@LibertyAppsUK@CYBERTALKLDN
GDPR
Understanding the
risks
@LibertyAppsUK@CYBERTALKLDN
Steve Hilton
@LibertyAppsUK@CYBERTALKLDN
Trusted Reviews
Apps That Mobilise Lives
4
Public Health England Hackathon winners
@LibertyAppsUK@CYBERTALKLDN
Liberty Apps
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
THE
IMPORTANT
STATS
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
GDPR compliance timeline
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Phase 1: Need to understand
@LibertyAppsUK@CYBERTALKLDN
Phase 2: Assess Risk
@LibertyAppsUK@CYBERTALKLDN
Phase 2: Assess Risk (1 of 2)
@LibertyAppsUK@CYBERTALKLDN
Phase 2: Assess Risk (2 of 2)
@LibertyAppsUK@CYBERTALKLDN
Phase 3: Implement
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Do we have a data retention policy?
It is down to the board of directors to decide what that retention
policy is, when and how will this approval be received? – data
must not be kept for any longer than is deemed necessary.
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
• How would we erase an individuals’ data?
• What is our process for correcting individuals’ data?
• Can we manage / remove consent for direct marketing and
automated decision making?
@LibertyAppsUK@CYBERTALKLDN
What will we do if a customer exercises their rights?
How would we handle a request?
What processes & policies do we have in place should we plan to refus
What will our partners whom we share data with need to do?
Do we have confidence that these partners are compliant and would no
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Employers can’t rely on employee consent to process HR
data
@LibertyAppsUK@CYBERTALKLDN
Employers can’t rely on employee consent to process HR
data
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
 What will we do if there is a breach?
 How would we detect, report and investigate a breach?
 To manage effective & efficient investigation:
Assess which types of data are held.
Document which types fall within the notification requirement
and the process to be followed if there is a breach.
@LibertyAppsUK@CYBERTALKLDN
Data Breach Notification
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/
@LibertyAppsUK@CYBERTALKLDN
Optimal data breach notification timeline
@LibertyAppsUK@CYBERTALKLDN
Incident occurs
@LibertyAppsUK@CYBERTALKLDN
Clock starts
@LibertyAppsUK@CYBERTALKLDN
Key decisions
@LibertyAppsUK@CYBERTALKLDN
Notifications
@LibertyAppsUK@CYBERTALKLDN
Post notification period
@LibertyAppsUK@CYBERTALKLDN
Data Breach Notification
@LibertyAppsUK@CYBERTALKLDN
How would we implement an assessment in our organisation?
Who would carry it out?
Would it be run centrally or locally?
@LibertyAppsUK@CYBERTALKLDN
A data protection impact assessment (DPIA) is a process to help
you identify and minimise the data protection risks of a project.
Data protection impact assessments (DPIA)
@LibertyAppsUK@CYBERTALKLDN
Data protection impact assessments (DPIA)
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Phase 4: Demonstrate
@LibertyAppsUK@CYBERTALKLDN
Control over processes that collect and use personal
data?
@LibertyAppsUK@CYBERTALKLDN
Appropriate measures?
@LibertyAppsUK@CYBERTALKLDN
Ability to respond?
@LibertyAppsUK@CYBERTALKLDN
Records of what we do?
@LibertyAppsUK@CYBERTALKLDN
A published Privacy Notice
@LibertyAppsUK@CYBERTALKLDN
Consent and individual rights management.
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Difficulty identifying and reporting a breach within 72
hours
2017 VERITAS GDPR REPORT
https://www.veritas.com/content/dam/Veritas/docs/reports/gdpr-report-ch2-en.pdf
@LibertyAppsUK@CYBERTALKLDN
Are former employees able to access company data?
2017 VERITAS GDPR REPORT
https://www.veritas.com/content/dam/Veritas/docs/reports/gdpr-report-ch2-en.pdf
@LibertyAppsUK@CYBERTALKLDN
The enemy within?
2017 Varonis Data Risk Report
https://info.varonis.com/hubfs/docs/research_reports/2017-data-risk-report.pdf
@LibertyAppsUK@CYBERTALKLDN
GDPR is an Evolutionary Process
@LibertyAppsUK@CYBERTALKLDN
Key Takeaway
@LibertyAppsUK@CYBERTALKLDN
Questions?Questions?
Steve@LibertyApps.co.
uk
@SteveHiltonCEO
+44 0161 883 2450
LibertyApps.co.uk

GDPR and Data Breach notifications