SlideShare a Scribd company logo
1 of 24
Applicability of GDPR and APPI to
international companies and the impact
on IT Security
Dr Matthias Lachenmann
Attorney-at-Law (Rechtsanwalt), Data Protection Officer (UDIScert)
@LAWchenmann
I. EU and Japan: new Trade Deals and Data Protection
Laws
II. Definition of personal data, personal information and PII
III. Applicability of the GDPR and the APPI
IV. IT Security documentation according to GDPR and APPI
V. Lessons learned
Content
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
EU and Japan: new Trade Deals and Data Protection Laws
A look back to 25 May 2018:
Applicability of the EU General Data Protection Regulation (GDPR)
EU and Japan: new Trade Deals and Data Protection Laws
Republic of Korea:
Personal Information Protection Act (PIPA),
since 30 September 2011
Several sector-specific Data Protection Laws
IT Security Act, applicable since 13 June
2019
Plans for a revision of the PIPA
India:
Personal Data Protection Bill 2018 (Draft)
China:
Cybersecurity-Law (CSG), since 1 June
2017
California:
California Consumer Privacy Act (CCPA),
will be valid from 2020© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Source: Greenleaf, Graham, Countries
with Data Privacy Laws – By Year 1973-
2019 (May 10, 2019), SSRN:
https://ssrn.com/abstract=3386510
New Trade Deals: EU-Japan Strategic Partnership
Agreement (SPA) and EU-Japan Economic
Partnership Agreement (EPA)
Biggest trade agreement concluded to date by the
EU
Covering over 600 million people and almost one third
of the world’s total GDP
Providing EU companies nondiscriminatory access as
suppliers to the procurement markets of 54 cities in
Japan
Clauses on labor rights, environmental protection,
intellectual property
Japanese adequacy decision regarding EU and EU
Commission’s adequacy decision regarding Japan
Both 23 January 2019
First adequacy decision since the GDPR came into
effect
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
EU and Japan: new Trade Deals and Data Protection Laws
EU and Japan: new Trade Deals and Data Protection Laws
Data Protection Laws and Rules in Japan relevant in international context:
Act on the Protection of Personal Information (“APPI”)
Updated version introduced 30.5.2017; first version introduced 30 May 2003
Cabinet Decision ("Basic Policy"), dated 12 June 2018
Binding provisions for all companies with APPI applicable
Enforcement Rules for the Act on the Protection of Personal
Information adopted by the PPC (“Enforcement Rules”)
Supplementary rules under the APPI for the handling of Personal Data
transferred from the EU based on an Adequacy Decision
(“Supplementary Rules”)
Established on 15 June 2018 by the Japanese data protection authority Personal
Information Protection Commission Japan (PPC)
Aiming at providing a higher level of data protection for EU data processed in
Japan
Only applicable for data received from EU entities© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
I. EU and Japan: new Trade Deals and Data Protection
Laws
II. Definition of personal data, personal information and PII
III. Applicability of the GDPR and the APPI
IV. IT Security documentation according to GDPR and APPI
V. Lessons learned
Content
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Definition of personal data, personal information and PII
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Types
of Data
PII: Personally
identifiable data
(USA)
Personal Data
(EU)
Special
categories of
personal data
(EU)
special care-
required
personal
information (JP)
Personal
Information (JP)
Personal Data
(JP)
Definition of personal data, personal information and PII
Personal Information (APPI): “information relating to a living individual”
Broad range: if any other entity may identify the person based on the information
Personal Data (GDPR): “all information relating to an identified or
identifiable living natural person (‘data subject’)”
PII (NIST): “any information about an individual maintained by an
agency”
Information linked or linkable to an individual
GDPR and APPI: Pseudonymous Data is Personal Data/Personal
Information!
All identifiable characteristics are replaced by identifiers
Including individual identification codes (even encrypted data)
Even if the Controller does not have access to the identifying information
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Definition of personal data, personal information and PII
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Type of Data PII (USA) Personal information (JP) Personal Data (EU)
Name, Address,
Date of birth
Social Security or
Credit Card No.
superman42@
hotmail.com
IP-Addresses, (IoT)
DeviceIDs
Online Identifiers
(CookieID, …)
Location Data
I. EU and Japan: new Trade Deals and Data Protection
Laws
II. Definition of personal data, personal information and PII
III. Applicability of the GDPR and the APPI
IV. IT Security documentation according to GDPR and APPI
V. Lessons learned
Content
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Applicability of the GDPR and the APPI
Basic Principles on international applicability of data protection laws:
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
1
2
3
Applicability of the GDPR and the APPI
Case 1:Collection of a Data Subject’s personal data by a entity located
within the same country as the Data Subject (one step)
Only the country’s laws of Data Subject’s and entity’s location apply
GDPR special provisions: territorial scope also applicable if the foreign
company has an establishment in Europe
The establishment in Europe does not need to process the data subject’s data
E.g. renting office space only for advertisement purposes
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
1
Applicability of the GDPR and the APPI
Case 2:First, collection of Personal Data within the Data Subject’s
country;
Second, transfer from the entity to an entity located in a third
country
GDPR requirements for third country transfers:
Full GDPR compliance only for first entity which collects the data
Appropriate safeguards, e.g. adequacy decision, Standard Contractual Clauses
(SCC)
For the receiving entity: bound to the provisions of Appropriate Safeguards,
GDPR compliant purposes and local laws and further provisions apply
APPI requirements for third country transfers:
To be based on a) equivalent standards set by PI Protection Commission, b)
contractual agreements to ensure equivalent standards or c) consent was© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
2
Applicability of the GDPR and the APPI
Case 3:Collection of a Data Subject’s personal data by an entity located in
another country than the data subject (third country)
Basis: local laws of the collecting entity apply
Additionally: extraterritorial scope in many Data Protection Laws
E.g. in Article 3 (2) GDPR, Article 75 APPI or § 1798.140 [c] CCPA
Even with no establishment in the country where the Data Subject is located
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
3
Applicability of the GDPR and the APPI
Case 3: GDPR’s scope on collection of personal data outside the EU,
Article 3 (2):
Entity aiming at Data Subjects located in the EU and
Entity offers goods or services in the EU or …
Applicable when obviously intending to offer services in EU member states
Examples: websites in an EU language, price labeling in local currency (e.g.
EUR)
… observing the behavior of Data Subjects located in EU
Activity linked with behavioral monitoring of Data Subjects taking place within the
EU
Special GDPR provisions with extraterritorial scope:
Designation of a Representative within the EU acc. Article 27© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
3
Applicability of the GDPR and the APPI
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
1 2 3
Applicable Data
Protection Law in Japan:
-
Applicable Data
Protection Law in Japan:
APPI
Basic Policy
Supplementary Rules
Enforcement Rules
GDPR purpose limitation
Applicable Data
Protection Law in Japan:
APPI
Basic Policy
Supplementary Rules
GDPR
I. EU and Japan: new Trade Deals and Data Protection
Laws
II. Definition of personal data, personal information and PII
III. Applicability of the GDPR and the APPI
IV. IT Security documentation according to GDPR and APPI
V. Lessons learned
Content
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
IT Security documentation according to GDPR and APPI
General Compliance obligations of the GDPR:
Accountability Principle (documentation of GDPR compliance)
Information obligations (supplying privacy policies for websites,
customers, …)
Rights of the data subject (access, correction, deletion, …)
Data protection by design and by default (considering GDPR when
planning)
Contract Data Processing (contracts to bind processing Service
Providers)
Records of processing activities (documentation of processing
operations)
Security of processing (technical and organizational measures)
Notification of a personal data breach (72 hour deadline to supervisory
authority)© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
IT Security documentation according to GDPR and APPI
Appropriate technical and
organizational measures, Article 32
GDPR, include:
the pseudonymization and
encryption of personal data
the ability to ensure the ongoing
confidentiality, integrity, availability
and resilience of processing systems
the ability to restore the availability
in a case of a Security incident;
a process for regularly testing,
assessing and evaluating the
effectiveness of the taken measures
Taking into account Costs and
Risks
GDPR stresses availability of data
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Security Control Action,
Article 20 APPI:
“A personal information handling
business operator shall take necessary
and appropriate action for the security
control of personal data
including preventing the leakage, loss
or damage of its handled personal data.”
APPI stresses minizing risks of data
loss
IT Security documentation according to GDPR and APPI
Recommended Documentation of IT Security Measures:
 Establishing procedures for a Data Security Process:
Management measures to protect personal data, …
General information:
Location of premises and data centers, processing systems,
…
Organizational control:
Management tasks, employee training, Review process, …
Description of the technical and administrative
measures:
Protection target: Confidentiality (Entry control, Admittance
control, Access control, Separation control)
Protection target: Integrity (Data circulation control, Entry
control)
Protection target: Availability (Availability control)© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Measures to
document IT
Security
Data Security
Process
Documentation
of IT Security
Measures
I. EU and Japan: new Trade Deals and Data Protection
Laws
II. Definition of personal data, personal information and PII
III. Applicability of the GDPR and the APPI
IV. IT Security documentation according to GDPR and APPI
V. Lessons learned
Content
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Lessons learned:
More data protection laws worldwide require data audits
Ensure tagging and documentation of all data, depending on applicable
law(s)
Personal Data/Information cover most information on identifiable
individuals
APPI offers possibilities on processing Anonymously Processed
Information
Most laws contain provisions on extraterritorial applicability
GDPR: Obligation to appoint a Representative acc. Article 27
Organize processing to avoid (full) GDPR applicability
Document IT Security measures
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Contact
BHO Legal
Hohenstaufenring 29-37
50674 Cologne
Germany
Tel.: + 49 (0) 221 270 956 0
E-Mail: cologne@bho-legal.com
© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
Dr. Matthias Lachenmann
Attorney-at-Law | Partner
Tel.: + 49 (0) 221 270 956 180
Cell: + 49 (0) 151 240 213 44
E-Mail: matthias.lachenmann@bho-legal.com

More Related Content

What's hot

20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security PrinciplesLisa Catanzaro
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Meteringnuances
 
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake Morgan
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
Sirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & LearnSirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & LearnIgnitionOne
 
Privacy and Data Protection in South Africa
Privacy and Data Protection in South AfricaPrivacy and Data Protection in South Africa
Privacy and Data Protection in South Africablogzilla
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
 
Uia presentation Eng
Uia presentation EngUia presentation Eng
Uia presentation EngFabio Marazzi
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-LatemAnn Van den Bunder
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoKeithBudden3
 
20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulationFebelmar
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanKrowdthink
 
Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...
Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...
Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...Alexander Loechel
 
Overview of PSI developments in Germany
Overview of PSI developments in Germany Overview of PSI developments in Germany
Overview of PSI developments in Germany Michael Fanning
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPRSpoon London
 

What's hot (20)

20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Metering
 
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012
 
Quick guide gdpr
Quick guide gdprQuick guide gdpr
Quick guide gdpr
 
Is Poland Ready for GDPR?
Is Poland Ready for GDPR? Is Poland Ready for GDPR?
Is Poland Ready for GDPR?
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
Sirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & LearnSirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & Learn
 
Privacy and Data Protection in South Africa
Privacy and Data Protection in South AfricaPrivacy and Data Protection in South Africa
Privacy and Data Protection in South Africa
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
EU Data Protection Regulation Skyhigh Networks
EU Data Protection Regulation Skyhigh NetworksEU Data Protection Regulation Skyhigh Networks
EU Data Protection Regulation Skyhigh Networks
 
Uia presentation Eng
Uia presentation EngUia presentation Eng
Uia presentation Eng
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth Boardman
 
Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...
Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...
Lightning Talk: Regulation (EU) 2018/1724 "Single Digital Gateway" & the "You...
 
Overview of PSI developments in Germany
Overview of PSI developments in Germany Overview of PSI developments in Germany
Overview of PSI developments in Germany
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 

Similar to [CB19] Applicability of GDPR and APPI to international companies and the impact on IT Security

GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookPlr-Printables
 
GDPR A Privacy Regime
GDPR A Privacy RegimeGDPR A Privacy Regime
GDPR A Privacy Regimeijtsrd
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterTrustArc
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Meteringnuances
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingJes Breslaw
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulationndcmanagement
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?EngageHub
 
How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...Carrenza
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.Matthias Dobbelaere-Welvaert
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Agustin Argelich Casals
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India SadanandGahivare
 
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...John Nas
 
United Kingdom GDPR Action Taken Against Canadian Company
United Kingdom GDPR Action Taken Against Canadian CompanyUnited Kingdom GDPR Action Taken Against Canadian Company
United Kingdom GDPR Action Taken Against Canadian CompanyBarry Schuman
 

Similar to [CB19] Applicability of GDPR and APPI to international companies and the impact on IT Security (20)

GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e book
 
GDPR A Privacy Regime
GDPR A Privacy RegimeGDPR A Privacy Regime
GDPR A Privacy Regime
 
DPA and GDPR
DPA and GDPRDPA and GDPR
DPA and GDPR
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-masking
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Privacy Year In Preview
Privacy Year In PreviewPrivacy Year In Preview
Privacy Year In Preview
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
Didier Reynders letter to the EU Parliament
Didier Reynders letter to the EU ParliamentDidier Reynders letter to the EU Parliament
Didier Reynders letter to the EU Parliament
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
Data protection
Data protectionData protection
Data protection
 
How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India
 
Are you compliant?
Are you compliant?Are you compliant?
Are you compliant?
 
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
 
United Kingdom GDPR Action Taken Against Canadian Company
United Kingdom GDPR Action Taken Against Canadian CompanyUnited Kingdom GDPR Action Taken Against Canadian Company
United Kingdom GDPR Action Taken Against Canadian Company
 

More from CODE BLUE

[cb22] Hayabusa Threat Hunting and Fast Forensics in Windows environments fo...
[cb22] Hayabusa  Threat Hunting and Fast Forensics in Windows environments fo...[cb22] Hayabusa  Threat Hunting and Fast Forensics in Windows environments fo...
[cb22] Hayabusa Threat Hunting and Fast Forensics in Windows environments fo...CODE BLUE
 
[cb22] Tales of 5G hacking by Karsten Nohl
[cb22] Tales of 5G hacking by Karsten Nohl[cb22] Tales of 5G hacking by Karsten Nohl
[cb22] Tales of 5G hacking by Karsten NohlCODE BLUE
 
[cb22] Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...
[cb22]  Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...[cb22]  Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...
[cb22] Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...CODE BLUE
 
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...CODE BLUE
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之CODE BLUE
 
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...CODE BLUE
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo PupilloCODE BLUE
 
[cb22] ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...
[cb22]  ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...[cb22]  ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...
[cb22] ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...CODE BLUE
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman
[cb22]  「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman [cb22]  「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman CODE BLUE
 
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...CODE BLUE
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by 高橋 郁夫
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by  高橋 郁夫[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by  高橋 郁夫
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by 高橋 郁夫CODE BLUE
 
[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...
[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...
[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...CODE BLUE
 
[cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka
[cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka [cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka
[cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka CODE BLUE
 
[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...
[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...
[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...CODE BLUE
 
[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...
[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...
[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...CODE BLUE
 
[cb22] From Parroting to Echoing: The Evolution of China’s Bots-Driven Info...
[cb22]  From Parroting to Echoing:  The Evolution of China’s Bots-Driven Info...[cb22]  From Parroting to Echoing:  The Evolution of China’s Bots-Driven Info...
[cb22] From Parroting to Echoing: The Evolution of China’s Bots-Driven Info...CODE BLUE
 
[cb22] Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...
[cb22]  Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...[cb22]  Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...
[cb22] Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...CODE BLUE
 
[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也
[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也
[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也CODE BLUE
 
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...CODE BLUE
 
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...CODE BLUE
 

More from CODE BLUE (20)

[cb22] Hayabusa Threat Hunting and Fast Forensics in Windows environments fo...
[cb22] Hayabusa  Threat Hunting and Fast Forensics in Windows environments fo...[cb22] Hayabusa  Threat Hunting and Fast Forensics in Windows environments fo...
[cb22] Hayabusa Threat Hunting and Fast Forensics in Windows environments fo...
 
[cb22] Tales of 5G hacking by Karsten Nohl
[cb22] Tales of 5G hacking by Karsten Nohl[cb22] Tales of 5G hacking by Karsten Nohl
[cb22] Tales of 5G hacking by Karsten Nohl
 
[cb22] Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...
[cb22]  Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...[cb22]  Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...
[cb22] Your Printer is not your Printer ! - Hacking Printers at Pwn2Own by A...
 
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(4) by 板橋 博之
 
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(3) by Lorenzo Pupillo
 
[cb22] ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...
[cb22]  ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...[cb22]  ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...
[cb22] ”The Present and Future of Coordinated Vulnerability Disclosure” Inte...
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman
[cb22]  「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman [cb22]  「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション(2)by Allan Friedman
 
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
[cb22] "The Present and Future of Coordinated Vulnerability Disclosure" Inter...
 
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by 高橋 郁夫
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by  高橋 郁夫[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by  高橋 郁夫
[cb22] 「協調された脆弱性開示の現在と未来」国際的なパネルディスカッション (1)by 高橋 郁夫
 
[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...
[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...
[cb22] Are Embedded Devices Ready for ROP Attacks? -ROP verification for low-...
 
[cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka
[cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka [cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka
[cb22] Wslinkのマルチレイヤーな仮想環境について by Vladislav Hrčka
 
[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...
[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...
[cb22] Under the hood of Wslink’s multilayered virtual machine en by Vladisla...
 
[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...
[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...
[cb22] CloudDragon’s Credential Factory is Powering Up Its Espionage Activiti...
 
[cb22] From Parroting to Echoing: The Evolution of China’s Bots-Driven Info...
[cb22]  From Parroting to Echoing:  The Evolution of China’s Bots-Driven Info...[cb22]  From Parroting to Echoing:  The Evolution of China’s Bots-Driven Info...
[cb22] From Parroting to Echoing: The Evolution of China’s Bots-Driven Info...
 
[cb22] Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...
[cb22]  Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...[cb22]  Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...
[cb22] Who is the Mal-Gopher? - Implementation and Evaluation of “gimpfuzzy”...
 
[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也
[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也
[cb22] Mal-gopherとは?Go系マルウェアの分類のためのgimpfuzzy実装と評価 by 澤部 祐太, 甘粕 伸幸, 野村 和也
 
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
 
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
[cb22] Fight Against Malware Development Life Cycle by Shusei Tomonaga and Yu...
 

Recently uploaded

Motivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdfMotivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdfakankshagupta7348026
 
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...Krijn Poppe
 
George Lever - eCommerce Day Chile 2024
George Lever -  eCommerce Day Chile 2024George Lever -  eCommerce Day Chile 2024
George Lever - eCommerce Day Chile 2024eCommerce Institute
 
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...NETWAYS
 
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdfCTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdfhenrik385807
 
SBFT Tool Competition 2024 - CPS-UAV Test Case Generation Track
SBFT Tool Competition 2024 - CPS-UAV Test Case Generation TrackSBFT Tool Competition 2024 - CPS-UAV Test Case Generation Track
SBFT Tool Competition 2024 - CPS-UAV Test Case Generation TrackSebastiano Panichella
 
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...NETWAYS
 
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...Salam Al-Karadaghi
 
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝soniya singh
 
Philippine History cavite Mutiny Report.ppt
Philippine History cavite Mutiny Report.pptPhilippine History cavite Mutiny Report.ppt
Philippine History cavite Mutiny Report.pptssuser319dad
 
WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )
WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )
WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )Pooja Nehwal
 
Work Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxWork Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxmavinoikein
 
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...Kayode Fayemi
 
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)Basil Achie
 
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...NETWAYS
 
The 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software EngineeringThe 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software EngineeringSebastiano Panichella
 
Russian Call Girls in Kolkata Vaishnavi 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Vaishnavi 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Vaishnavi 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Vaishnavi 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSimulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSebastiano Panichella
 
SBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation TrackSBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation TrackSebastiano Panichella
 
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024eCommerce Institute
 

Recently uploaded (20)

Motivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdfMotivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdf
 
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
 
George Lever - eCommerce Day Chile 2024
George Lever -  eCommerce Day Chile 2024George Lever -  eCommerce Day Chile 2024
George Lever - eCommerce Day Chile 2024
 
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
 
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdfCTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
 
SBFT Tool Competition 2024 - CPS-UAV Test Case Generation Track
SBFT Tool Competition 2024 - CPS-UAV Test Case Generation TrackSBFT Tool Competition 2024 - CPS-UAV Test Case Generation Track
SBFT Tool Competition 2024 - CPS-UAV Test Case Generation Track
 
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
 
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
 
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
 
Philippine History cavite Mutiny Report.ppt
Philippine History cavite Mutiny Report.pptPhilippine History cavite Mutiny Report.ppt
Philippine History cavite Mutiny Report.ppt
 
WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )
WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )
WhatsApp 📞 9892124323 ✅Call Girls In Juhu ( Mumbai )
 
Work Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxWork Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptx
 
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
 
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
 
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
 
The 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software EngineeringThe 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software Engineering
 
Russian Call Girls in Kolkata Vaishnavi 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Vaishnavi 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Vaishnavi 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Vaishnavi 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSimulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
 
SBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation TrackSBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation Track
 
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
 

[CB19] Applicability of GDPR and APPI to international companies and the impact on IT Security

  • 1. Applicability of GDPR and APPI to international companies and the impact on IT Security Dr Matthias Lachenmann Attorney-at-Law (Rechtsanwalt), Data Protection Officer (UDIScert) @LAWchenmann
  • 2. I. EU and Japan: new Trade Deals and Data Protection Laws II. Definition of personal data, personal information and PII III. Applicability of the GDPR and the APPI IV. IT Security documentation according to GDPR and APPI V. Lessons learned Content © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 3. EU and Japan: new Trade Deals and Data Protection Laws A look back to 25 May 2018: Applicability of the EU General Data Protection Regulation (GDPR)
  • 4. EU and Japan: new Trade Deals and Data Protection Laws Republic of Korea: Personal Information Protection Act (PIPA), since 30 September 2011 Several sector-specific Data Protection Laws IT Security Act, applicable since 13 June 2019 Plans for a revision of the PIPA India: Personal Data Protection Bill 2018 (Draft) China: Cybersecurity-Law (CSG), since 1 June 2017 California: California Consumer Privacy Act (CCPA), will be valid from 2020© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 Source: Greenleaf, Graham, Countries with Data Privacy Laws – By Year 1973- 2019 (May 10, 2019), SSRN: https://ssrn.com/abstract=3386510
  • 5. New Trade Deals: EU-Japan Strategic Partnership Agreement (SPA) and EU-Japan Economic Partnership Agreement (EPA) Biggest trade agreement concluded to date by the EU Covering over 600 million people and almost one third of the world’s total GDP Providing EU companies nondiscriminatory access as suppliers to the procurement markets of 54 cities in Japan Clauses on labor rights, environmental protection, intellectual property Japanese adequacy decision regarding EU and EU Commission’s adequacy decision regarding Japan Both 23 January 2019 First adequacy decision since the GDPR came into effect © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 EU and Japan: new Trade Deals and Data Protection Laws
  • 6. EU and Japan: new Trade Deals and Data Protection Laws Data Protection Laws and Rules in Japan relevant in international context: Act on the Protection of Personal Information (“APPI”) Updated version introduced 30.5.2017; first version introduced 30 May 2003 Cabinet Decision ("Basic Policy"), dated 12 June 2018 Binding provisions for all companies with APPI applicable Enforcement Rules for the Act on the Protection of Personal Information adopted by the PPC (“Enforcement Rules”) Supplementary rules under the APPI for the handling of Personal Data transferred from the EU based on an Adequacy Decision (“Supplementary Rules”) Established on 15 June 2018 by the Japanese data protection authority Personal Information Protection Commission Japan (PPC) Aiming at providing a higher level of data protection for EU data processed in Japan Only applicable for data received from EU entities© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 7. I. EU and Japan: new Trade Deals and Data Protection Laws II. Definition of personal data, personal information and PII III. Applicability of the GDPR and the APPI IV. IT Security documentation according to GDPR and APPI V. Lessons learned Content © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 8. Definition of personal data, personal information and PII © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 Types of Data PII: Personally identifiable data (USA) Personal Data (EU) Special categories of personal data (EU) special care- required personal information (JP) Personal Information (JP) Personal Data (JP)
  • 9. Definition of personal data, personal information and PII Personal Information (APPI): “information relating to a living individual” Broad range: if any other entity may identify the person based on the information Personal Data (GDPR): “all information relating to an identified or identifiable living natural person (‘data subject’)” PII (NIST): “any information about an individual maintained by an agency” Information linked or linkable to an individual GDPR and APPI: Pseudonymous Data is Personal Data/Personal Information! All identifiable characteristics are replaced by identifiers Including individual identification codes (even encrypted data) Even if the Controller does not have access to the identifying information © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 10. Definition of personal data, personal information and PII © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 Type of Data PII (USA) Personal information (JP) Personal Data (EU) Name, Address, Date of birth Social Security or Credit Card No. superman42@ hotmail.com IP-Addresses, (IoT) DeviceIDs Online Identifiers (CookieID, …) Location Data
  • 11. I. EU and Japan: new Trade Deals and Data Protection Laws II. Definition of personal data, personal information and PII III. Applicability of the GDPR and the APPI IV. IT Security documentation according to GDPR and APPI V. Lessons learned Content © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 12. Applicability of the GDPR and the APPI Basic Principles on international applicability of data protection laws: © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 1 2 3
  • 13. Applicability of the GDPR and the APPI Case 1:Collection of a Data Subject’s personal data by a entity located within the same country as the Data Subject (one step) Only the country’s laws of Data Subject’s and entity’s location apply GDPR special provisions: territorial scope also applicable if the foreign company has an establishment in Europe The establishment in Europe does not need to process the data subject’s data E.g. renting office space only for advertisement purposes © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 1
  • 14. Applicability of the GDPR and the APPI Case 2:First, collection of Personal Data within the Data Subject’s country; Second, transfer from the entity to an entity located in a third country GDPR requirements for third country transfers: Full GDPR compliance only for first entity which collects the data Appropriate safeguards, e.g. adequacy decision, Standard Contractual Clauses (SCC) For the receiving entity: bound to the provisions of Appropriate Safeguards, GDPR compliant purposes and local laws and further provisions apply APPI requirements for third country transfers: To be based on a) equivalent standards set by PI Protection Commission, b) contractual agreements to ensure equivalent standards or c) consent was© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 2
  • 15. Applicability of the GDPR and the APPI Case 3:Collection of a Data Subject’s personal data by an entity located in another country than the data subject (third country) Basis: local laws of the collecting entity apply Additionally: extraterritorial scope in many Data Protection Laws E.g. in Article 3 (2) GDPR, Article 75 APPI or § 1798.140 [c] CCPA Even with no establishment in the country where the Data Subject is located © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 3
  • 16. Applicability of the GDPR and the APPI Case 3: GDPR’s scope on collection of personal data outside the EU, Article 3 (2): Entity aiming at Data Subjects located in the EU and Entity offers goods or services in the EU or … Applicable when obviously intending to offer services in EU member states Examples: websites in an EU language, price labeling in local currency (e.g. EUR) … observing the behavior of Data Subjects located in EU Activity linked with behavioral monitoring of Data Subjects taking place within the EU Special GDPR provisions with extraterritorial scope: Designation of a Representative within the EU acc. Article 27© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 3
  • 17. Applicability of the GDPR and the APPI © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 1 2 3 Applicable Data Protection Law in Japan: - Applicable Data Protection Law in Japan: APPI Basic Policy Supplementary Rules Enforcement Rules GDPR purpose limitation Applicable Data Protection Law in Japan: APPI Basic Policy Supplementary Rules GDPR
  • 18. I. EU and Japan: new Trade Deals and Data Protection Laws II. Definition of personal data, personal information and PII III. Applicability of the GDPR and the APPI IV. IT Security documentation according to GDPR and APPI V. Lessons learned Content © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 19. IT Security documentation according to GDPR and APPI General Compliance obligations of the GDPR: Accountability Principle (documentation of GDPR compliance) Information obligations (supplying privacy policies for websites, customers, …) Rights of the data subject (access, correction, deletion, …) Data protection by design and by default (considering GDPR when planning) Contract Data Processing (contracts to bind processing Service Providers) Records of processing activities (documentation of processing operations) Security of processing (technical and organizational measures) Notification of a personal data breach (72 hour deadline to supervisory authority)© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 20. IT Security documentation according to GDPR and APPI Appropriate technical and organizational measures, Article 32 GDPR, include: the pseudonymization and encryption of personal data the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems the ability to restore the availability in a case of a Security incident; a process for regularly testing, assessing and evaluating the effectiveness of the taken measures Taking into account Costs and Risks GDPR stresses availability of data © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 Security Control Action, Article 20 APPI: “A personal information handling business operator shall take necessary and appropriate action for the security control of personal data including preventing the leakage, loss or damage of its handled personal data.” APPI stresses minizing risks of data loss
  • 21. IT Security documentation according to GDPR and APPI Recommended Documentation of IT Security Measures:  Establishing procedures for a Data Security Process: Management measures to protect personal data, … General information: Location of premises and data centers, processing systems, … Organizational control: Management tasks, employee training, Review process, … Description of the technical and administrative measures: Protection target: Confidentiality (Entry control, Admittance control, Access control, Separation control) Protection target: Integrity (Data circulation control, Entry control) Protection target: Availability (Availability control)© BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 Measures to document IT Security Data Security Process Documentation of IT Security Measures
  • 22. I. EU and Japan: new Trade Deals and Data Protection Laws II. Definition of personal data, personal information and PII III. Applicability of the GDPR and the APPI IV. IT Security documentation according to GDPR and APPI V. Lessons learned Content © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 23. Lessons learned: More data protection laws worldwide require data audits Ensure tagging and documentation of all data, depending on applicable law(s) Personal Data/Information cover most information on identifiable individuals APPI offers possibilities on processing Anonymously Processed Information Most laws contain provisions on extraterritorial applicability GDPR: Obligation to appoint a Representative acc. Article 27 Organize processing to avoid (full) GDPR applicability Document IT Security measures © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019
  • 24. Contact BHO Legal Hohenstaufenring 29-37 50674 Cologne Germany Tel.: + 49 (0) 221 270 956 0 E-Mail: cologne@bho-legal.com © BHO Legal, 2019 | Dr. Matthias Lachenmann | Code Blue Conference | 30 October 2019 Dr. Matthias Lachenmann Attorney-at-Law | Partner Tel.: + 49 (0) 221 270 956 180 Cell: + 49 (0) 151 240 213 44 E-Mail: matthias.lachenmann@bho-legal.com