname. GDPR (25 May 2018) • Under GDPR investments firms are Data Controller. • Under MIFID II they are required to report disaggregated (i.e. Client, Client of Client etc.) reports. • Firms need to take steps to ensure that the data they report is accurate, and that appropriate consent is obtained to using individual’s data as part of transaction reporting, in a way that meets data protection requirements. • The safety, security and confidentiality of clients information stay with the investments firms Marjane Moghimi Nov 2017
  • 21. Regulation Overlap: MIFID II and GDPR MIFID II The name and date of birth in both side of the trade are mandatory part of trade, transaction and position reporting duties • Buyer • Buyer Decision Maker • Seller • Seller Decision Maker GDPR • Employees information are held in HR database • Counterparties information in Counterparty Data base. • Clients information in Client database ►You need to have specific consent from those data subject concerned by MIFID II ►Consents from all 1/3 parties are necessary if you have a legitimate interest in collecting their data Marjane Moghimi Nov 2017
  • 22. e-privacy • Is a Regulation coming into force the same date as GDPR • Will replace the current Directive • Its aim is high level of privacy and data protection • The new regulation will bring significant changes: – concern to all providers of electronic communication services • Include Facebook Messenger, Whatsapp, etc. – will apply to content and meta data – Simpler rules regarding cookies and spam – Needs for specific and free consents ; which can easily withdraw. – Put the emphasis on confidentiality of electronic communications data including while in transit and cover storage providers (including ’cloud’) • The regulation is still not finalised so some changes may come into light later. Marjane Moghimi Nov 2017
  • 23. Reference • Text: – http://ec.europa.eu/justice/data-protection/individuals/index_en.htm – https://gdpr-info.eu – ec.europa.eu/justice/ data-protection/reform/ files/regulation_oj_en.pdf • Summary: www.eugdpr.org/article-summaries.html • FAQs: www.eugdpr.org/gdpr-faqs.html • E-privacy: https://edps.europa.eu/sites/edp/files/publication/17-10- 05_edps_recommendations_on_ep_amendments_en.pdf Marjane Moghimi Nov 2017