SlideShare a Scribd company logo
A practical guide
to GDPR
preparation.
Dean Evens
Director
Satori Consulting
Megan Maddocks
Account Executive
Promapp
APRACTICALGUIDETO GENERALDATA
PROTECTIONREGULATION(GDPR)
PREPARATION
MAY 1, 2018
A PRACTICAL GUIDE TO GDPR PREPARATION
AGENDA
3
This session will address key GDPR questions:
1. What is GDPR and why is it important?
2. What are the core GDPR concepts?
3. What should practitioners know to achieve and maintain
compliance?
4. What are the keys to success?
5. Process owners as data stewards?
6. How can Promapp be leveraged to achieve and maintain readiness?
WHAT IS GDPR AND WHY IS IT IMPORTANT?
4
PRACTICAL GUIDE TO GDPR PREPARATION
GDPR DEFINITION & FOCUS
5
The objective of the General Data Protection Regulation (GDPR) is
harmonization of EU regulations to enhance the rights of EU citizens to govern
the privacy of their personal information and ensure organizations provide the
right protections.
The GDPR applies to EU and non-EU organizations that:
(i) offer goods or services to EU residents;
(ii) monitor the behavior of EU residents
The GDPR effective date:
▪ May 25, 2018
Penalties:
▪ Up to 20,000,000 EUR or 4% worldwide revenue from the previous fiscal
year (Article 83). Fines are determined by the Data Protection Authority
(Supervisory Authority).
* The “Articles” referenced in this document refer to the articles included in the GDPR regulation. A link
to the regulation text is included in the Appendix section of this document.
A PRACTICAL GUIDE TO GDPR PREPARATION
GDPR DEFINITION & FOCUS: PERSONAL DATA
6
Personal data references any data that can identify a natural person
(“data subject”): name, online identifier, identification number,
location data, IP address etc.
Personal Data Considerations
A PRACTICAL GUIDE TO GDPR PREPARATION
GDPR DEFINITION & FOCUS: ROLES ROLES & RESPONSIBILITIES
7
There are several roles needed to
support GDPR implementation*.
The DPO role is key to successful
execution and should act as
GDPR owner.
Data Protection Officer**: Role
that acts as point of contact for
the EU Representative and DPA.
Understanding GDPR
requirements and identifying how
it relates to the organization is
key.
The DPO should identify the
appropriate Data Protection
Authority (DPA) to engage with.
* Controllers that process small scale data intermittently and do not handle sensitive personal
data are exempt
** DPO is not required to be a dedicated FTE (see Article 37, 38, and 39)
WHAT ARE THE CORE GDPR CONCEPTS?
8
A PRACTICAL GUIDE TO GDPR PREPARATION
GDPR CONCEPTS
9
Principles, privacy, and protection represent the core focus for GDPR readiness.
Organizations must focus on adhering to principles, implementing processes to
satisfy privacy rights of the individual, and securing data.
Principles
▪ Data processed lawfully, fairly, and transparently
▪ Only collect personal data needed
▪ Accuracy of personal data must be maintained
▪ Minimize the time data is kept in a form to identify
data subjects
▪ Maintain the confidentiality and integrity of
personal data
Privacy (rights of data subjects)
▪ Transparent information, communication and
modalities for the exercise of the rights of the
data subject
▪ Information to be provided where personal data
are collected from the data subject
▪ Right of access by the data subject
▪ Right to rectification
▪ Right to erasure (‘right to be forgotten’)
▪ Right to restriction of processing
▪ Right to data portability
Protection (controllers and processors)
▪ Data Protection Officer (DPO)
▪ Data protection by design
▪ Records of processing activities
▪ Security of processing
▪ Notification of a personal data breach to the
Supervisory Authority
▪ Communication of a personal data breach to the
data subject
▪ Data Protection Impact Assessment (DPIA)
▪ Code of conduct
A PRACTICAL GUIDE TO GDPR PREPARATION
CONTROLLERS AND PROCESSORS
10
Controller collects and
determines the purposes and
means of processing
personal data.
Processor processes personal
data on behalf of the
controller.
Identify processors and
provisioned services:
▪ AWS* – EBS, S3,
Cloudfront
▪ Data Dog
▪ Application integration
points
A PRACTICAL GUIDE TO GDPR PREPARATION
CONTROLLERS AND PROCESSORS: PROCESSOR OBLIGATIONS
11
Processors are obligated to establish and maintain GDPR compliance.
1. Processor is required to obtain written consent from the controller prior to
appointing sub-processor.
2. Processors (and any sub-processors) shall not process personal data, except in
accordance with the instructions of the controller
3. Comply with recordkeeping obligations
4. Cooperate with Data Protection Authorities
5. Adhere to data security obligations
6. Comply with data breach reporting requirements
7. Appoint a Data Protection Officer, if applicable
8. Adhere to cross border transfers requirements
WHAT SHOULD PRACTITIONERS KNOW TO
ACHIEVE AND MAINTAIN COMPLIANCE?
12
A PRACTICAL GUIDE TO GDPR PREPARATION
PRINCIPLES FOR CONTROLLERS AND PROCESSORS
13
Objective – establish guidelines to promote collection, use, processing,
and storage is performed responsibly and in accordance with GDPR
requirements.
GDPR Requirement…
Security Principles**
1. Simplicity
2. Balanced Security
3. Least Privilege
4. Plan for Failure
5. Zero/limit Trust
6. Data Centric Security
7. Design with Multi-tenancy in Mind
8. Build in Traceability
Privacy Principles
1. Lawful, fairness, and transparency
2. Purpose limitations
3. Data minimization
4. Accuracy
5. Storage limitation
6. Integrity and confidentiality
A PRACTICAL GUIDE TO GDPR PREPARATION
DATA PROTECTION BY DESIGN AND BY DEFAULT
14
Objective - To minimize risk to privacy and build trust in the system. Protection by
design applies to all personal data.
GDPR Requirement…
Implement the appropriate technical and organizational measures and integrate
them into processing to protect the rights and freedoms of EU citizens. GDPR risk
drives development of measures.
Actions to Take…
1. Operationalize principles
2. Implement process to establish and maintain records of data processing activities
3. Establish information flows of personal data
4. Define technical and organization measures – pseudonymization, encryption
A PRACTICAL GUIDE TO GDPR PREPARATION
DATA PROTECTION IMPACT ASSESSMENT (DPIA)
15
Objective – Identify privacy and security risk and take the right measures to
reduce it to an acceptable level. DPIA applies to high risk personal data.
GDPR Requirement…
1. Documented measures to ensure risk is managed in compliance with GDPR DPIA
required during processing of high risk activities.
2. DPIA must be perform prior to implementation
Actions to Take…
1. Implement DPIA Process
▪ Develop DPIA questionnaire and establish threshold for DPIA requirement
▪ Define method for privacy and security review
▪ Create template for DPIA documentation
▪ Establish DPIA approval process
A PRACTICAL GUIDE TO GDPR PREPARATION
CROSS BORDER TRANSFERS
16
Transfers of personal data outside the EEA (European Economic Area) is
strictly prohibited. Data transfer can occur if:
▪ Adequacy decision
▪ Binding Corporate Rules (BCR) approved by DPA
▪ Certifications in place
▪ Standard contractual clauses are in place
▪ Ad hoc contractual clauses
▪ Consent from the data subject
▪ Approved Code of Conduct
▪ Privacy Shield compliance
A PRACTICAL GUIDE TO GDPR PREPARATION
SECURITY OF PROCESSING
17
Identify stack responsibility and apply controls to
ensure security of processing
▪ IT Security Policy
▪ Security Processes and Procedures
▪ Access Control
▪ Security in Systems Lifecycle Management
▪ Secure Software Development
▪ Data Protection
▪ Malware Protection
▪ Network Security
▪ Vulnerability Management
▪ Change Management
▪ Security Incident Response – Breach Notification
▪ Disaster Recovery
▪ Supplier Management
WHAT ARE THE KEYS TO SUCCESS?
18
A PRACTICAL GUIDE TO GDPR PREPARATION
ESTABLISH A PLAN
19
GDPR requires the organization to address privacy and security of personal data.
A proven approach to gaining clarity on GDPR relevance and understanding how
to execute is described below. The Data Protection Officer (DPO) must lead the
effort to achieve and maintain alignment.
Preparation
•Assign data privacy
ownership
•Understand the
regulation
Assessment
•Assess the EU citizen
personal data collected
and processed
•Identify how the rights
of the individual
applies
•Understand the risk of
activities
•Assess processors
Implementation
•Implement GDPR
principles
•Implement data
protection by design
•Create and maintain
documentation for
personal processing
activities
•Implement data
protection impact
assessments
•Align security controls
Maintenance
•Operationalize GDPR
controls
A PRACTICAL GUIDE TO GDPR PREPARATION
PROCESS OWNERS AS DATA STEWARD
20
• Leading practices are evolving to establish Data Steward role
• Role is aligned with Business Process Owners to understand data assets
supporting the process and ensuring controls are in place
• Key contributor to DPIA as/if required
• Work with DPO, Application, Information Security, Compliance and Supplier
Management team members to ensure data protection
• Underpins Data Protection by Design principle
A PRACTICAL GUIDE TO GDPR PREPARATION
KEY POINTS
21
Focus on the following…
1. Understand your data
2. Use principles to drive the right behaviors and build a culture of privacy &
security
3. Address protection by design for all personal data
4. Maintain records of processing activities documentation
5. Align security controls with the activities performed and ensure they are
defensible
6. Perform data protection impact assessments for all high risk activities, and
maintain documentation
7. Manage third party/processor relationships
A PRACTICAL GUIDE TO GDPR PREPARATION
PROMAPP TO ACHIEVE AND MAINTAIN READINESS
22
A short demonstration…
Questions?
www.promapp.com
www.satoriconsulting.com
APPENDIX
24
A PRACTICAL GUIDE TO GDPR PREPARATION
GDPR MYTHS
25
Understanding GDPR requirements can be complex. There are several common
misperceptions that should be clarified.
1. A Data Protection Officer is required for all organizations
2. Each GDPR incident will carry a fine equivalent to the greater of 20 mil Euro or
4% annual worldwide revenue
3. Consent is always required for processing of personal data
4. Parental consent is always required when collecting personal information from
a child
5. Individuals have the absolute right to be forgotten
6. Biometric data is sensitive data
7. Controllers do not require processing agreements with processors – GDPR
takes care of this
8. Security technology solutions are needed to enable GDPR compliance
9. Automated decision-making can not be performed (e.g., use of AI)
A PRACTICAL GUIDE TO GDPR PREPARATION
REFERENCE SOURCES
26
▪ GDPR Regulation - Full regulation Abbreviated regulation Web-based GDPR
regulation resource
▪ UK ICO Guide to GDPR
▪ White & Case has great insight into GDPR
▪ A series of 10 posts that provide insight into the operational impact of GDPR
▪ List of Data Protection Authorities for EU Member States
▪ UK ICO Assessment Questionnaire

More Related Content

What's hot

DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
DAMA Ireland
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
Microsoft Österreich
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Omo Osagiede
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
Ulf Mattsson
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
Tim Gough
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Frank Dawson
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
Ardoq
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
Kyle Davies
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
Vuzion
 
Data Privacy and the GDPR
Data Privacy and the GDPRData Privacy and the GDPR
Data Privacy and the GDPR
Demandbase
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
VYTIS MALECKAS
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
Zymplify
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
Acquia
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
Cliff Ashcroft
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
BCC - Solutions for IBM Collaboration Software
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
eHealth Forum
 
Webianr: GDPR: How to build a data protection framework
Webianr: GDPR: How to build a data protection frameworkWebianr: GDPR: How to build a data protection framework
Webianr: GDPR: How to build a data protection framework
Leigh Hill
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
Jake DiMare
 

What's hot (20)

DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Data Privacy and the GDPR
Data Privacy and the GDPRData Privacy and the GDPR
Data Privacy and the GDPR
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
Webianr: GDPR: How to build a data protection framework
Webianr: GDPR: How to build a data protection frameworkWebianr: GDPR: How to build a data protection framework
Webianr: GDPR: How to build a data protection framework
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 

Similar to A practical guide to GDPR preparation

Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018
Dean Evans
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
Common Practice in Data Privacy Program Management
Common Practice in Data Privacy Program ManagementCommon Practice in Data Privacy Program Management
Common Practice in Data Privacy Program Management
Eryk Budi Pratama
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
Microsoft dynamics 365 for small and medium sized charities - session 2 gdprMicrosoft dynamics 365 for small and medium sized charities - session 2 gdpr
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
m-hance
 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdf
tsaaroacademy
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
Dimitri Sirota
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
What happens if you’re not ready for the GDPR?
What happens if you’re not ready for the GDPR?What happens if you’re not ready for the GDPR?
What happens if you’re not ready for the GDPR?
Digital Transformation EXPO Event Series
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
accenture
 
GDPR Jennifer Rose
GDPR Jennifer RoseGDPR Jennifer Rose
GDPR Jennifer Rose
Jennifer Rose
 
GDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to KnowGDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to Know
Rachel Roach
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
Clive Rich
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
EQS Group
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance Primer
IAB Europe
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
MongoDB
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
Gary Dodson
 
GDPR and API Security
GDPR and API SecurityGDPR and API Security
GDPR and API Security
WSO2
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
Olivier BARROT
 
GDPR How to get started?
GDPR  How to get started?GDPR  How to get started?
GDPR How to get started?
Peter Witsenburg
 

Similar to A practical guide to GDPR preparation (20)

Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Common Practice in Data Privacy Program Management
Common Practice in Data Privacy Program ManagementCommon Practice in Data Privacy Program Management
Common Practice in Data Privacy Program Management
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
Microsoft dynamics 365 for small and medium sized charities - session 2 gdprMicrosoft dynamics 365 for small and medium sized charities - session 2 gdpr
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdf
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What happens if you’re not ready for the GDPR?
What happens if you’re not ready for the GDPR?What happens if you’re not ready for the GDPR?
What happens if you’re not ready for the GDPR?
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
GDPR Jennifer Rose
GDPR Jennifer RoseGDPR Jennifer Rose
GDPR Jennifer Rose
 
GDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to KnowGDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to Know
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance Primer
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
 
GDPR and API Security
GDPR and API SecurityGDPR and API Security
GDPR and API Security
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
GDPR How to get started?
GDPR  How to get started?GDPR  How to get started?
GDPR How to get started?
 

More from Promapp Solutions

Promapp webinar how to drive engagement in process
Promapp webinar how to drive engagement in processPromapp webinar how to drive engagement in process
Promapp webinar how to drive engagement in process
Promapp Solutions
 
Promapp how to get sufficient resourcing
Promapp how to get sufficient resourcingPromapp how to get sufficient resourcing
Promapp how to get sufficient resourcing
Promapp Solutions
 
How to get leadership buy in promapp
How to get leadership buy in promappHow to get leadership buy in promapp
How to get leadership buy in promapp
Promapp Solutions
 
Marlborough District Council presentation
Marlborough District Council presentationMarlborough District Council presentation
Marlborough District Council presentation
Promapp Solutions
 
Promapp CONNECT photos
Promapp CONNECT photosPromapp CONNECT photos
Promapp CONNECT photos
Promapp Solutions
 
Promapp CONNECT 2018
Promapp CONNECT 2018Promapp CONNECT 2018
Promapp CONNECT 2018
Promapp Solutions
 
Michigan State University presentation
Michigan State University presentationMichigan State University presentation
Michigan State University presentation
Promapp Solutions
 
Matt Spears presentation
Matt Spears presentationMatt Spears presentation
Matt Spears presentation
Promapp Solutions
 
RPA and BPM: Making the connection
RPA and BPM: Making the connectionRPA and BPM: Making the connection
RPA and BPM: Making the connection
Promapp Solutions
 
Nurturing improvement with Ravensdown
Nurturing improvement with RavensdownNurturing improvement with Ravensdown
Nurturing improvement with Ravensdown
Promapp Solutions
 
Queenstown Lakes District Council presentation
Queenstown Lakes District Council presentationQueenstown Lakes District Council presentation
Queenstown Lakes District Council presentation
Promapp Solutions
 
Medifab presentation
Medifab presentationMedifab presentation
Medifab presentation
Promapp Solutions
 
Central Coast Council presentation
Central Coast Council presentationCentral Coast Council presentation
Central Coast Council presentation
Promapp Solutions
 
Bayside City Council presentation
Bayside City Council presentationBayside City Council presentation
Bayside City Council presentation
Promapp Solutions
 
Affinity Education presentation
Affinity Education presentationAffinity Education presentation
Affinity Education presentation
Promapp Solutions
 
CONNECT top takeaways
CONNECT top takeawaysCONNECT top takeaways
CONNECT top takeaways
Promapp Solutions
 
Promapp CONNECT Global trends
Promapp CONNECT Global trends Promapp CONNECT Global trends
Promapp CONNECT Global trends
Promapp Solutions
 
Promapp webinar Understand the role of process in digital transformation.
Promapp webinar Understand the role of process in digital transformation.Promapp webinar Understand the role of process in digital transformation.
Promapp webinar Understand the role of process in digital transformation.
Promapp Solutions
 
Australian council drives process ownership and success
Australian council drives process ownership and successAustralian council drives process ownership and success
Australian council drives process ownership and success
Promapp Solutions
 
A fresh approach to bpm drives engagement
A fresh approach to bpm drives engagementA fresh approach to bpm drives engagement
A fresh approach to bpm drives engagement
Promapp Solutions
 

More from Promapp Solutions (20)

Promapp webinar how to drive engagement in process
Promapp webinar how to drive engagement in processPromapp webinar how to drive engagement in process
Promapp webinar how to drive engagement in process
 
Promapp how to get sufficient resourcing
Promapp how to get sufficient resourcingPromapp how to get sufficient resourcing
Promapp how to get sufficient resourcing
 
How to get leadership buy in promapp
How to get leadership buy in promappHow to get leadership buy in promapp
How to get leadership buy in promapp
 
Marlborough District Council presentation
Marlborough District Council presentationMarlborough District Council presentation
Marlborough District Council presentation
 
Promapp CONNECT photos
Promapp CONNECT photosPromapp CONNECT photos
Promapp CONNECT photos
 
Promapp CONNECT 2018
Promapp CONNECT 2018Promapp CONNECT 2018
Promapp CONNECT 2018
 
Michigan State University presentation
Michigan State University presentationMichigan State University presentation
Michigan State University presentation
 
Matt Spears presentation
Matt Spears presentationMatt Spears presentation
Matt Spears presentation
 
RPA and BPM: Making the connection
RPA and BPM: Making the connectionRPA and BPM: Making the connection
RPA and BPM: Making the connection
 
Nurturing improvement with Ravensdown
Nurturing improvement with RavensdownNurturing improvement with Ravensdown
Nurturing improvement with Ravensdown
 
Queenstown Lakes District Council presentation
Queenstown Lakes District Council presentationQueenstown Lakes District Council presentation
Queenstown Lakes District Council presentation
 
Medifab presentation
Medifab presentationMedifab presentation
Medifab presentation
 
Central Coast Council presentation
Central Coast Council presentationCentral Coast Council presentation
Central Coast Council presentation
 
Bayside City Council presentation
Bayside City Council presentationBayside City Council presentation
Bayside City Council presentation
 
Affinity Education presentation
Affinity Education presentationAffinity Education presentation
Affinity Education presentation
 
CONNECT top takeaways
CONNECT top takeawaysCONNECT top takeaways
CONNECT top takeaways
 
Promapp CONNECT Global trends
Promapp CONNECT Global trends Promapp CONNECT Global trends
Promapp CONNECT Global trends
 
Promapp webinar Understand the role of process in digital transformation.
Promapp webinar Understand the role of process in digital transformation.Promapp webinar Understand the role of process in digital transformation.
Promapp webinar Understand the role of process in digital transformation.
 
Australian council drives process ownership and success
Australian council drives process ownership and successAustralian council drives process ownership and success
Australian council drives process ownership and success
 
A fresh approach to bpm drives engagement
A fresh approach to bpm drives engagementA fresh approach to bpm drives engagement
A fresh approach to bpm drives engagement
 

Recently uploaded

Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Holger Mueller
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
sssourabhsharma
 
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & InnovationInnovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Operational Excellence Consulting
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
ssuser567e2d
 
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Neil Horowitz
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
SabaaSudozai
 
Easily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYCEasily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYC
Any kyc Account
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
my Pandit
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
APCO
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
Christian Dahlen
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
taqyea
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
Chandresh Chudasama
 
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
hartfordclub1
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
marketing317746
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
my Pandit
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
jeffkluth1
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
Adnet Communications
 
Best practices for project execution and delivery
Best practices for project execution and deliveryBest practices for project execution and delivery
Best practices for project execution and delivery
CLIVE MINCHIN
 
Digital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital ExcellenceDigital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital Excellence
Operational Excellence Consulting
 

Recently uploaded (20)

Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
 
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & InnovationInnovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & Innovation
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
 
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
 
Easily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYCEasily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYC
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
 
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
 
Best practices for project execution and delivery
Best practices for project execution and deliveryBest practices for project execution and delivery
Best practices for project execution and delivery
 
Digital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital ExcellenceDigital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital Excellence
 

A practical guide to GDPR preparation

  • 1. A practical guide to GDPR preparation. Dean Evens Director Satori Consulting Megan Maddocks Account Executive Promapp
  • 3. A PRACTICAL GUIDE TO GDPR PREPARATION AGENDA 3 This session will address key GDPR questions: 1. What is GDPR and why is it important? 2. What are the core GDPR concepts? 3. What should practitioners know to achieve and maintain compliance? 4. What are the keys to success? 5. Process owners as data stewards? 6. How can Promapp be leveraged to achieve and maintain readiness?
  • 4. WHAT IS GDPR AND WHY IS IT IMPORTANT? 4
  • 5. PRACTICAL GUIDE TO GDPR PREPARATION GDPR DEFINITION & FOCUS 5 The objective of the General Data Protection Regulation (GDPR) is harmonization of EU regulations to enhance the rights of EU citizens to govern the privacy of their personal information and ensure organizations provide the right protections. The GDPR applies to EU and non-EU organizations that: (i) offer goods or services to EU residents; (ii) monitor the behavior of EU residents The GDPR effective date: ▪ May 25, 2018 Penalties: ▪ Up to 20,000,000 EUR or 4% worldwide revenue from the previous fiscal year (Article 83). Fines are determined by the Data Protection Authority (Supervisory Authority). * The “Articles” referenced in this document refer to the articles included in the GDPR regulation. A link to the regulation text is included in the Appendix section of this document.
  • 6. A PRACTICAL GUIDE TO GDPR PREPARATION GDPR DEFINITION & FOCUS: PERSONAL DATA 6 Personal data references any data that can identify a natural person (“data subject”): name, online identifier, identification number, location data, IP address etc. Personal Data Considerations
  • 7. A PRACTICAL GUIDE TO GDPR PREPARATION GDPR DEFINITION & FOCUS: ROLES ROLES & RESPONSIBILITIES 7 There are several roles needed to support GDPR implementation*. The DPO role is key to successful execution and should act as GDPR owner. Data Protection Officer**: Role that acts as point of contact for the EU Representative and DPA. Understanding GDPR requirements and identifying how it relates to the organization is key. The DPO should identify the appropriate Data Protection Authority (DPA) to engage with. * Controllers that process small scale data intermittently and do not handle sensitive personal data are exempt ** DPO is not required to be a dedicated FTE (see Article 37, 38, and 39)
  • 8. WHAT ARE THE CORE GDPR CONCEPTS? 8
  • 9. A PRACTICAL GUIDE TO GDPR PREPARATION GDPR CONCEPTS 9 Principles, privacy, and protection represent the core focus for GDPR readiness. Organizations must focus on adhering to principles, implementing processes to satisfy privacy rights of the individual, and securing data. Principles ▪ Data processed lawfully, fairly, and transparently ▪ Only collect personal data needed ▪ Accuracy of personal data must be maintained ▪ Minimize the time data is kept in a form to identify data subjects ▪ Maintain the confidentiality and integrity of personal data Privacy (rights of data subjects) ▪ Transparent information, communication and modalities for the exercise of the rights of the data subject ▪ Information to be provided where personal data are collected from the data subject ▪ Right of access by the data subject ▪ Right to rectification ▪ Right to erasure (‘right to be forgotten’) ▪ Right to restriction of processing ▪ Right to data portability Protection (controllers and processors) ▪ Data Protection Officer (DPO) ▪ Data protection by design ▪ Records of processing activities ▪ Security of processing ▪ Notification of a personal data breach to the Supervisory Authority ▪ Communication of a personal data breach to the data subject ▪ Data Protection Impact Assessment (DPIA) ▪ Code of conduct
  • 10. A PRACTICAL GUIDE TO GDPR PREPARATION CONTROLLERS AND PROCESSORS 10 Controller collects and determines the purposes and means of processing personal data. Processor processes personal data on behalf of the controller. Identify processors and provisioned services: ▪ AWS* – EBS, S3, Cloudfront ▪ Data Dog ▪ Application integration points
  • 11. A PRACTICAL GUIDE TO GDPR PREPARATION CONTROLLERS AND PROCESSORS: PROCESSOR OBLIGATIONS 11 Processors are obligated to establish and maintain GDPR compliance. 1. Processor is required to obtain written consent from the controller prior to appointing sub-processor. 2. Processors (and any sub-processors) shall not process personal data, except in accordance with the instructions of the controller 3. Comply with recordkeeping obligations 4. Cooperate with Data Protection Authorities 5. Adhere to data security obligations 6. Comply with data breach reporting requirements 7. Appoint a Data Protection Officer, if applicable 8. Adhere to cross border transfers requirements
  • 12. WHAT SHOULD PRACTITIONERS KNOW TO ACHIEVE AND MAINTAIN COMPLIANCE? 12
  • 13. A PRACTICAL GUIDE TO GDPR PREPARATION PRINCIPLES FOR CONTROLLERS AND PROCESSORS 13 Objective – establish guidelines to promote collection, use, processing, and storage is performed responsibly and in accordance with GDPR requirements. GDPR Requirement… Security Principles** 1. Simplicity 2. Balanced Security 3. Least Privilege 4. Plan for Failure 5. Zero/limit Trust 6. Data Centric Security 7. Design with Multi-tenancy in Mind 8. Build in Traceability Privacy Principles 1. Lawful, fairness, and transparency 2. Purpose limitations 3. Data minimization 4. Accuracy 5. Storage limitation 6. Integrity and confidentiality
  • 14. A PRACTICAL GUIDE TO GDPR PREPARATION DATA PROTECTION BY DESIGN AND BY DEFAULT 14 Objective - To minimize risk to privacy and build trust in the system. Protection by design applies to all personal data. GDPR Requirement… Implement the appropriate technical and organizational measures and integrate them into processing to protect the rights and freedoms of EU citizens. GDPR risk drives development of measures. Actions to Take… 1. Operationalize principles 2. Implement process to establish and maintain records of data processing activities 3. Establish information flows of personal data 4. Define technical and organization measures – pseudonymization, encryption
  • 15. A PRACTICAL GUIDE TO GDPR PREPARATION DATA PROTECTION IMPACT ASSESSMENT (DPIA) 15 Objective – Identify privacy and security risk and take the right measures to reduce it to an acceptable level. DPIA applies to high risk personal data. GDPR Requirement… 1. Documented measures to ensure risk is managed in compliance with GDPR DPIA required during processing of high risk activities. 2. DPIA must be perform prior to implementation Actions to Take… 1. Implement DPIA Process ▪ Develop DPIA questionnaire and establish threshold for DPIA requirement ▪ Define method for privacy and security review ▪ Create template for DPIA documentation ▪ Establish DPIA approval process
  • 16. A PRACTICAL GUIDE TO GDPR PREPARATION CROSS BORDER TRANSFERS 16 Transfers of personal data outside the EEA (European Economic Area) is strictly prohibited. Data transfer can occur if: ▪ Adequacy decision ▪ Binding Corporate Rules (BCR) approved by DPA ▪ Certifications in place ▪ Standard contractual clauses are in place ▪ Ad hoc contractual clauses ▪ Consent from the data subject ▪ Approved Code of Conduct ▪ Privacy Shield compliance
  • 17. A PRACTICAL GUIDE TO GDPR PREPARATION SECURITY OF PROCESSING 17 Identify stack responsibility and apply controls to ensure security of processing ▪ IT Security Policy ▪ Security Processes and Procedures ▪ Access Control ▪ Security in Systems Lifecycle Management ▪ Secure Software Development ▪ Data Protection ▪ Malware Protection ▪ Network Security ▪ Vulnerability Management ▪ Change Management ▪ Security Incident Response – Breach Notification ▪ Disaster Recovery ▪ Supplier Management
  • 18. WHAT ARE THE KEYS TO SUCCESS? 18
  • 19. A PRACTICAL GUIDE TO GDPR PREPARATION ESTABLISH A PLAN 19 GDPR requires the organization to address privacy and security of personal data. A proven approach to gaining clarity on GDPR relevance and understanding how to execute is described below. The Data Protection Officer (DPO) must lead the effort to achieve and maintain alignment. Preparation •Assign data privacy ownership •Understand the regulation Assessment •Assess the EU citizen personal data collected and processed •Identify how the rights of the individual applies •Understand the risk of activities •Assess processors Implementation •Implement GDPR principles •Implement data protection by design •Create and maintain documentation for personal processing activities •Implement data protection impact assessments •Align security controls Maintenance •Operationalize GDPR controls
  • 20. A PRACTICAL GUIDE TO GDPR PREPARATION PROCESS OWNERS AS DATA STEWARD 20 • Leading practices are evolving to establish Data Steward role • Role is aligned with Business Process Owners to understand data assets supporting the process and ensuring controls are in place • Key contributor to DPIA as/if required • Work with DPO, Application, Information Security, Compliance and Supplier Management team members to ensure data protection • Underpins Data Protection by Design principle
  • 21. A PRACTICAL GUIDE TO GDPR PREPARATION KEY POINTS 21 Focus on the following… 1. Understand your data 2. Use principles to drive the right behaviors and build a culture of privacy & security 3. Address protection by design for all personal data 4. Maintain records of processing activities documentation 5. Align security controls with the activities performed and ensure they are defensible 6. Perform data protection impact assessments for all high risk activities, and maintain documentation 7. Manage third party/processor relationships
  • 22. A PRACTICAL GUIDE TO GDPR PREPARATION PROMAPP TO ACHIEVE AND MAINTAIN READINESS 22 A short demonstration…
  • 25. A PRACTICAL GUIDE TO GDPR PREPARATION GDPR MYTHS 25 Understanding GDPR requirements can be complex. There are several common misperceptions that should be clarified. 1. A Data Protection Officer is required for all organizations 2. Each GDPR incident will carry a fine equivalent to the greater of 20 mil Euro or 4% annual worldwide revenue 3. Consent is always required for processing of personal data 4. Parental consent is always required when collecting personal information from a child 5. Individuals have the absolute right to be forgotten 6. Biometric data is sensitive data 7. Controllers do not require processing agreements with processors – GDPR takes care of this 8. Security technology solutions are needed to enable GDPR compliance 9. Automated decision-making can not be performed (e.g., use of AI)
  • 26. A PRACTICAL GUIDE TO GDPR PREPARATION REFERENCE SOURCES 26 ▪ GDPR Regulation - Full regulation Abbreviated regulation Web-based GDPR regulation resource ▪ UK ICO Guide to GDPR ▪ White & Case has great insight into GDPR ▪ A series of 10 posts that provide insight into the operational impact of GDPR ▪ List of Data Protection Authorities for EU Member States ▪ UK ICO Assessment Questionnaire