SlideShare a Scribd company logo
1 of 7
Download to read offline
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 1
May 1, 2018
RE: European Union General Data Protection Regulation (GDPR) Checklist
Greetings,
Our firm has prepared an overview of the European Union’s General Data Protection
Regulation (GDPR) that was approved by the European Commission in April 2016. This regulation
is going into effect imminently, and companies need to be in compliance by May 25, 2018.
The GDPR imposes enhanced requirements on all businesses operating in the EU, which
includes those processing personal data in the EU and transferring data from the EU. It aims to
create a more consistent data protection regime, while providing EU citizens better control over
the use of their information by creating new rights.
The following is a checklist of items that serves as a guideline for what companies have to
do before May 25, 2018, to ensure GDPR compliance. Gagnier Margossian LLP is advising its
clients to undergo this compliance implementation immediately.
Item Compliance
Status
1. Assess the risk and identify areas that could cause compliance problems under
the GDPR.
- Fines for non-compliance can be up to 20 million Euros or 4% of the
company’s annual global turnover.
- Additionally, collective actions can be filed by consumer associations.
2. Make sure to document:
- The personal data the company holds/collects;
- Where the information came from;
- Where the information is stored;
- How the information is processed;
- How the information it protected; and
- With whom it is shared (annual audits are now a necessity for
recordkeeping).
3. Maintain detailed records of the processing performed on personal data. This
must include:
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 2
- Determining the types of data processing being carried out;
- Identifying the basis for carrying it out; and
- Documenting the basis.
- The company will have to explain their legal basis for processing data in their
privacy notice and when they respond to a subject access request.
4. Evaluate the company’s policies and procedures to ensure they take into
account all the rights individuals have under the GDPR, including the:
- Right to access information;
- Right to correct inaccuracies;
- Right to have information erased (the right to be forgotten) without undue
delay; and
- Right to withdraw consent at any time, which must be an easy to access
process.
5. Companies must also:
- Prevent direct marketing;
- Prevent automated decision-making and profiling; and
- Provide data electronically and in a commonly used format (data portability).
6. Draft or revise security policies, which should include implementing appropriate
technical and organizational measures, taking into account the nature, scope,
context and purposes for processing as well as the risk of varying likelihood and
severity for the rights and freedoms of individuals. Security actions may include:
- The pseudonymisation and encryption of personal data;
- The ability to ensure the ongoing confidentiality, integrity, availability and
resilience of systems and services processing personal data;
- The ability to restore the availability and access to data in a timely manner in
the event of a physical or technical incident; and
- A process for regularly testing, assessing and evaluating the effectiveness of
technical and organizational measure for ensuring the security of the
processing.
- NOTE: Controllers or processors that adhere to either an approved code of
conduct or an approved certification mechanism can use these tools to
demonstrate compliance with the GDPR’s security standards.
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 3
7. Ensure procedures are in place to continually monitor compliance with these
policies, including the security policies, prior to, during and after processing of
personal data.
- Additionally, perform a gap assessment and consider participation in
certification programs.
8. Before collecting personal data, the company must disclose:
- The identity of the controller;
- The purposes for processing;
- Any recipients of personal data; and
How long the data will be stored.
- Disclosures must be intelligible and easily accessible, using clear and plain
language.
9. Additionally, the company must inform data subjects of their:
- Right to withdraw consent at any time;
- Right to request access, rectification or restriction of processing; and
- Right to lodge a complaint to a supervisory authority.
10. Review how the company is seeking, obtaining and recording consent. The
company must comply with the following requirements.
- Consent must be “freely given, specific, informed and unambiguous (opt in),”
or it is explicit (the higher standard). This should include assessing whether
the company’s audit trail for such consent is effective and whether they need
to make any changes. Consent must be referenced in the company Privacy
Policy.
o Consent is not freely given if there is a clear imbalance between the
data subject and the controller, in particular, where the controller is a
public authority.
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 4
o Additionally, the controller cannot make a service conditional upon
consent, unless the processing is necessary for the service.
- To show consent, the data subject must signal agreement by “a statement or
clear affirmative action.”
- Consent must be specific to each data processing operations.
- Data subjects must be informed about their right to withdraw consent at
anytime, before they give their consent.
- The controller must provide “accurate and full information on all relevant
issues,” including the nature of the data that will be process, the purposes of
processing, the identity of the controller and the identity of any other
recipients of the data.
- Your company’s customers should explicitly reference use of your company’s
platform and technologies in their policies. This is a reliable means to put the
public on Notice and ensure Consent at this juncture.
11. Review current privacy notices and make necessary changes to include the
additional communication requirements to individuals on:
- The legal basis for processing data;
- The data retention periods; and
- The individual’s right to complain if the individual believes the data is being
mishandled.
12. Update the company’s procedures and/or amend retention policies if necessary
to comply with GDPR requirements, including:
- Privacy policies are easily accessible, written in clear and plain language, and
include full disclosure of your data collection and processing;
- Disclosure of data retention policies;
- Respect to access requests within a month; and
- Allow individuals to correct inaccurate information about them.
13. The company should conduct a thorough data privacy impact assessment where
data processing operations may lead to high risks to data subjects’ personal data.
- The company should refer and implement the provisions of the Information
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 5
Commissioners Office’s guidance on Privacy Impact Assessments.
14. Ensure the company has proper procedures in place to detect, report and
investigate a data breach in which individuals are likely to suffer some form of
damage. To comply with this requirement, the company should do the following:
- Assess the types of data the company holds;
- Document which type of data would trigger notice if there was a breach;
and
- Develop appropriate policies and procedures.
15. The company must comply with the following notification requirements when a
breach occurs:
- If a data processor experiences a personal data breach, it must notify the
controller but otherwise has no other notification or reported obligation
under the GDPR.
- If a breach occurs the company (controller) is required to notify privacy
regulators of the data breach within seventy-two (72) hours after the breach
is discovered.
o If notification is not made within seventy-two (72) hours, the
controller must provide a “reasoned justification” for the delay.
o There is an exception to the supervisory authority notification
requirement that states notice is not required if the personal data
breach is unlikely to result in a risk for the rights and freedoms of
individuals.
- When notifying the supervisory authority, the notification must:
• Describe the nature of the personal data breach, including the number
and categories of data subjects and data records affected;
• Provide the data protection officer’s contact information;
• Describe the likely consequences of the personal data breach; and
• Describe how the controller proposes to address the breach, including
any mitigation efforts.
16. Data subjects will also need to be notified “without undue delay” where a
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 6
breach poses a high risk to the data subject’s rights and freedoms. However,
there is an exception to the requirement to notify data subjects in the following
circumstances:
o The controller has “implemented appropriate technical and
organizational protection measures” that “render the data
unintelligible to any person who is not authorized to access it, such as
encryption;”
o The controller takes actions subsequent to the personal data breach
to “ensure that the high risk for the rights and freedoms of data
subjects” is unlikely to materialize; or
o When notification to each data subject would “involve
disproportionate effort,” in which case alternative communication
measures may be used.
17. Limit data collection to the minimum necessary (data minimization) and adopt a
“privacy by design” approach to projects, which promotes privacy and data
protection compliance from the beginning.
- Ensure the company collects the minimum amount of personal data
necessary for the proper performance of the products and services.
18. Controllers and Processors of personal information must designate a Data
Protection Officer (DPO) when:
- The processing is carried out by a public authority or body; or
- The controller’s or processor’s core activities require regular and systematic
monitoring of data subjects on a large scale or consist of “processing on a
large scale of special categories of data.”
19. The DPO must be “designated on the basis of professional qualities and, in
particular, expert knowledge of data protection law and practices.”
The DPO must have the authority and independence to inform the company of
its obligations under GDPR, and must have the ability to fulfill the tasks
designated, such as regulatory compliance, training staff on proper data handling
and coordinating with the supervisory authority, with an ability to understand
and balance data processing risks.
2352 Market Street
San Francisco, CA 94114
T: 415.795.1572
F: 909.972.1639
gamallp.com
	
	 7
The DPO also needs to monitor compliance and conduct internal audits.
The DPO will be the company’s point of contact for data subjects’ inquiries,
withdrawals of consent, right to be forgotten requests and other related rights.
NOTE: Our law firm will be providing these services to companies.
20. Consider putting systems in place to verify individuals’ ages and to gather
parental or guardian consent for any data processing activity involving children
under thirteen (13) years of age. If such information is involved, the privacy
notice will need to be drafted in a manner understandable by children.
21. Review Binding Corporate Rules (BCRs) or Standard Contractual Clauses
(SCCs) for trans-Atlantic data flows for compliance with new requirements of
GDPR.
Draft addendums to SCCs and other contracts as necessary to address the
onward transfer restrictions, which includes ensuring that downstream entities
comply with limitations on purpose and meet all the requirements, including
remediating any unauthorized processing by the downstream entity.
Need guidance?
Contact Christina Gagnier, lead of GAMA’s Global Data Privacy Practice.
gagnier@gamallp.com
415.795.1572

More Related Content

What's hot

Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidencePrecisely
 
General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018Fraser Hay
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPRNeha Patel
 
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
GDPR Compliance Software | General Data Protection Regulation (GDPR) DashboardGDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
GDPR Compliance Software | General Data Protection Regulation (GDPR) DashboardCorporater
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPRGDPR Course
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Happiest Minds Technologies
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European unionRohana K Amarakoon
 
Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPRMissMarvel70
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Kimberly Simon MBA
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsChris Doolittle
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role HackerOne
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarSagittarius
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterBrowne Jacobson LLP
 

What's hot (20)

An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with Confidence
 
General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
GDPR Compliance Software | General Data Protection Regulation (GDPR) DashboardGDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Smart grid
Smart gridSmart grid
Smart grid
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
GDPR Jennifer Rose
GDPR Jennifer RoseGDPR Jennifer Rose
GDPR Jennifer Rose
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPR
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It Webinar
 
What is GDPR ? by M32
What is GDPR ? by M32What is GDPR ? by M32
What is GDPR ? by M32
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 

Similar to European Union General Data Protection Regulation (GDPR) Checklist

European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistChristina Gagnier
 
EU Privacy Shield Self Certification
EU Privacy Shield Self Certification EU Privacy Shield Self Certification
EU Privacy Shield Self Certification Christina Gagnier
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteSilverTech
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...TrustArc
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsUlf Mattsson
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)Napier University
 
Guide to Prospective European Union - United States Privacy Shield Program
Guide to Prospective European Union - United States Privacy Shield ProgramGuide to Prospective European Union - United States Privacy Shield Program
Guide to Prospective European Union - United States Privacy Shield ProgramChristina Gagnier
 
Paul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore ToolPaul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore ToolSagittarius
 
California Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowCalifornia Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowTokenEx
 

Similar to European Union General Data Protection Regulation (GDPR) Checklist (20)

European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation Checklist
 
EU Privacy Shield Self Certification
EU Privacy Shield Self Certification EU Privacy Shield Self Certification
EU Privacy Shield Self Certification
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
Ichec dig strat gdpr
Ichec dig strat gdpr Ichec dig strat gdpr
Ichec dig strat gdpr
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
Guide to Prospective European Union - United States Privacy Shield Program
Guide to Prospective European Union - United States Privacy Shield ProgramGuide to Prospective European Union - United States Privacy Shield Program
Guide to Prospective European Union - United States Privacy Shield Program
 
Paul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore ToolPaul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore Tool
 
California Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowCalifornia Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To Know
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 

More from Christina Gagnier

The United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsThe United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsChristina Gagnier
 
Regulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarRegulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarChristina Gagnier
 
China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"Christina Gagnier
 
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaInitial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaChristina Gagnier
 
Conducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsConducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsChristina Gagnier
 
SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017Christina Gagnier
 
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Christina Gagnier
 
Student Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomStudent Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomChristina Gagnier
 
Gender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsGender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsChristina Gagnier
 
ABC's of Privacy and Security
ABC's of Privacy and SecurityABC's of Privacy and Security
ABC's of Privacy and SecurityChristina Gagnier
 
Starting a Business: The Legal Details
Starting a Business: The Legal DetailsStarting a Business: The Legal Details
Starting a Business: The Legal DetailsChristina Gagnier
 
GAMABrief: What Every School Needs to Know About Copyright Law
GAMABrief: What Every School Needs to Know About Copyright LawGAMABrief: What Every School Needs to Know About Copyright Law
GAMABrief: What Every School Needs to Know About Copyright LawChristina Gagnier
 
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)Christina Gagnier
 
GAMABrief: Preparing for the Capital Gains Tax Hike
GAMABrief: Preparing for the Capital Gains Tax HikeGAMABrief: Preparing for the Capital Gains Tax Hike
GAMABrief: Preparing for the Capital Gains Tax HikeChristina Gagnier
 
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Christina Gagnier
 
Revenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentRevenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentChristina Gagnier
 
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...Christina Gagnier
 
Seth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingSeth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingChristina Gagnier
 
Student Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomStudent Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomChristina Gagnier
 
Employees, Employers & Social Media
Employees, Employers & Social MediaEmployees, Employers & Social Media
Employees, Employers & Social MediaChristina Gagnier
 

More from Christina Gagnier (20)

The United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsThe United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin Offerings
 
Regulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarRegulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in Gibraltar
 
China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"
 
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaInitial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
 
Conducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsConducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and Considerations
 
SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017
 
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
 
Student Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomStudent Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the Classroom
 
Gender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsGender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All Students
 
ABC's of Privacy and Security
ABC's of Privacy and SecurityABC's of Privacy and Security
ABC's of Privacy and Security
 
Starting a Business: The Legal Details
Starting a Business: The Legal DetailsStarting a Business: The Legal Details
Starting a Business: The Legal Details
 
GAMABrief: What Every School Needs to Know About Copyright Law
GAMABrief: What Every School Needs to Know About Copyright LawGAMABrief: What Every School Needs to Know About Copyright Law
GAMABrief: What Every School Needs to Know About Copyright Law
 
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
GAMAByte: The Legal Ramifications of Going 3D (Printing, That is)
 
GAMABrief: Preparing for the Capital Gains Tax Hike
GAMABrief: Preparing for the Capital Gains Tax HikeGAMABrief: Preparing for the Capital Gains Tax Hike
GAMABrief: Preparing for the Capital Gains Tax Hike
 
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
 
Revenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentRevenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without Consent
 
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
Understanding "Cyber" Bullying: California Law & Proactive Steps for School D...
 
Seth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingSeth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" Bullying
 
Student Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomStudent Privacy Rights in the Classroom
Student Privacy Rights in the Classroom
 
Employees, Employers & Social Media
Employees, Employers & Social MediaEmployees, Employers & Social Media
Employees, Employers & Social Media
 

Recently uploaded

Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceMichael Cicero
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一st Las
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书FS LS
 
An Analysis of the Essential Commodities Act, 1955
An Analysis of the Essential Commodities Act, 1955An Analysis of the Essential Commodities Act, 1955
An Analysis of the Essential Commodities Act, 1955Abheet Mangleek
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书SD DS
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxAbhishekchatterjee248859
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书SD DS
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一jr6r07mb
 

Recently uploaded (20)

Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
 
An Analysis of the Essential Commodities Act, 1955
An Analysis of the Essential Commodities Act, 1955An Analysis of the Essential Commodities Act, 1955
An Analysis of the Essential Commodities Act, 1955
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptx
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
 

European Union General Data Protection Regulation (GDPR) Checklist

  • 1. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 1 May 1, 2018 RE: European Union General Data Protection Regulation (GDPR) Checklist Greetings, Our firm has prepared an overview of the European Union’s General Data Protection Regulation (GDPR) that was approved by the European Commission in April 2016. This regulation is going into effect imminently, and companies need to be in compliance by May 25, 2018. The GDPR imposes enhanced requirements on all businesses operating in the EU, which includes those processing personal data in the EU and transferring data from the EU. It aims to create a more consistent data protection regime, while providing EU citizens better control over the use of their information by creating new rights. The following is a checklist of items that serves as a guideline for what companies have to do before May 25, 2018, to ensure GDPR compliance. Gagnier Margossian LLP is advising its clients to undergo this compliance implementation immediately. Item Compliance Status 1. Assess the risk and identify areas that could cause compliance problems under the GDPR. - Fines for non-compliance can be up to 20 million Euros or 4% of the company’s annual global turnover. - Additionally, collective actions can be filed by consumer associations. 2. Make sure to document: - The personal data the company holds/collects; - Where the information came from; - Where the information is stored; - How the information is processed; - How the information it protected; and - With whom it is shared (annual audits are now a necessity for recordkeeping). 3. Maintain detailed records of the processing performed on personal data. This must include:
  • 2. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 2 - Determining the types of data processing being carried out; - Identifying the basis for carrying it out; and - Documenting the basis. - The company will have to explain their legal basis for processing data in their privacy notice and when they respond to a subject access request. 4. Evaluate the company’s policies and procedures to ensure they take into account all the rights individuals have under the GDPR, including the: - Right to access information; - Right to correct inaccuracies; - Right to have information erased (the right to be forgotten) without undue delay; and - Right to withdraw consent at any time, which must be an easy to access process. 5. Companies must also: - Prevent direct marketing; - Prevent automated decision-making and profiling; and - Provide data electronically and in a commonly used format (data portability). 6. Draft or revise security policies, which should include implementing appropriate technical and organizational measures, taking into account the nature, scope, context and purposes for processing as well as the risk of varying likelihood and severity for the rights and freedoms of individuals. Security actions may include: - The pseudonymisation and encryption of personal data; - The ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services processing personal data; - The ability to restore the availability and access to data in a timely manner in the event of a physical or technical incident; and - A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measure for ensuring the security of the processing. - NOTE: Controllers or processors that adhere to either an approved code of conduct or an approved certification mechanism can use these tools to demonstrate compliance with the GDPR’s security standards.
  • 3. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 3 7. Ensure procedures are in place to continually monitor compliance with these policies, including the security policies, prior to, during and after processing of personal data. - Additionally, perform a gap assessment and consider participation in certification programs. 8. Before collecting personal data, the company must disclose: - The identity of the controller; - The purposes for processing; - Any recipients of personal data; and How long the data will be stored. - Disclosures must be intelligible and easily accessible, using clear and plain language. 9. Additionally, the company must inform data subjects of their: - Right to withdraw consent at any time; - Right to request access, rectification or restriction of processing; and - Right to lodge a complaint to a supervisory authority. 10. Review how the company is seeking, obtaining and recording consent. The company must comply with the following requirements. - Consent must be “freely given, specific, informed and unambiguous (opt in),” or it is explicit (the higher standard). This should include assessing whether the company’s audit trail for such consent is effective and whether they need to make any changes. Consent must be referenced in the company Privacy Policy. o Consent is not freely given if there is a clear imbalance between the data subject and the controller, in particular, where the controller is a public authority.
  • 4. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 4 o Additionally, the controller cannot make a service conditional upon consent, unless the processing is necessary for the service. - To show consent, the data subject must signal agreement by “a statement or clear affirmative action.” - Consent must be specific to each data processing operations. - Data subjects must be informed about their right to withdraw consent at anytime, before they give their consent. - The controller must provide “accurate and full information on all relevant issues,” including the nature of the data that will be process, the purposes of processing, the identity of the controller and the identity of any other recipients of the data. - Your company’s customers should explicitly reference use of your company’s platform and technologies in their policies. This is a reliable means to put the public on Notice and ensure Consent at this juncture. 11. Review current privacy notices and make necessary changes to include the additional communication requirements to individuals on: - The legal basis for processing data; - The data retention periods; and - The individual’s right to complain if the individual believes the data is being mishandled. 12. Update the company’s procedures and/or amend retention policies if necessary to comply with GDPR requirements, including: - Privacy policies are easily accessible, written in clear and plain language, and include full disclosure of your data collection and processing; - Disclosure of data retention policies; - Respect to access requests within a month; and - Allow individuals to correct inaccurate information about them. 13. The company should conduct a thorough data privacy impact assessment where data processing operations may lead to high risks to data subjects’ personal data. - The company should refer and implement the provisions of the Information
  • 5. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 5 Commissioners Office’s guidance on Privacy Impact Assessments. 14. Ensure the company has proper procedures in place to detect, report and investigate a data breach in which individuals are likely to suffer some form of damage. To comply with this requirement, the company should do the following: - Assess the types of data the company holds; - Document which type of data would trigger notice if there was a breach; and - Develop appropriate policies and procedures. 15. The company must comply with the following notification requirements when a breach occurs: - If a data processor experiences a personal data breach, it must notify the controller but otherwise has no other notification or reported obligation under the GDPR. - If a breach occurs the company (controller) is required to notify privacy regulators of the data breach within seventy-two (72) hours after the breach is discovered. o If notification is not made within seventy-two (72) hours, the controller must provide a “reasoned justification” for the delay. o There is an exception to the supervisory authority notification requirement that states notice is not required if the personal data breach is unlikely to result in a risk for the rights and freedoms of individuals. - When notifying the supervisory authority, the notification must: • Describe the nature of the personal data breach, including the number and categories of data subjects and data records affected; • Provide the data protection officer’s contact information; • Describe the likely consequences of the personal data breach; and • Describe how the controller proposes to address the breach, including any mitigation efforts. 16. Data subjects will also need to be notified “without undue delay” where a
  • 6. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 6 breach poses a high risk to the data subject’s rights and freedoms. However, there is an exception to the requirement to notify data subjects in the following circumstances: o The controller has “implemented appropriate technical and organizational protection measures” that “render the data unintelligible to any person who is not authorized to access it, such as encryption;” o The controller takes actions subsequent to the personal data breach to “ensure that the high risk for the rights and freedoms of data subjects” is unlikely to materialize; or o When notification to each data subject would “involve disproportionate effort,” in which case alternative communication measures may be used. 17. Limit data collection to the minimum necessary (data minimization) and adopt a “privacy by design” approach to projects, which promotes privacy and data protection compliance from the beginning. - Ensure the company collects the minimum amount of personal data necessary for the proper performance of the products and services. 18. Controllers and Processors of personal information must designate a Data Protection Officer (DPO) when: - The processing is carried out by a public authority or body; or - The controller’s or processor’s core activities require regular and systematic monitoring of data subjects on a large scale or consist of “processing on a large scale of special categories of data.” 19. The DPO must be “designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices.” The DPO must have the authority and independence to inform the company of its obligations under GDPR, and must have the ability to fulfill the tasks designated, such as regulatory compliance, training staff on proper data handling and coordinating with the supervisory authority, with an ability to understand and balance data processing risks.
  • 7. 2352 Market Street San Francisco, CA 94114 T: 415.795.1572 F: 909.972.1639 gamallp.com 7 The DPO also needs to monitor compliance and conduct internal audits. The DPO will be the company’s point of contact for data subjects’ inquiries, withdrawals of consent, right to be forgotten requests and other related rights. NOTE: Our law firm will be providing these services to companies. 20. Consider putting systems in place to verify individuals’ ages and to gather parental or guardian consent for any data processing activity involving children under thirteen (13) years of age. If such information is involved, the privacy notice will need to be drafted in a manner understandable by children. 21. Review Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs) for trans-Atlantic data flows for compliance with new requirements of GDPR. Draft addendums to SCCs and other contracts as necessary to address the onward transfer restrictions, which includes ensuring that downstream entities comply with limitations on purpose and meet all the requirements, including remediating any unauthorized processing by the downstream entity. Need guidance? Contact Christina Gagnier, lead of GAMA’s Global Data Privacy Practice. gagnier@gamallp.com 415.795.1572