SlideShare a Scribd company logo
1 of 41
9 Steps 2 GDPR Compliance
General Data Protection Regulation (GDPR),
since May 25th, 2018
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
Text, Important Text
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
Terminology
What is personal data?
Any information relating to an identified or identifiable natural
person. Such as name, age, residence, occupation, location, marital
status, natural characteristics, education, job description, interests,
activities, habits, hobbies etc.
The identified or identifiable natural person under the aforementioned
data is called the Data Subject.
Terminology
What is sensitive personal data?
Any information regarding the Data Subject including the racial or
ethnic origin, political opinions, religious beliefs or other beliefs of a
similar nature, physical or mental health or condition, sex life, whether
the DS is a member of a trade union, the commission or alleged
commission by the DS of any offence, any proceedings for any offence
committed or alleged to have been committed by him, the sentence of
any court etc.
Sensitive personal data is protected under stricter regulations.
Ορολογία
DS: Data Subject - the identified or identifiable natural person whose
data we collect.
DC: Data Controller – the person (or business) who determines the
purposes for which, and the way in which, personal data is processed.
DP: Data Processor – anyone who processes personal data on behalf
of the data controller.
DPO: Data Protection Officer – responsible for overseeing data
protection strategy and implementation to ensure compliance with
GDPR requirements.
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
About the Data (2 questions)
1. Do I have the right to own data?
Note: In any case, I have the right to keep personal data when it is
covered by a legal act (recruitment, financial transaction, invoicing,
contracts and family data, employee’s medical counseling, maternity
and pregnancy leave, civil status, etc.). In such cases I am entitled to
and obliged, by law, to keep data on the data subjects for a minimum
period of 5 – 6 years, for most European countries.
About the Data (2 questions)
2. How do I protect the data that I keep?
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
Fines
Fines up to 20 Million Euros or more, but before we start getting that
scared, we may receive...
1. Warnings
2. Reprimands
3. Orders to compliance with the DS’s requests
4. Orders to communicate the data breaches directly to the DS
Fines
Categories:
Tier I: 10 Million Euros or 10% of annual turnover (whichever is higher)
- Breaches of Data Controller and Data Processor obligations.
Tier II: 10 Million Euros or 10% of annual turnover (whichever is higher)
- Breaches of DS's rights.
Fines
Value of the fines to be imposed is not straightforward and the
organization’s steps to compliance and general behavior will be taken
into account when determining the fine.
Available information is unclear full of jargon.
Terminology
About the Data
Fines
9 Steps to Compliance
STEP 1 – Data Gathering
Gather, store and organize all your data in one place.
Key Points
• You have to be able to get anyone’s data asap and aaap (accurately), if
ever asked.
• You have to show that you know exactly what data you have on who
and where, if ever investigated by GDPR.
• You have to gather all existing Personal Data.
STEP 2 – Data Audit
Audit your data and dispose what you don’t need.
Key Points
• Why do you have other people's data?
• Categorize your data to: not useful anymore, useful but harmless,
useful and risky (medical, financial).
• Delete all data you don't need.
STEP 3 – Secure Data
Protect against breaches, hacks, blocks and ransomware,
destruction and deletion of data etc.
Key Points
• Cloud Security
• Active Protection (antivirus, firewall, remote wipe out of data)
• Security for Hard Copies of Data (locked, disaster-proof)
NOT RECOMMENDED due to risk and high costs
• Written Procedures on Safety Measures
STEP 4 – Data Policy
Write a clear fair privacy policy.
Key Points
• Document that clearly describes What Data you collect and How You
Use Them.
• Easy Access to the Data Policy (ideally, a link before every submit
button).
• AVOID Technical Language and or Jargon.
STEP 4 – Data Policy
Answer the following (all of them):
1. What Information do you collect?
2. Who are you?
3. How is information collected?
4. Why do you collect information?
STEP 4 – Data Policy
Answer the following (all of them):
5. How will you use information?
6. Who will you share it with?
7. How are people, whose data you have and process, influenced?
8. Is the intended use likely to cause objections?
STEP 5 – Export Data
Setup a process for exporting all data you have on a person.
Key Points
• Provide the requested information within a month and free of
charge.
STEP 6 – Update & Delete Data
Setup a process for updating and / or deleting data, if ever
asked by the DS.
STEP 6 – Update & Delete Data
DANGER, in case you contact a
person you are supposed to have
no data on anymore!
STEP 7 – Positive Opt In, Action & Evidence
We collect data only when the DS proactively submits it!
Key Points
• AVOID pre-checked boxes.
• Clear and visible "Yes, I agree..." checkbox.
• Double opt-in.
• Sign a paper in-person, in case you collect personal data offline.
• Inform all your database about GDPR and encourage subscribers to
re-subscribe or answer back with a copy-paste consenting email.
STEP 8 – Easy Opt Out
Make it easy for anyone to opt-out.
Key Points
• Newsletter
• SMS
• Call Centers
• Provide clear opt-out directions with no small print
STEP 8 – Easy Opt Out
DANGER, in case you contact
an opted-out person!
STEP 9 – Inform
Make sure everyone in your company knows about GDPR.
Make sure customers and vendors also know about GDPR
and review your contracts with them.
Key Points
• Send informative emails.
• Train everyone.
• Assign responsibilities to a Data Protection Officer (DPO) in case your
organization consists of more than 250 employees.
Let’s not forget…
some interesting points concerning a potential data-ownership change!
Data Ownership
SHOULD I BUY DATA?
Make sure the Provider Company is GDPR compliant and each and
every DS in the dataset has actively opted-in for their data to be stored
by a third party company.
In practice, it is advisable not to buy!
Data Ownership
MAYBE I SELL MY BUSINESS ONE DAY! WHAT ABOUT THE
DATA?
There has to be a clear-cut section in your Data Policy stating that in
case of a buying off, all data will be in possession of the new owner.
When that day comes, you should inform the new owner about your
existing data policies and the fact that he has no right to use them in
any other way.
Are you GDPR Compliant?
Andreas Batsis, Digital Strategy & Cloud Security Solutions

More Related Content

What's hot

EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticheramy_hatton
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk- Mark - Fullbright
 
Data Protection Audit Checklist
Data Protection Audit ChecklistData Protection Audit Checklist
Data Protection Audit ChecklistDigital Guardian
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.Matthias Dobbelaere-Welvaert
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Lauren Isaacs
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 

What's hot (20)

EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticher
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Data Protection Audit Checklist
Data Protection Audit ChecklistData Protection Audit Checklist
Data Protection Audit Checklist
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 

Similar to 9 Practical Steps 2 GDPR Compliance

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist  AVG / GDPR - Algemene Verordering GegevensbeschermingMagento checklist  AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist AVG / GDPR - Algemene Verordering GegevensbeschermingErwin Otten
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To ConsiderSymantec
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Forums financiers de Wallonie
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationcaniceconsulting
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPRNate Stockard
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyRay ABOU
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018Human Capital Department
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxTimBee1
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRCase IQ
 

Similar to 9 Practical Steps 2 GDPR Compliance (20)

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist  AVG / GDPR - Algemene Verordering GegevensbeschermingMagento checklist  AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
GDPR Demystified
GDPR Demystified GDPR Demystified
GDPR Demystified
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 

More from Andreas Batsis

Weatherman 1-hour Speed Course for Web [2023]
Weatherman 1-hour Speed Course for Web [2023]Weatherman 1-hour Speed Course for Web [2023]
Weatherman 1-hour Speed Course for Web [2023]Andreas Batsis
 
Linked Business - Empowering organizations to achieve evidence-based calculat...
Linked Business - Empowering organizations to achieve evidence-based calculat...Linked Business - Empowering organizations to achieve evidence-based calculat...
Linked Business - Empowering organizations to achieve evidence-based calculat...Andreas Batsis
 
Linked Business: All-in-one Business Leads
Linked Business: All-in-one Business LeadsLinked Business: All-in-one Business Leads
Linked Business: All-in-one Business LeadsAndreas Batsis
 
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...Andreas Batsis
 
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYCThe AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYCAndreas Batsis
 
Linked Business Platform GR - v15
Linked Business Platform GR - v15Linked Business Platform GR - v15
Linked Business Platform GR - v15Andreas Batsis
 
Crisis-Proof: Strategy for Digital and non-Digital Businesses
Crisis-Proof: Strategy for Digital and non-Digital BusinessesCrisis-Proof: Strategy for Digital and non-Digital Businesses
Crisis-Proof: Strategy for Digital and non-Digital BusinessesAndreas Batsis
 
Linked Business Platform EN - v11
Linked Business Platform EN - v11Linked Business Platform EN - v11
Linked Business Platform EN - v11Andreas Batsis
 
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)Andreas Batsis
 
Batcic @ Delta, Digital Era (v.11)
Batcic @ Delta, Digital Era (v.11)Batcic @ Delta, Digital Era (v.11)
Batcic @ Delta, Digital Era (v.11)Andreas Batsis
 
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...Andreas Batsis
 
Εκπαιδευτικός Άτλαντας Νεφών
Εκπαιδευτικός Άτλαντας ΝεφώνΕκπαιδευτικός Άτλαντας Νεφών
Εκπαιδευτικός Άτλαντας ΝεφώνAndreas Batsis
 

More from Andreas Batsis (13)

Weatherman 1-hour Speed Course for Web [2023]
Weatherman 1-hour Speed Course for Web [2023]Weatherman 1-hour Speed Course for Web [2023]
Weatherman 1-hour Speed Course for Web [2023]
 
Linked Business - Empowering organizations to achieve evidence-based calculat...
Linked Business - Empowering organizations to achieve evidence-based calculat...Linked Business - Empowering organizations to achieve evidence-based calculat...
Linked Business - Empowering organizations to achieve evidence-based calculat...
 
Linked Business: All-in-one Business Leads
Linked Business: All-in-one Business LeadsLinked Business: All-in-one Business Leads
Linked Business: All-in-one Business Leads
 
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
 
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYCThe AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
 
Linked Business Platform GR - v15
Linked Business Platform GR - v15Linked Business Platform GR - v15
Linked Business Platform GR - v15
 
Crisis-Proof: Strategy for Digital and non-Digital Businesses
Crisis-Proof: Strategy for Digital and non-Digital BusinessesCrisis-Proof: Strategy for Digital and non-Digital Businesses
Crisis-Proof: Strategy for Digital and non-Digital Businesses
 
Linked Business Platform EN - v11
Linked Business Platform EN - v11Linked Business Platform EN - v11
Linked Business Platform EN - v11
 
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
 
Batcic @ Delta, Digital Era (v.11)
Batcic @ Delta, Digital Era (v.11)Batcic @ Delta, Digital Era (v.11)
Batcic @ Delta, Digital Era (v.11)
 
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
 
iWeatherman
iWeathermaniWeatherman
iWeatherman
 
Εκπαιδευτικός Άτλαντας Νεφών
Εκπαιδευτικός Άτλαντας ΝεφώνΕκπαιδευτικός Άτλαντας Νεφών
Εκπαιδευτικός Άτλαντας Νεφών
 

Recently uploaded

1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样vhwb25kk
 
B2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docxB2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docxStephen266013
 
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfKantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfSocial Samosa
 
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...Jack DiGiovanna
 
Data Science Jobs and Salaries Analysis.pptx
Data Science Jobs and Salaries Analysis.pptxData Science Jobs and Salaries Analysis.pptx
Data Science Jobs and Salaries Analysis.pptxFurkanTasci3
 
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
DBA Basics: Getting Started with Performance Tuning.pdf
DBA Basics: Getting Started with Performance Tuning.pdfDBA Basics: Getting Started with Performance Tuning.pdf
DBA Basics: Getting Started with Performance Tuning.pdfJohn Sterrett
 
9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home Service9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home ServiceSapana Sha
 
Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...
Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...
Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...ThinkInnovation
 
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...limedy534
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Cantervoginip
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一F sss
 
GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]📊 Markus Baersch
 
专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改
专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改
专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改yuu sss
 
Call Girls In Mahipalpur O9654467111 Escorts Service
Call Girls In Mahipalpur O9654467111  Escorts ServiceCall Girls In Mahipalpur O9654467111  Escorts Service
Call Girls In Mahipalpur O9654467111 Escorts ServiceSapana Sha
 
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...Suhani Kapoor
 
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptxAmazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptxAbdelrhman abooda
 

Recently uploaded (20)

1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
 
B2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docxB2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docx
 
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfKantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
 
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
 
Call Girls in Saket 99530🔝 56974 Escort Service
Call Girls in Saket 99530🔝 56974 Escort ServiceCall Girls in Saket 99530🔝 56974 Escort Service
Call Girls in Saket 99530🔝 56974 Escort Service
 
Data Science Jobs and Salaries Analysis.pptx
Data Science Jobs and Salaries Analysis.pptxData Science Jobs and Salaries Analysis.pptx
Data Science Jobs and Salaries Analysis.pptx
 
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
 
DBA Basics: Getting Started with Performance Tuning.pdf
DBA Basics: Getting Started with Performance Tuning.pdfDBA Basics: Getting Started with Performance Tuning.pdf
DBA Basics: Getting Started with Performance Tuning.pdf
 
9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home Service9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home Service
 
Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...
Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...
Predictive Analysis - Using Insight-informed Data to Determine Factors Drivin...
 
E-Commerce Order PredictionShraddha Kamble.pptx
E-Commerce Order PredictionShraddha Kamble.pptxE-Commerce Order PredictionShraddha Kamble.pptx
E-Commerce Order PredictionShraddha Kamble.pptx
 
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Canter
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
 
GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]
 
专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改
专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改
专业一比一美国俄亥俄大学毕业证成绩单pdf电子版制作修改
 
Call Girls In Mahipalpur O9654467111 Escorts Service
Call Girls In Mahipalpur O9654467111  Escorts ServiceCall Girls In Mahipalpur O9654467111  Escorts Service
Call Girls In Mahipalpur O9654467111 Escorts Service
 
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
 
Deep Generative Learning for All - The Gen AI Hype (Spring 2024)
Deep Generative Learning for All - The Gen AI Hype (Spring 2024)Deep Generative Learning for All - The Gen AI Hype (Spring 2024)
Deep Generative Learning for All - The Gen AI Hype (Spring 2024)
 
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptxAmazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
 

9 Practical Steps 2 GDPR Compliance

  • 1. 9 Steps 2 GDPR Compliance General Data Protection Regulation (GDPR), since May 25th, 2018
  • 2. Contents Terminology About the Data Fines 9 Steps to Compliance Text, Important Text
  • 4. Terminology What is personal data? Any information relating to an identified or identifiable natural person. Such as name, age, residence, occupation, location, marital status, natural characteristics, education, job description, interests, activities, habits, hobbies etc. The identified or identifiable natural person under the aforementioned data is called the Data Subject.
  • 5. Terminology What is sensitive personal data? Any information regarding the Data Subject including the racial or ethnic origin, political opinions, religious beliefs or other beliefs of a similar nature, physical or mental health or condition, sex life, whether the DS is a member of a trade union, the commission or alleged commission by the DS of any offence, any proceedings for any offence committed or alleged to have been committed by him, the sentence of any court etc. Sensitive personal data is protected under stricter regulations.
  • 6. Ορολογία DS: Data Subject - the identified or identifiable natural person whose data we collect. DC: Data Controller – the person (or business) who determines the purposes for which, and the way in which, personal data is processed. DP: Data Processor – anyone who processes personal data on behalf of the data controller. DPO: Data Protection Officer – responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR requirements.
  • 8. About the Data (2 questions) 1. Do I have the right to own data? Note: In any case, I have the right to keep personal data when it is covered by a legal act (recruitment, financial transaction, invoicing, contracts and family data, employee’s medical counseling, maternity and pregnancy leave, civil status, etc.). In such cases I am entitled to and obliged, by law, to keep data on the data subjects for a minimum period of 5 – 6 years, for most European countries.
  • 9. About the Data (2 questions) 2. How do I protect the data that I keep?
  • 11. Fines Fines up to 20 Million Euros or more, but before we start getting that scared, we may receive... 1. Warnings 2. Reprimands 3. Orders to compliance with the DS’s requests 4. Orders to communicate the data breaches directly to the DS
  • 12. Fines Categories: Tier I: 10 Million Euros or 10% of annual turnover (whichever is higher) - Breaches of Data Controller and Data Processor obligations. Tier II: 10 Million Euros or 10% of annual turnover (whichever is higher) - Breaches of DS's rights.
  • 13. Fines Value of the fines to be imposed is not straightforward and the organization’s steps to compliance and general behavior will be taken into account when determining the fine. Available information is unclear full of jargon.
  • 14. Terminology About the Data Fines 9 Steps to Compliance
  • 15.
  • 16. STEP 1 – Data Gathering Gather, store and organize all your data in one place. Key Points • You have to be able to get anyone’s data asap and aaap (accurately), if ever asked. • You have to show that you know exactly what data you have on who and where, if ever investigated by GDPR. • You have to gather all existing Personal Data.
  • 17.
  • 18. STEP 2 – Data Audit Audit your data and dispose what you don’t need. Key Points • Why do you have other people's data? • Categorize your data to: not useful anymore, useful but harmless, useful and risky (medical, financial). • Delete all data you don't need.
  • 19.
  • 20. STEP 3 – Secure Data Protect against breaches, hacks, blocks and ransomware, destruction and deletion of data etc. Key Points • Cloud Security • Active Protection (antivirus, firewall, remote wipe out of data) • Security for Hard Copies of Data (locked, disaster-proof) NOT RECOMMENDED due to risk and high costs • Written Procedures on Safety Measures
  • 21.
  • 22. STEP 4 – Data Policy Write a clear fair privacy policy. Key Points • Document that clearly describes What Data you collect and How You Use Them. • Easy Access to the Data Policy (ideally, a link before every submit button). • AVOID Technical Language and or Jargon.
  • 23. STEP 4 – Data Policy Answer the following (all of them): 1. What Information do you collect? 2. Who are you? 3. How is information collected? 4. Why do you collect information?
  • 24. STEP 4 – Data Policy Answer the following (all of them): 5. How will you use information? 6. Who will you share it with? 7. How are people, whose data you have and process, influenced? 8. Is the intended use likely to cause objections?
  • 25.
  • 26. STEP 5 – Export Data Setup a process for exporting all data you have on a person. Key Points • Provide the requested information within a month and free of charge.
  • 27.
  • 28. STEP 6 – Update & Delete Data Setup a process for updating and / or deleting data, if ever asked by the DS.
  • 29. STEP 6 – Update & Delete Data DANGER, in case you contact a person you are supposed to have no data on anymore!
  • 30.
  • 31. STEP 7 – Positive Opt In, Action & Evidence We collect data only when the DS proactively submits it! Key Points • AVOID pre-checked boxes. • Clear and visible "Yes, I agree..." checkbox. • Double opt-in. • Sign a paper in-person, in case you collect personal data offline. • Inform all your database about GDPR and encourage subscribers to re-subscribe or answer back with a copy-paste consenting email.
  • 32.
  • 33. STEP 8 – Easy Opt Out Make it easy for anyone to opt-out. Key Points • Newsletter • SMS • Call Centers • Provide clear opt-out directions with no small print
  • 34. STEP 8 – Easy Opt Out DANGER, in case you contact an opted-out person!
  • 35.
  • 36. STEP 9 – Inform Make sure everyone in your company knows about GDPR. Make sure customers and vendors also know about GDPR and review your contracts with them. Key Points • Send informative emails. • Train everyone. • Assign responsibilities to a Data Protection Officer (DPO) in case your organization consists of more than 250 employees.
  • 37. Let’s not forget… some interesting points concerning a potential data-ownership change!
  • 38.
  • 39. Data Ownership SHOULD I BUY DATA? Make sure the Provider Company is GDPR compliant and each and every DS in the dataset has actively opted-in for their data to be stored by a third party company. In practice, it is advisable not to buy!
  • 40. Data Ownership MAYBE I SELL MY BUSINESS ONE DAY! WHAT ABOUT THE DATA? There has to be a clear-cut section in your Data Policy stating that in case of a buying off, all data will be in possession of the new owner. When that day comes, you should inform the new owner about your existing data policies and the fact that he has no right to use them in any other way.
  • 41. Are you GDPR Compliant? Andreas Batsis, Digital Strategy & Cloud Security Solutions